{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"layer_decay_and_expiration_management__computer_science","archetype_slug":"layer_decay_and_expiration_management","domain_slug":"computer_science","title":"Dependency-Gated Lifecycle Management for Superseded CI Artifacts","opportunity_summary":"Evaluate whether policy-gated archival, reversible quarantine, dependency vetoes, tombstones, and restoration tests can bound obsolete registry artifacts more safely than age-only or untagged-artifact cleanup. The candidate is operationally specific, but local problem magnitude, comparative benefit, hidden-reference coverage, and distinctiveness remain unverified.","adopter_authorizer":"The registry owner would execute the policy with approval from release engineering and security; compliance or legal authorities control applicable holds, while service owners review unresolved dependencies.","scores":{"meaningful_impact":{"score":3,"rationale":"The proposal could reduce active stale bytes, obsolete-artifact exposure, and unsafe cleanup while preserving rollback and provenance, but the packet provides no evidence that superseded artifacts create material burden or incidents in a target registry."},"stakeholder_pull":{"score":3,"rationale":"Release, registry, security, incident-response, compliance, and service-owner interests are concretely identified, but no adopter requests, observed incidents, budget commitment, or demonstrated dissatisfaction with existing cleanup is supplied."},"incremental_advantage":{"score":4,"rationale":"Relative to the stated age-only or untagged baseline, dependency vetoes, holds, reversible quarantine, archival restoration tests, and recorded disposition directly address rollback and provenance failure modes; comparative performance and operator burden remain untested."},"distinctiveness_plausibility":{"score":2,"rationale":"The composition is coherent, but prior-art status is explicitly unsearched and the packet supplies no basis for determining whether equivalent registry-retention, soft-deletion, archival, or restoration systems already exist."},"technical_implementability":{"score":3,"rationale":"The candidate defines artifact states, policy stages, audit records, restoration tests, and halt conditions, but implementation depends on reliable hold enforcement, cross-system reference discovery, shared-blob handling, and archive fidelity that are not established."},"adoption_authority_feasibility":{"score":4,"rationale":"Execution, approval, hold authority, and dependency review are separated clearly, and a nonproduction namespace offers a bounded starting point; coordination across legal, compliance, security, and service owners could still delay production authorization."},"evidence_readiness":{"score":4,"rationale":"A 30-day, at-most-500-artifact nonproduction study, explicit comparators, problem and intervention falsifiers, restore testing, and halt criteria are provided. Preset acceptance bounds and recovery objectives must still be instantiated."},"safety_net_benefit":{"score":5,"rationale":"Dependency vetoes, mandatory holds, reversible quarantine, no pilot hard deletion, audit preservation, tombstones, archive restoration tests, and explicit rollback conditions form a strong proposal-specific safety net against destructive cleanup."},"scalability":{"score":3,"rationale":"The lifecycle model could apply across namespaces and registries, but scaling depends on heterogeneous metadata, external digest consumers, shared manifests, retention rules, archive performance, and exception governance."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"10K_TO_50K","scope":"A 30-day, single-nonproduction-namespace evaluation covering at most 500 superseded artifacts, including read-only inventory, dependency and hold review, age-only comparator simulation, archival of a sample, restore tests, analysis, and acceptance-threshold definition.","confidence":"MODERATE","assumptions":["Existing registry APIs and metadata are accessible without major platform development.","The namespace contains no more than 500 evaluated artifacts.","One release or registry engineer and fractional security, service-owner, and compliance participation are sufficient.","No production artifact is hard-deleted or made unavailable."]},"initial_deployment_startup":{"band_2026_usd":"50K_TO_250K","scope":"Build and validate a production-capable lifecycle service for a limited registry environment, including inventory connectors, policy and hold enforcement, dependency checks, quarantine, tombstones, archival integration, restoration testing, audit logging, and operational controls.","confidence":"LOW","assumptions":["The organization has usable artifact, deployment, and identity interfaces.","A suitable archival tier and audit system already exist or require only integration.","The scope is limited to one registry platform and a small number of artifact classes.","Formal legal or regulatory certification is not required before limited rollout."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Launch across production namespaces for one organization, including policy migration, owner onboarding, dependency-coverage validation, recovery exercises, compliance approval, monitoring, incident procedures, documentation, and staged rollout support.","confidence":"LOW","assumptions":["The launch spans multiple services but not a multi-enterprise commercial product.","Hidden consumers can be investigated through available deployment and access records.","Existing registry and archive infrastructure can support quarantine and restoration.","High-criticality artifact classes receive additional review rather than bespoke platform redevelopment."]