{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp04_retrieval_first_paired20_20260802","cell_id":"computability_boundary_mapping__ethnography_qualitative_methods","round_index":0,"assessments":[{"hypothesis_id":"H1","search_queries":["qualitative research theoretical saturation code saturation meaning saturation finite sample negative cases primary study","grounded theory saturation stopping criterion no new codes software dashboard saturation","Guest Namey Chen saturation qualitative research calculator","theoretical saturation cannot prove future cases qualitative sampling guidance"],"sources":[{"source_id":"H1S1","title":"A simple method to assess and report thematic saturation in qualitative research","publisher":"PLOS ONE","url":"https://journals.plos.org/plosone/article/file?id=10.1371%2Fjournal.pone.0232076&type=printable","source_class":"PRIMARY_RESEARCH","claims_supported":["Existing methods operationalize saturation using a base size, run length, and new-information threshold.","The paper distinguishes prospective bounded assessment from retrospective calculations that inevitably reach 100% on fixed datasets.","The method reports little or no new information relative to study objectives rather than proving that no future case could add information."]},{"source_id":"H1S2","title":"Code Saturation Versus Meaning Saturation: How Many Interviews Are Enough?","publisher":"Qualitative Health Research / SAGE","url":"https://journals.sagepub.com/doi/pdf/10.1177/1049732316665344","source_class":"PRIMARY_RESEARCH","claims_supported":["Code saturation and meaning saturation are already distinguished empirically.","Different saturation goals require different sample sizes and depend on study purpose, population, sampling strategy, data quality, and codebook development.","The literature already recommends prespecified stopping criteria and transparent, verifiable reporting."]}],"closest_analogue":"Guest, Namey, and Chen's base-size/run-length/new-information-threshold method, supplemented by Hennink, Kaiser, and Marconi's separation of code from meaning saturation.","overlap":"Both analogues replace an unsupported intuitive stopping call with an explicit, auditable rule tied to observed novelty over a declared run of interviews. They also distinguish weaker code-level evidence from stronger meaning or theory claims and warn that fixed-dataset saturation measures are bounded by the collected sample.","remaining_difference":"The hypothesis adds an output contract that reserves an explicit UNKNOWN state and separately permits exact exhaustion only for an enforceably finite frame. Its test against deliberately delayed negative cases is also more adversarial than the validation reported in the opened sources. A direct experiment can compare false terminal calls under matched late-negative-case schedules while checking whether finite frames alone receive an exhaustion certificate.","classification":"POSSIBLE_DISTINCTION","disposition":"ADVANCE","rationale":"The core stopping-rule idea has strong prior art, but the strict three-state semantics and finite-frame-only certification remain concrete, falsifiable additions rather than a claim of novelty from search failure."},{"hypothesis_id":"H2","search_queries":["site:ukdataservice.ac.uk anonymisation qualitative data auxiliary information re-identification risk","site:icpsr.umich.edu qualitative data disclosure risk anonymization field notes","NIST de-identification threat model auxiliary information re-identification standard","Qualitative Data Repository de-identification human participants guidance"],"sources":[{"source_id":"H2S1","title":"NIST SP 800-188: De-Identifying Government Datasets: Techniques and Governance","publisher":"National Institute of Standards and Technology","url":"https://csrc.nist.gov/pubs/sp/800/188/final","source_class":"GOVERNMENT_OR_REGULATOR","claims_supported":["De-identification should be evaluated against release risks rather than treated as an absolute label.","NIST recommends measurable de-identification standards, re-identification studies, disclosure-review governance, and alternative sharing models including synthetic data, query interfaces, and protected enclaves.","Tools that merely mask information may be insufficient for de-identification."]},{"source_id":"H2S2","title":"Sharing Human Participant Data","publisher":"Qualitative Data Repository / Managing Qualitative Data","url":"https://managing-qualitative-data.org/modules/3/b/","source_class":"OFFICIAL_GUIDANCE","claims_supported":["Indirect identifiers in qualitative narratives require context-sensitive treatment and documented de-identification rules.","Complete de-identification while retaining analytic utility is often impossible, and protection is relative to who possesses contextual knowledge.","When de-identification is insufficient, controlled access is recommended as a complement or replacement."]