{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__organizational_management","trajectory_id":"R","attempt_index":0,"archetype_slug":"computability_boundary_mapping","domain_slug":"organizational_management","decision":"CANDIDATE","problem_id":"universal_workflow_policy_assurance_overclaim","causal_lever_id":"formal_solvability_boundary_and_governed_fallback","proposal":{"problem":"HYPOTHESIS: A central governance function promises an exact, always-terminating preapproval decision about whether any proposed organizational workflow or programmable policy can ever violate organizational rules, although the proposal language permits unbounded iteration, recursion, or process invocation.","actors_substrate":["governance and compliance office","workflow and policy authors","employees governed by the workflows","automation engineers","executive risk owner","independent proof reviewers","programmable workflow/rule language"],"observable_state":"HYPOTHESIS: Universal approval claims coexist with timeouts, ad hoc exclusions, repeated analyzer redesign, or forced approve/reject outputs where the analysis actually remains unknown.","consequence":"The organization may approve unsafe workflows, reject acceptable ones, conceal the real scope of assurance, or continue funding an impossible unrestricted analyzer.","affected_objective":"Reliable, timely, and accountable governance of organizational workflows without overstating automation guarantees.","structural_mapping":[{"archetype_element":"open-ended problem class","domain_realization":"All workflows expressible in the organization's programmable rule language.","claim_kind":"HYPOTHESIS"},{"archetype_element":"semantic decision property","domain_realization":"Whether any execution can produce a defined policy breach.","claim_kind":"INFERENCE"},{"archetype_element":"total exact decider demand","domain_realization":"A required Boolean preapproval that is correct and terminates for every submitted workflow.","claim_kind":"HYPOTHESIS"},{"archetype_element":"decidable restricted region","domain_realization":"An enforceable finite-state or otherwise proven-decidable workflow fragment.","claim_kind":"INFERENCE"},{"archetype_element":"honest weaker operation","domain_realization":"Exact decisions in-fragment; conservative analysis, bounded search, UNKNOWN, or accountable escalation elsewhere.","claim_kind":"INFERENCE"}],"component_map":[{"component":"Problem-Class Specification","status":"adapted","domain_realization":"Define workflow class and breach property."},{"component":"Instance Representation Contract","status":"adapted","domain_realization":"Versioned workflow syntax, semantics, and policy encoding."},{"component":"Computation Model Contract","status":"adapted","domain_realization":"Declare language execution and external-service capabilities."},{"component":"Solvability Guarantee Profile","status":"adapted","domain_realization":"Separate exact, sound-one-sided, bounded, and unresolved guarantees."},{"component":"Quantifier and Scope Map","status":"adapted","domain_realization":"Distinguish every workflow from named or bounded workflows."},{"component":"Computability Status Lattice","status":"direct","domain_realization":"Classify modes as decidable, recognizable, relative, or unresolved."},{"component":"Constructive Procedure Witness","status":"adapted","domain_realization":"Restricted-fragment analyzer with correctness and termination argument."},{"component":"Reduction Preservation Contract","status":"direct","domain_realization":"Check total source-to-workflow translation and answer preservation."},{"component":"Computability Impossibility Certificate","status":"adapted","domain_realization":"Reviewed reduction for the unrestricted workflow language."},{"component":"Assumption Register","status":"adapted","domain_realization":"Record expressiveness, semantics, policy predicate, and oracle assumptions."},{"component":"Decidable Subclass Map","status":"adapted","domain_realization":"Map enforceable safe workflow fragments."},{"component":"One-Sided Recognition Contract","status":"adapted","domain_realization":"State which breach witnesses can be confirmed."},{"component":"Unknown and Nontermination Policy","status":"adapted","domain_realization":"Keep UNKNOWN, timeout, false, and tool failure distinct."},{"component":"Fallback Solution Contract","status":"adapted","domain_realization":"Publish guarantee and permitted use for each fallback."},{"component":"Computability Guarantee Record","status":"adapted","domain_realization":"Version the shipped assurance claim and evidence."},{"component":"Recheck Trigger","status":"adapted","domain_realization":"Reassess after language, policy, bound, or external-service changes."},{"component":"Termination Condition","status":"adapted","domain_realization":"Total restricted analysis or explicit resource bound."},{"component":"Scope Boundary","status":"adapted","domain_realization":"Mechanically admit, reject, or quarantine submissions."},{"component":"Decision Record","status":"adapted","domain_realization":"Record chosen boundary, owner, evidence, and expiry."},{"component":"Uncertainty Residue","status":"adapted","domain_realization":"List semantic gaps and unproved obligations."},{"component":"Independent Proof Review","status":"direct","domain_realization":"Independent review of formalization and reduction."},{"component":"Complexity Follow-On Gate","status":"adapted","domain_realization":"Assess cost only after decidability is established."}],"mechanism_dispositions":[{"slug":"abstract_interpretation_or_model_checking","disposition":"selected_supporting","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Conservative finite workflow abstraction; alarms may be false positives.","counterfactual_removal":"Removes the sound approximate fallback."},{"slug":"bounded_domain_exhaustive_search","disposition":"selected_supporting","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Exhaust finite pilot bounds without generalization.","counterfactual_removal":"Weakens bounded validation, not the boundary proof."},{"slug":"computability_boundary_decision_record","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Version assurance, assumptions, owners, and triggers.","counterfactual_removal":"Allows guarantee drift."},{"slug":"computational_complexity_analysis","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Gate feasibility review after solvability.","counterfactual_removal":"Decidable but unusable modes may ship."},{"slug":"constructive_algorithm_and_correctness_proof","disposition":"selected_supporting","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Prove the restricted analyzer total and correct.","counterfactual_removal":"Restricted exactness lacks a witness."},{"slug":"diagonalization_impossibility_proof","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Halting reduction is more directly tied to workflow execution.","counterfactual_removal":"No change."