},"annual_recurring":{"band_2026_usd":"50K_TO_250K","scope":"Annual operation for one organization, including storage and retrieval, lifecycle-service hosting, policy maintenance, exception and hold review, dependency reconciliation, periodic restore exercises, audit support, monitoring, and operator time.","confidence":"LOW","assumptions":["Artifact volume and cold-tier retrieval frequency are moderate.","The service uses existing registry, observability, and identity infrastructure.","Exception queues and tombstones are actively governed rather than allowed to grow without review.","The estimate excludes major registry replacement or organization-wide compliance transformation."]}},"research_burden":"MODERATE","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"YES","reason":"The candidate specifies affected artifacts, observable lifecycle states, concrete failure modes, affected operational objectives, and a falsifier based on bounded inventory; actual prevalence and severity still require measurement."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The registry owner is the executor, release engineering and security approve policy, compliance or legal authorities control holds, and service owners review unresolved dependencies."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The candidate can be compared with age-only cleanup on active stale bytes, obsolete discoverability, dependency misses, restoration failures, policy violations, and operator effort."},"bounded_next_evidence_step":{"status":"YES","reason":"A 30-day evaluation in one nonproduction namespace with at most 500 artifacts, sampled archival and restoration, explicit comparison, no hard deletion, and stated halt conditions is bounded and decision-relevant."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The proposed first step prohibits production hard deletion and hold overrides, requires dependency-clear status, permits restoration, preserves audit records, and names authorized reviewers and halt triggers."},"implementation_cost_scope_and_range":{"status":"YES","reason":"The assessment provides broad resource-equivalent bands and defined scopes for evidence, limited implementation, production launch, and recurring operation, while marking integration-dependent estimates as low confidence."}},"blocking_evidence":["A bounded inventory showing material accumulation, stale discoverability, operational burden, or retention conflict in the target namespace.","Evidence that dependency discovery covers deployment systems, shared manifests and blobs, and relevant external digest consumers well enough to support quarantine decisions.","Preset acceptance bounds for stale-byte reduction, obsolete discoverability, dependency misses, restoration fidelity and latency, policy violations, rollback risk, and operator effort.","Comparative results against age-only cleanup under the same artifact set and policy constraints.","Demonstration that holds reliably veto disposition and that quarantine or archival does not conflict with applicable erasure obligations.","External prior-art research establishing whether the proposed mechanism composition differs meaningfully from existing registry lifecycle systems."],"next_evidence_step":"Conduct a 30-day shadow evaluation in one nonproduction registry namespace on at most 500 superseded artifacts: inventory artifacts and known references, simulate both the proposed policy and age-only cleanup on the same set, archive and restore-test a stratified sample without changing deployability, and prohibit hard deletion. Stop or reject the problem if the inventory finds no material accumulation, stale exposure, burden, or retention conflict; reject the intervention if it fails preset comparative bounds or increases missed dependencies, restoration failures, policy violations, or operator effort.","research_questions":["How many artifacts and active bytes are genuinely superseded, and what storage, search, maintenance, or stale-selection consequences do they create?","What proportion of deployment, rollback, provenance, investigation, and external digest references can the available dependency graph observe?","Which artifact classes, rollback windows, holds, and recovery objectives should control eligibility and restoration testing?","Compared with age-only cleanup, does the proposed policy reduce stale bytes or obsolete discoverability without exceeding bounds for dependency misses, restoration failures, policy violations, and operator effort?","Can shared blobs and manifests be tiered or quarantined without impairing artifacts that remain live?","How often do archive retrieval latency or cost interfere with rollback and incident-response objectives?","Do existing registry lifecycle, retention, archival, or soft-deletion systems already implement the same composition?","What governance prevents tombstones, holds, and exceptions from becoming another indefinite accumulation layer?"],"recommendation":"VALIDATE_PROBLEM_FIRST","uncertainty_constraints":["No external evidence establishes problem prevalence, stakeholder demand, market size, realized impact, or current baseline performance.","Prior art is unsearched, so distinctiveness and novelty cannot be credited.","Pilot acceptance bounds and recovery objectives are unspecified and must be set from local criticality and compliance requirements.","The completeness of dependency visibility, especially for external digest consumers and shared blobs, is unknown.","Cost bands are resource-equivalent planning ranges, not quotes, and depend strongly on existing registry, archive, audit, and deployment interfaces.","Sampled restoration cannot establish recoverability for untested artifacts or future archive conditions."],"closed_book_prior_art_boundary":"This assessment makes no claim that the candidate, its components, or their composition are novel, rare, prevalent, or absent from existing products or practices. Distinctiveness remains unresolved until external research compares the proposal with registry retention and garbage collection, artifact attestation, archival restoration, quarantine or soft-deletion, tombstone, and dependency-analysis systems."}