},{"source_id":"H2S3","title":"Open-Science Guidance for Qualitative Research: An Empirically Validated Approach for De-Identifying Sensitive Narrative Data","publisher":"Association for Psychological Science","url":"https://www.psychologicalscience.org/journals/ampps/25152459231205832/","source_class":"PRIMARY_RESEARCH","claims_supported":["A qualitative-specific framework already uses stakeholder consultation to characterize re-identifiability risks.","It applies iterative remediation through group review and consensus.","It includes multiple strategies for validating whether remediated transcripts adequately protect participants."]},{"source_id":"H2S4","title":"Guide for Sharing Qualitative Data at ICPSR","publisher":"Inter-university Consortium for Political and Social Research","url":"https://wpvip.icpsr.umich.edu/icpsr/wp-content/uploads/sites/11/2025/06/Guide-for-Sharing-Qualitative-Data-at-ICPSR-V2.pdf","source_class":"OFFICIAL_GUIDANCE","claims_supported":["ICPSR performs disclosure-risk review of qualitative data before release, considering direct identifiers, indirect identifiers, contextual information, and access restrictions.","Its workflow routes higher-risk material to secure download, virtual or physical enclaves, or delayed dissemination.","Qualitative-data review can trade stronger masking against restricted access to preserve reuse value."]}],"closest_analogue":"NIST SP 800-188's risk-relative de-identification governance instantiated by QDR and ICPSR qualitative-data disclosure review.","overlap":"The prior art already rejects universal anonymity, evaluates re-identification risk in context, documents rules, conducts re-identification or disclosure-risk studies, uses expert review, and routes material among open release, stronger transformation, restricted access, or nonrelease.","remaining_difference":"The proposed seeded-attack benchmark and an explicitly enumerable linkage-space certificate are narrower implementation details. They could be tested, but they do not change the already-established threat-relative review-and-routing intervention.","classification":"OBVIOUS_COLLISION","disposition":"REJECT","rationale":"Authoritative and qualitative-specific sources jointly contain the hypothesis's central causal structure; relabeling covered, uncovered, and unresolved risks does not establish a material distinction at this shallow screen."},{"hypothesis_id":"H3","search_queries":["adaptive interview protocol executable workflow branching logic ethics model checking","clinical trial protocol model checking workflow safety adaptive protocol formal verification","REDCap branching logic survey official documentation adaptive instruments","formal verification human subjects research protocol finite state model"],"sources":[{"source_id":"H3S1","title":"ICH E6(R3) Guideline: Good Clinical Practice","publisher":"International Council for Harmonisation","url":"https://database.ich.org/sites/default/files/ICH_E6%28R3%29_DraftGuideline_2023_0519.pdf","source_class":"STANDARD","claims_supported":["Human-participant trials may use adaptive designs, but adaptability should remain within protocol provisions and must not undermine participant safety or scientific validity.","Protocols should specify procedures, stages, stopping rules, and discontinuation criteria.","Computerized trial systems should be fit for purpose and critical quality factors should be addressed in their design or adaptation."]},{"source_id":"H3S2","title":"Coding Guidelines for REDCap Library Curated Forms and Instruments","publisher":"REDCap Consortium","url":"https://projectredcap.org/wp-content/resources/redcap_library_coding_guidelines.pdf","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","claims_supported":["Research instruments are already represented electronically with conditional branching logic.","The guidance exposes cases where branching across separate forms is not applicable, demonstrating a practical boundary on the executable representation."]},{"source_id":"H3S3","title":"Model Checking for Clinical Guidelines: an Agent-based Approach","publisher":"American Medical Informatics Association","url":"https://pmc.ncbi.nlm.nih.gov/articles/PMC1839493/","source_class":"PRIMARY_RESEARCH","claims_supported":["Clinical guidelines have been translated from a formal protocol representation into Promela and checked with SPIN.","Temporal properties are verified against a model describing possible system evolutions.","The work treats clinical guidelines as protocol-like workflows suitable for model checking."]