{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"deadweight_loss_reduction__gender_studies","archetype_slug":"deadweight_loss_reduction","domain_slug":"gender_studies","title":"Field-Specific Separation of Legal and Used Names","opportunity_summary":"Audit whether legal names propagate into institutional fields that do not require them, then test opt-in use of field-specific name rules in low-risk displays and communications while preserving confidential linkage, necessary verification, and rollback controls.","adopter_authorizer":"An institution's data-governance authority, acting within its field mandate and with legal, privacy, security, accessibility, records, system-owner, and affected-party review.","scores":{"meaningful_impact":{"score":3,"rationale":"The proposal targets disclosure, correction work, delays, and participation barriers that could be meaningful, but their prevalence, severity, and affected population are unsupported hypotheses."},"stakeholder_pull":{"score":3,"rationale":"Affected users, frontline staff, system owners, and oversight authorities are identifiable, but the packet provides no evidence of expressed demand, complaint volume, or institutional priority."},"incremental_advantage":{"score":4,"rationale":"Purpose-specific field rules directly replace repeated discretionary exceptions and could prevent propagation at its source, although superiority over the manual chosen-name process remains untested."},"distinctiveness_plausibility":{"score":3,"rationale":"The combination of field-purpose rules, confidential linkage, and bounded monitoring is specific and testable, but prior art is explicitly unsearched and no originality claim can be supported."},"technical_implementability":{"score":3,"rationale":"Stable confidential linkage and changes limited to low-risk display and communication fields make a pilot plausible, while legacy dependencies, identifier behavior, and integration complexity are unknown."},"adoption_authority_feasibility":{"score":4,"rationale":"The candidate names a bounded institutional authority, required reviewers, excluded records, and rollback conditions; feasibility could still be reduced by distributed system ownership or legal constraints."},"evidence_readiness":{"score":2,"rationale":"The problem and intervention are hypotheses with no supplied baseline measurements or outcome evidence, despite having auditable indicators and separate falsifiers."},"safety_net_benefit":{"score":4,"rationale":"The design could reduce unwanted identity disclosure while retaining confidential linkage and necessary checks, and it includes explicit halt and rollback rules; linkage exposure and identity fragmentation remain material risks."},"scalability":{"score":3,"rationale":"A field-purpose model could be reused across institutional interfaces, but system heterogeneity, field-specific legal duties, staff workarounds, and local governance make transferability uncertain."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"10K_TO_50K","scope":"A bounded field-purpose audit at one institution covering selected low-risk display and communication fields, baseline ticket and correction measures, affected-party review, and a go/no-go comparison against current propagation.","confidence":"MODERATE","assumptions":["Existing field inventories, policies, and support records are accessible.","The audit covers a limited number of systems and does not require production changes.","Legal, privacy, records, technical, and affected-party reviewers contribute limited staff time."]},"initial_deployment_startup":{"band_2026_usd":"50K_TO_250K","scope":"Configure and evaluate a time-limited opt-in pilot in a small set of low-risk fields, including confidential linkage, access controls, instrumentation, staff procedures, consent, and rollback testing.","confidence":"LOW","assumptions":["Existing systems permit configuration or modest integration rather than major replacement.","The pilot is confined to one institution and excludes regulated or legally controlled records.","Security, privacy, accessibility, and legal review do not uncover a blocking redesign requirement."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Institution-wide launch across approved nonregulated interfaces, including integration work, data governance, testing, training, communications, monitoring, remediation, and formal evaluation.","confidence":"LOW","assumptions":["Launch spans several institutional systems but not a complete identity-platform replacement.","Stable identifiers and confidential linkage can be preserved across participating systems.","Material vendor customization, regulatory certification, or record migration is not required."]},"annual_recurring":{"band_2026_usd":"50K_TO_250K","scope":"Ongoing governance, access review, incident response, field-purpose reassessment, support, correction handling, outcome monitoring, staff training, and system maintenance for one institution.","confidence":"LOW","assumptions":["The institution operates a moderate number of participating systems.","Monitoring uses existing support and analytics infrastructure where possible.","No persistent high rate of manual reconciliation or serious incidents emerges."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"YES","reason":"The candidate identifies concrete observable manifestations—unnecessary propagation, mismatch tickets, corrections, delays, disclosures, and abandoned interactions—although their actual prevalence remains unverified."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The institution's data-governance authority is explicitly identified, with bounded jurisdiction and named specialist and affected-party reviewers."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal can be compared with canonical legal-name propagation and manual exceptions on exposure, correction, access, and serious failure outcomes."},"bounded_next_evidence_step":{"status":"YES","reason":"A field-purpose audit is bounded to selected interfaces and can determine whether meaningful unnecessary propagation exists before any live pilot is authorized."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The candidate excludes regulated-record alteration and removal of necessary checks, requires confidential linkage and authorized review, and specifies suspension and restoration after threshold events."},"implementation_cost_scope_and_range":{"status":"YES","reason":"The audit, limited pilot, broader launch, and recurring operations can be separately scoped into broad resource bands, though architecture and system-count uncertainty make later-stage estimates low confidence."}},"blocking_evidence":["Whether meaningful legal-name propagation occurs in fields lacking a legal or operational requirement.","Baseline rates and consequences of mismatch tickets, repeated corrections, processing delays, unwanted disclosures, and avoided interactions.","Whether stable confidential linkage can preserve identification, continuity, privacy, safety, and reporting in the selected systems.","Comparative pilot evidence against canonical propagation and manual exceptions, including access outcomes and serious failure thresholds.","Applicable field-level legal, contractual, records, security, and reporting requirements.","Evidence on unequal pilot access, staff workarounds, and effects across affected groups.","Prior-art evidence concerning chosen-name systems, field-purpose designs, confidential linkage models, and comparable pilot protocols."],"next_evidence_step":"At one institution, audit a predefined set of low-risk display and communication fields and compare each field's documented legal or operational purpose with actual legal-name propagation, baseline mismatch and correction indicators, and existing separation behavior; falsify progression if nearly all propagation is necessary, separation already functions adequately, or no meaningful burden is observable.","research_questions":["Which audited fields genuinely require legal-name display or propagation, and under what authority or operational dependency?","How often do current propagation and manual exceptions produce corrections, delays, unwanted disclosures, or abandoned interactions?","Does field-specific separation improve access and correction outcomes relative to the current default and manual exception process?","Can stable confidential linkage prevent record fragmentation, misidentification, impersonation, and reporting failures?","Are opt-in access, benefits, burdens, or errors distributed unequally across affected groups?","Do staff workarounds recreate exposure or impose new administrative burdens?","What prior implementations resemble the field-purpose rules, linkage design, or pilot protocol?","Which preset error and harm thresholds should trigger suspension or rollback?"] ,"recommendation":"VALIDATE_PROBLEM_FIRST","uncertainty_constraints":["Closed-book assessment cannot establish problem prevalence, stakeholder demand, realized impact, legal applicability, technical performance, or market size.","Prior art is unsearched, so distinctiveness and novelty are unmeasured.","Cost bands are resource-equivalent scenarios, not observed prices, and depend heavily on system count, legacy architecture, and review requirements.","The candidate spans multiple institutional settings and populations, but the proposed first evidence step supports conclusions only for the audited institution and fields.","Dignity, avoidance, and unwanted disclosure may be undercounted by administrative metrics alone."],"closed_book_prior_art_boundary":"No conclusion is made about novelty, prevalence, existing chosen-name capabilities, comparable identity-record designs, or documented outcomes. Distinctiveness is assessed only as the internal specificity and testability of the sealed mechanism relative to its stated baseline and nearest rival."}