{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"deadweight_loss_reduction__gender_studies","archetype_slug":"deadweight_loss_reduction","domain_slug":"gender_studies","title":"Field-Specific Separation of Legal and Used Names","opportunity_summary":"Audit where legal names propagate without a necessary legal, safety, reporting, or continuity purpose, then test opt-in use of field-specific display and communication names while retaining confidential linkage and stable identifiers. The proposal could reduce unwanted disclosure, correction work, delay, and avoided participation, but local problem prevalence, legal constraints, intervention effects, and prior implementations remain unverified.","adopter_authorizer":"An institution's data-governance authority, acting within its field mandate and with legal, privacy, security, accessibility, records, system-owner, and affected-party review.","scores":{"meaningful_impact":{"score":4,"rationale":"The candidate targets unwanted identity disclosure, participation barriers, processing delays, and repeated correction work, all potentially consequential to affected users and institutions. The magnitude and prevalence of these burdens are unsupported hypotheses, preventing a score of 5."},"stakeholder_pull":{"score":3,"rationale":"The proposal identifies affected users, frontline staff, record owners, and governance authorities with plausible reasons to seek improvement, but supplies no evidence of requests, complaints, adoption interest, or institutional priority."},"incremental_advantage":{"score":4,"rationale":"Field-specific purpose rules directly replace repeated discretionary exceptions with a default that suppresses unnecessary propagation while preserving confidential linkage. This is plausibly better than the stated manual chosen-name process, although comparative performance is untested."},"distinctiveness_plausibility":{"score":3,"rationale":"The field-purpose separation, confidential linkage, and preset safety monitoring form a specific mechanism distinct from the stated manual exception rival. However, prior art is unsearched, so distinctiveness relative to existing chosen-name systems cannot be established."},"technical_implementability":{"score":4,"rationale":"A limited pilot in low-risk display and communication fields with stable identifiers and rollback is technically bounded and plausible. Legacy integrations, downstream synchronization, permissions, and linkage-table security could still create substantial implementation difficulty."},"adoption_authority_feasibility":{"score":4,"rationale":"The candidate names an institutional data-governance authority, limits action to fields under its mandate, and requires specialist and affected-party review. Feasibility remains contingent on institution-specific law, contracts, regulated records, and divided system ownership."},"evidence_readiness":{"score":4,"rationale":"The proposal supplies auditable indicators, separate problem and intervention falsifiers, a baseline, a nearest rival, preset harm thresholds, and rollback. Baseline data availability and reliable measurement of avoidance or dignity-related harm are not established."},"safety_net_benefit":{"score":4,"rationale":"The design preserves confidential legal linkage, excludes unauthorized changes to controlled records, retains necessary identity checks, and specifies immediate suspension and configuration restoration after serious events. Rollback may not undo an unwanted disclosure once it occurs."},"scalability":{"score":3,"rationale":"Field-purpose rules could be reused across institutional interfaces, but legal requirements, legacy architectures, record taxonomies, workflow ownership, and affected-party needs may vary substantially by institution and domain."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"10K_TO_50K","scope":"A bounded field-purpose and baseline audit at one institution covering a selected set of display and communication interfaces, including stakeholder interviews, ticket and correction review, privacy/legal screening, and comparison of necessary versus unnecessary legal-name uses.","confidence":"LOW","assumptions":["The institution can identify relevant fields and interfaces without major data-engineering work.","Existing tickets, correction records, or workflow samples are accessible under appropriate privacy controls.","The audit does not include live configuration changes or a production pilot."]},"initial_deployment_startup":{"band_2026_usd":"50K_TO_250K","scope":"Design, configure, secure, and test an opt-in pilot in a small number of low-risk fields within one institution, including confidential linkage, permissions, quality assurance, consent materials, monitoring, and rollback preparation.","confidence":"LOW","assumptions":["The pilot avoids regulated legal records and high-risk identity-verification workflows.","Existing systems support configurable display fields or limited integration changes.","The scope is limited to one institution and a small number of interfaces."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Broader one-institution launch across multiple approved systems, including integration remediation, governance review, security testing, training, support processes, migration, communications, accessibility work, and outcome evaluation.","confidence":"LOW","assumptions":["Launch remains within fields controlled by the institution.","Several legacy or vendor-managed integrations require modification and testing.","No wholesale replacement of a core identity-management platform is required."]