},{"slug":"enumeration_and_dovetailing","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Unbounded recognizer is unsuitable for approval latency.","counterfactual_removal":"No change."},{"slug":"fallback_mode_router","disposition":"selected_load_bearing","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Route by proven scope and attach the actual guarantee.","counterfactual_removal":"Weaker results can be mistaken for exact approval."},{"slug":"halting_problem_reduction","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Use only if workflow semantics support a valid embedding.","counterfactual_removal":"The unrestricted impossibility claim remains unresolved."},{"slug":"language_fragment_restriction","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Enforce a syntactic decidable workflow fragment.","counterfactual_removal":"No total exact production region is secured."},{"slug":"many_one_reduction_proof","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Its obligations are incorporated in the selected halting reduction.","counterfactual_removal":"No change."},{"slug":"promise_problem_restriction","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Unenforced promises permit authoritative outputs outside guarantee.","counterfactual_removal":"No change."},{"slug":"proof_by_counterexample","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Refutes an implementation claim but cannot establish undecidability.","counterfactual_removal":"No change."},{"slug":"proof_checking","disposition":"selected_supporting","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Independently check the formal theorem and assumptions.","counterfactual_removal":"Subtle proof gaps may govern policy."},{"slug":"reduction_direction_checklist","disposition":"selected_supporting","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Gate source-to-target direction before accepting impossibility.","counterfactual_removal":"A reversed reduction may be trusted."},{"slug":"semi_decision_with_explicit_unknown","disposition":"selected_load_bearing","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Return witnessed breach or UNKNOWN at a declared bound, never fabricated clearance.","counterfactual_removal":"Timeouts are likely to become false verdicts."},{"slug":"theorem_prover_guided_search","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Optional proof discovery is not required for the first boundary decision.","counterfactual_removal":"No change."},{"slug":"turing_reduction_analysis","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"No relative-oracle classification is needed.","counterfactual_removal":"No change."}],"causal_chain":["Formalize workflow semantics, policy-breach predicate, class, quantifiers, and computation model.","Seek a restricted constructive decider and an unrestricted impossibility reduction in parallel.","Independently review semantic fidelity, reduction direction, preservation, and assumptions.","Enforce the proven decidable fragment at submission.","Route other inputs to conservative, bounded, UNKNOWN, or human-governed modes with explicit labels.","Version the decision and reclassify when language, policies, or external capabilities change."],"baseline":"A committee or analyzer reviews workflows using examples, simulation, timeouts, and undocumented exceptions, then emits approve/reject.","nearest_rival":"Risk-tier rules plus human review, which may improve decisions but does not establish the boundary of universal exact automation.","authority_safety":{"affected_parties":["employees subject to automated workflows","workflow authors","compliance and operations staff","customers or partners affected by policy breaches"],"decision_authority":"The executive risk owner may authorize scope; policy owners approve breach semantics; independent reviewers must accept formal boundary evidence.","authorized_first_step":"Run a non-production pilot on 12 versioned synthetic and historical workflow models: formalize semantics, test a candidate fragment, check a reduction, seed known breaches, and compare labeled outputs with baseline review.","excluded_actions":["automatic production approval from pilot results","treating UNKNOWN or timeout as safe or noncompliant","generalizing bounded checks beyond their bound","restricting employee-facing policy without policy-owner approval","claiming impossibility before independent review"],"halt_rollback":"Halt if semantics cannot represent the real policy task, fragment membership is unenforceable, a seeded breach receives clearance, or proof review finds an open obligation; retain baseline review and revoke the affected guarantee record."}},"negative_tests":{"strongest_counterevidence":"The deployed workflow catalog may be finite and fixed, making exhaustive decision possible in principle; alternatively, policy meaning may be too ambiguous to define a stable predicate, making ontology—not computability—the primary problem.","analogy_break":"Management deliberation is not automatically computation. The mapping holds only where proposals have effective encodings and execution semantics; tacit judgment, political legitimacy, and changing meanings are not settled by a computability proof.","failure_condition":"The intervention fails operationally if users routinely need excluded expressiveness, bypass admission controls, or cannot act safely on conservative alarms and UNKNOWN results.","problem_falsifier":"The problem is falsified if the required scope is a fixed finite set or an enforceable language already has a proven total decider and the remaining issue is only cost, coordination, or policy ambiguity.","intervention_falsifier":"The proposed lever is falsified if reviewed evidence cannot classify the stated problem, the restricted analyzer lacks totality or correctness, conservative analysis clears a modeled real breach, or routing labels do not prevent downstream Boolean coercion.","risks":["A correct proof may formalize the wrong organizational policy.","A restrictive fragment may displace work into ungoverned channels.","False alarms may create review fatigue.","Human escalation may become an unmodeled oracle or accountability sink.","An impossibility label may be used rhetorically to avoid feasible bounded automation."]},"null_rationale":null,"classification":{"candidate_kind":"MECHANISM_COMPOSITION","prior_art_status":"UNSEARCHED","evidence_maturity":"HYPOTHESIS"},"revision_change_log":{"revision_kind":"ORIGINAL","prior_problem_id":null,"prior_causal_lever_id":null,"problem_changed":false,"causal_lever_changed":false,"conceptual_changes":[],"operational_changes":[],"repairs_addressed":[]},"confidence":0.84,"generator_notes":"Closed-book structural transfer. Candidate depends on the workflow language being effectively encoded and sufficiently expressive; no claim is made that ordinary organizational judgment is undecidable."}