},{"source_id":"H3S4","title":"Model Checking for Verification of Interactive Health IT Systems","publisher":"Journal of Biomedical Informatics","url":"https://pmc.ncbi.nlm.nih.gov/articles/PMC4765626/","source_class":"PRIMARY_RESEARCH","claims_supported":["Finite-state model checking has been applied to healthcare workflows and interactive systems.","The method targets safety-relevant behavior beyond testing selected traces.","Formal workflow models can reveal problematic interactions in safety-critical human-machine systems."]}],"closest_analogue":"Finite-state model checking of executable clinical guidelines, combined with REDCap-style branching research instruments and ICH-bounded adaptive protocols.","overlap":"All principal technical components exist separately: executable branching instruments, protocol-defined adaptive boundaries, finite workflow representations, temporal safety properties, and exhaustive model checking rather than example-trace testing.","remaining_difference":"The opened sources do not show a qualitative-fieldwork authoring language that jointly encodes consent withdrawal, distress escalation, forbidden prompts, and observation boundaries, mechanically rejects unrestricted extensions, and presents expressiveness loss to an ethics reviewer. This can be tested by determining whether such properties cover real adaptive fieldwork protocols without forcing common, ethically necessary discretion out of the accepted fragment.","classification":"POSSIBLE_DISTINCTION","disposition":"ADVANCE","rationale":"The computation technique is established, so domain transfer alone is not novel; however, the ethics-property vocabulary, enforceable extension quarantine, and measured expressiveness tradeoff form a specific unresolved implementation distinction."},{"hypothesis_id":"H4","search_queries":["qualitative data analysis provenance scripts consent metadata automated checking plugins","research data workflow consent policy enforcement provenance static analysis transformations","workflow provenance policy compliance verification data transformations model checking","NVivo plugin scripts provenance consent restrictions qualitative data export"],"sources":[{"source_id":"H4S1","title":"Constraints of the Provenance Data Model","publisher":"World Wide Web Consortium","url":"https://www.w3.org/2012/10/prov-constraints","source_class":"STANDARD","claims_supported":["W3C PROV defines normalization, validity, equivalence, inferences, and constraint checking for provenance documents.","Constraint violations can be detected by checking forbidden patterns.","The specification provides a terminating normalization argument for its bounded formal problem rather than a guarantee about arbitrary transformation programs."]},{"source_id":"H4S2","title":"Formal Policy-based Provenance Audit","publisher":"Springer / IWSEC","url":"https://amphawa.eu/data/iwsec-paper.pdf","source_class":"PRIMARY_RESEARCH","claims_supported":["A formal framework checks provenance-record correctness and compliance with machine-readable usage policies.","The modeled policies include deletion, forwarding, linking, derivation, export, and authorized purposes for sensitive data.","The authors explicitly note that some purposes are not fully automatable and require complementary manual verification."]},{"source_id":"H4S3","title":"Policy Enforcement Overview","publisher":"Adobe","url":"https://experienceleague.adobe.com/en/docs/experience-platform/data-governance/enforcement/overview","source_class":"COMMERCIAL_FIRST_PARTY","claims_supported":["A deployed platform already combines data lineage, classification, and policy rules to evaluate and surface prohibited data operations.","Policy checks can be automatic or exposed through an API before an application performs an action."]},{"source_id":"H4S4","title":"Trust & Provenance for AI-Assisted Qualitative Coding","publisher":"OpenVerbatim","url":"https://openverbatim.com/trust/","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","claims_supported":["A qualitative-analysis platform records append-only adjudication events and distinguishes suggested from reviewed coding states.","Participant withdrawal triggers cascading deletion with a retained audit event.","Public sharing requires row-level masking, removal, or consent confirmation and exposes only whitelisted fields."]