},"annual_recurring":{"band_2026_usd":"50K_TO_250K","scope":"Ongoing governance, access control, linkage security, monitoring, incident response, user support, correction handling, staff training, vendor coordination, and periodic field-purpose review for one institution.","confidence":"LOW","assumptions":["The institution operates a moderate number of participating systems.","Monitoring can mostly use existing support and audit infrastructure.","Major platform replacement and litigation costs are excluded."]}},"research_burden":"MODERATE","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"YES","reason":"The candidate describes a coherent institutional-access problem and names auditable manifestations: non-required propagation, mismatch tickets, corrections, delays, unwanted disclosures, and abandoned interactions. Its local prevalence still requires validation."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The institution's data-governance authority is explicitly identified, with action bounded to fields under its mandate and conditioned on legal, privacy, security, records, accessibility, and affected-party review."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The candidate claims that field-specific suppression with confidential linkage will outperform default legal-name propagation plus manual exceptions on access and correction outcomes without exceeding preset safety or reporting thresholds."},"bounded_next_evidence_step":{"status":"YES","reason":"A field-purpose audit is authorized before deployment and can compare observed legal-name propagation and burden against documented necessity, with a stated falsifier if meaningful unnecessary propagation or burden is absent."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The proposal excludes changes to controlled records without authority, public exposure of linkage, and removal of necessary checks; it also requires suspension and rollback after serious events. Institution-specific approval remains a prerequisite rather than an identified absolute stop."},"implementation_cost_scope_and_range":{"status":"UNCERTAIN","reason":"The candidate bounds a pilot to low-risk fields but does not specify the number of systems, integration architecture, vendor constraints, data quality, staffing, or compliance workload needed to validate an implementation range."}},"blocking_evidence":["Whether the target institution has meaningful legal-name propagation in fields lacking a documented legal, safety, reporting, or continuity purpose.","Whether mismatch, correction, delay, unwanted-disclosure, or avoided-participation burdens are detectable relative to the baseline.","Which fields and identity checks are legally or operationally indispensable in the intended jurisdiction and institutional setting.","Whether existing systems already provide effective separation or would require extensive integration changes.","Whether confidential linkage and field separation can avoid serious identity, continuity, privacy, safety, fraud, and reporting failures.","How the proposed mechanism and pilot protocol compare with prior implementations, because prior art has not been searched or verified."],"next_evidence_step":"Conduct a four-to-six-week, non-deployment audit at one willing institution: sample a predefined set of low-risk display and communication interfaces, compare every legal-name use with a documented purpose-and-authority classification, and quantify associated correction tickets, delays, disclosure reports, and abandoned workflows where observable. Stop before a pilot if nearly all sampled uses are necessary, existing separation already works, or no meaningful burden is detected; otherwise produce a reviewed shortlist of pilot-eligible fields and estimated integration scope.","research_questions":["What proportion of sampled legal-name propagation lacks a documented legal, safety, reporting, identity-verification, or continuity requirement?","Which affected groups experience disclosures, mismatches, repeated corrections, delays, or avoidance, and how can those outcomes be measured without creating new exposure?","Does the institution already have chosen-name functionality, and where does it fail to prevent downstream propagation or repeated manual correction?","Can stable identifiers and confidential linkage preserve record continuity across the proposed pilot fields?","What preset rates or severities of disclosure, misidentification, fraud, safety, privacy, and reporting failures should halt the pilot?","Which system owners and governance bodies control each candidate field, and what approvals or vendor changes are required?","What documented prior systems use comparable field-purpose rules, confidential linkage, and opt-in safety-monitored pilots?"],"recommendation":"VALIDATE_PROBLEM_FIRST","uncertainty_constraints":["Problem prevalence and effect magnitude are unsupported by external or local evidence.","Stakeholder demand and authorizer willingness are not demonstrated.","Applicable legal, reporting, records, and identity-verification requirements are institution- and jurisdiction-specific.","Technical feasibility depends on unknown legacy integrations, vendor controls, permissions, and data quality.","Avoidance, dignity, and unwanted-disclosure effects may be difficult to observe without biased or privacy-invasive measurement.","Cost bands are resource-equivalent planning ranges based on assumed one-institution scope, not verified estimates.","Intervention performance and serious-failure rates remain hypothetical.","World novelty, market size, realized impact, and generalizability are unmeasured."],"closed_book_prior_art_boundary":"Prior art is explicitly unsearched and unverified in this closed-book assessment. No claim is made that field-specific name separation, confidential linkage, chosen-name workflows, or the proposed pilot protocol is novel, uncommon, or superior to documented external implementations."}