}],"closest_analogue":"Formal policy-based provenance audit, paired with lineage-aware policy enforcement systems and OpenVerbatim's qualitative consent, deletion, and sharing controls.","overlap":"Existing work already formalizes provenance and privacy-policy compliance over derivation and export events, automatically blocks labeled operations, retains audit trails, and routes nonautomatable judgments to human verification. Qualitative-specific consent and context controls also exist in a first-party platform.","remaining_difference":"The sources check formal provenance records or governed operations, not the universal semantic behavior of arbitrary user-supplied transformation programs. The remaining test is whether a qualitative pipeline can prove and clearly document that unrestricted exact verification is unavailable, then enforce guarantee-labeled routing among a verified DSL, sound abstraction, bounded testing, and escalation without granting exact-safe status to unrestricted code.","classification":"POSSIBLE_DISTINCTION","disposition":"ADVANCE","rationale":"There is substantial adjacent prior art, but the explicit unrestricted-program boundary and guarantee-preserving multi-mode router are not collapsed by the opened provenance-audit and policy-enforcement analogues."},{"hypothesis_id":"H5","search_queries":["AI assisted qualitative coding model card version changes revalidation human review audit guarantee","qualitative coding AI assurance record model codebook change validation","NIST AI RMF change management re-evaluation model updates human oversight documentation","ISO 42001 AI system impact assessment changes revalidation human oversight"],"sources":[{"source_id":"H5S1","title":"AI Risk Management Framework Core","publisher":"National Institute of Standards and Technology","url":"https://airc.nist.gov/airmf-resources/airmf/5-sec-core/","source_class":"GOVERNMENT_OR_REGULATOR","claims_supported":["AI risk management should be continuous across the system lifecycle with ongoing monitoring and periodic review.","The framework requires documentation of intended scope, knowledge limits, human oversight, operator competence, unmeasurable risks, uncertainty, third-party components, and residual risk.","Systems should be tested before deployment and regularly in operation, with context and capability changes prompting renewed mapping and measurement."]},{"source_id":"H5S2","title":"ISO/IEC 42001:2023 — Artificial intelligence management systems","publisher":"International Organization for Standardization","url":"https://www.iso.org/standard/42001","source_class":"STANDARD","claims_supported":["ISO/IEC 42001 requires establishing, maintaining, and continually improving an AI management system.","The standard covers lifecycle governance, risk treatment, traceability, transparency, reliability, and continuous learning.","Its Plan-Do-Check-Act structure is intended to govern changing AI systems across organizations."]},{"source_id":"H5S3","title":"Model Cards for Model Reporting","publisher":"Google Research","url":"https://research.google/pubs/model-cards-for-model-reporting/","source_class":"PRIMARY_RESEARCH","claims_supported":["Model cards document intended uses, unsuitable contexts, evaluation procedures, and performance under relevant conditions.","The framework provides a scoped public record accompanying a released model."]},{"source_id":"H5S4","title":"Trust & Provenance for AI-Assisted Qualitative Coding","publisher":"OpenVerbatim","url":"https://openverbatim.com/trust/","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","claims_supported":["A qualitative-coding platform already distinguishes machine suggestions from human-confirmed decisions.","Human adjudications are retained in an append-only audit trail.","Withdrawal, methods disclosure, and public sharing are handled as distinct governed workflows rather than one generic human-review claim."]}],"closest_analogue":"NIST AI RMF lifecycle documentation and re-evaluation, reinforced by ISO/IEC 42001 continual-improvement controls and model-card reporting.","overlap":"The authoritative frameworks already call for version-relevant scope and limitation records, continuous monitoring, periodic reassessment, documented human-AI roles and competencies, tracking of third-party components, uncertainty and residual risks, and re-evaluation when context, capabilities, or performance change. Model cards supply the release-facing record form, while qualitative software already records human adjudication provenance.","remaining_difference":"A specialized record could add computability-status terminology and explicit service-level fields for reviewer latency, refusal, and escalation capacity, but these are refinements within an established lifecycle assurance and human-oversight record rather than a distinct causal intervention.","classification":"OBVIOUS_COLLISION","disposition":"REJECT","rationale":"The hypothesis substantially restates current AI lifecycle governance and reporting requirements for a qualitative-coding use case; its additional fields do not survive this shallow screen as a material structural distinction."}],"nominated_ids":["H1","H3","H4"],"replenishment_recommended":false}