{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp04_retrieval_first_paired20_20260802","cell_id":"computability_boundary_mapping__ethnography_qualitative_methods","arm":"RETRIEVAL_FIRST","round_index":0,"hypotheses":[{"hypothesis_id":"H1","title":"Honest saturation states for theoretical sampling","problem":"Software may claim that no future admissible case can alter an emerging theory, although only a finite sample has been examined.","affected_stakeholder":"Grounded-theory researchers and populations affected by prematurely stabilized findings.","workflow_boundary":"After each coding round and before recruitment stops.","failure_mode":"A run with no new codes, low yield, or exhausted search time is reported as universal saturation rather than bounded evidence or unknown.","unit_of_analysis":"One study-specific stopping decision at one sampling round.","causal_lever":"Replace binary saturation with witnessed novelty, exhaustion of an enforceably finite frame, or explicit unknown; retain a declared search bound.","archetype_mapping":"Treat saturation as a class-wide guarantee only when the eligible case universe is finite and enumerable; otherwise expose bounded evidence without generalizing beyond it.","expected_value":"Could reduce premature closure and make the evidentiary scope of stopping decisions auditable.","falsifiable_claim":"Against ordinary saturation dashboards, the three-state protocol will produce fewer false saturation calls in studies seeded with late negative cases while still certifying exhausted finite frames.","diversity_rationale":"Targets sampling termination, with a study-round unit and an explicit-unknown lever rather than privacy, protocol verification, software analysis, or governance.","mechanism_slugs":["bounded_domain_exhaustive_search","semi_decision_with_explicit_unknown","computability_boundary_decision_record"],"search_questions":["Do qualitative-research tools already distinguish bounded code saturation from universal theoretical saturation?","How are saturation claims validated against deliberately delayed negative cases?","Which sampling frames are sufficiently finite and enforceable for exhaustive checking?"]},{"hypothesis_id":"H2","title":"Threat-model-bounded fieldnote de-identification","problem":"A release may be labeled non-reidentifiable against any present or future auxiliary information, although the external linkage capability is unbounded and unstated.","affected_stakeholder":"Research participants, archive custodians, and data-sharing committees.","workflow_boundary":"Between redaction of field materials and external deposit or sharing.","failure_mode":"Passing a fixed attack suite becomes a universal anonymity guarantee; threats outside the tested model are silently treated as safe.","unit_of_analysis":"A proposed data release paired with a declared adversary and auxiliary-information model.","causal_lever":"Enforce a threat-model promise, exhaustively test a finite linkage space, and route violations or unmatched threats to withholding, stronger transformation, or review.","archetype_mapping":"Classify privacy only relative to declared computational and informational capabilities; bounded success must not inherit an unrestricted guarantee.","expected_value":"Could preserve useful sharing while reducing false assurances about participant protection.","falsifiable_claim":"In releases containing seeded linkage attacks, the bounded-threat contract will classify covered, uncovered, and unresolved risks more accurately than a binary anonymized/not-anonymized review.","diversity_rationale":"Targets archival release and participant risk, using a release–adversary pair and enforced promise rather than a sampling or software-verification unit.","mechanism_slugs":["promise_problem_restriction","bounded_domain_exhaustive_search","fallback_mode_router"],"search_questions":["Which qualitative archives state explicit auxiliary-information or adversary bounds?","What reidentification tests are used for ethnographic fieldnotes and multimedia?","How often do release interfaces distinguish passed tests from protection against unmodeled linkage?"]},{"hypothesis_id":"H3","title":"Decidable safety fragment for adaptive fieldwork protocols","problem":"Reviewers may be asked to guarantee that an arbitrarily extensible, data-dependent interview or observation script can never enter a prohibited state.","affected_stakeholder":"Research participants, field researchers, and ethics reviewers.","workflow_boundary":"From executable protocol authoring through ethics approval, before field deployment.","failure_mode":"Passing example traces is treated as proof of safety for every interaction; plugins or unrestricted loops silently invalidate the guarantee.","unit_of_analysis":"One version of an executable adaptive fieldwork protocol.","causal_lever":"Constrain guaranteed protocols to a mechanically enforced finite-state language, model-check safety properties, and quarantine unrestricted extensions.","archetype_mapping":"Redraw the universal verification problem into a decidable language fragment with an exact termination guarantee and an explicit out-of-scope state.","expected_value":"Could give reviewers stronger assurance for supported protocols while making lost expressiveness visible.","falsifiable_claim":"On a benchmark of protocols with seeded reachable violations, the restricted checker will find every violation inside its formal model and will never certify an out-of-fragment protocol as universally safe.","diversity_rationale":"Targets pre-field ethics approval, with an executable-protocol unit and syntactic restriction plus model checking rather than bounded sampling or disclosure review.","mechanism_slugs":["language_fragment_restriction","abstract_interpretation_or_model_checking","constructive_algorithm_and_correctness_proof"],"search_questions":["Are adaptive interview or fieldwork protocols currently represented as executable workflows?","Which ethics properties can be expressed over finite protocol states without losing field-relevant behavior?","Do existing protocol simulators distinguish trace testing from exhaustive verification?"]},{"hypothesis_id":"H4","title":"Boundary-aware checking of qualitative transformation scripts","problem":"A universal analyzer may be expected to prove that arbitrary transcription, coding, redaction, or export scripts always preserve provenance, consent restrictions, and contextual links.","affected_stakeholder":"Qualitative data stewards, analysts, participants, and downstream reusers.","workflow_boundary":"Before installing or running a custom transformation in the analytic pipeline.","failure_mode":"Testing selected files or timing out is converted into a universal safe/unsafe verdict for arbitrary program behavior.","unit_of_analysis":"A transformation program together with its artifact and metadata schema.","causal_lever":"Establish the unrestricted verification boundary, then route scripts to a verified DSL, sound finite abstraction, bounded test, or human escalation with guarantee labels.","archetype_mapping":"Separate an impossibility result for unrestricted semantic behavior from decidable restricted implementations, and independently check the reduction before relying on it.","expected_value":"Could prevent silent loss of consent or interpretive context without banning all custom transformations.","falsifiable_claim":"On transformation programs with seeded semantic and schema violations, the router will issue fewer false universal clearances than test-suite-only approval, while unrestricted programs receive no exact-safe label.","diversity_rationale":"Targets analytic infrastructure, with a program–schema unit and impossibility-plus-fallback routing rather than a research decision or governance record.","mechanism_slugs":["halting_problem_reduction","reduction_direction_checklist","abstract_interpretation_or_model_checking","fallback_mode_router"],"search_questions":["Do qualitative-data platforms claim invariant preservation across arbitrary plugins or scripts?","Which provenance and consent properties have sound static or model-based checks?","Has undecidability been formally established for the relevant transformation language and property?"]},{"hypothesis_id":"H5","title":"Recheckable guarantee records for AI-assisted coding","problem":"Claims about exact coding, termination, or human-backed resolution may persist after changes to models, codebooks, context limits, connectors, or escalation staffing.","affected_stakeholder":"Methods leads, research auditors, coders, participants, and users of qualitative findings.","workflow_boundary":"At each release or material configuration change of an AI-assisted coding pipeline.","failure_mode":"A previously bounded guarantee drifts into an unrestricted product claim; human review is treated as an infallible, always-available oracle.","unit_of_analysis":"One versioned coding pipeline and its published guarantee.","causal_lever":"Maintain a superseding boundary record naming scope, computation model, human capability, unknown behavior, evidence, and mandatory recheck triggers.","archetype_mapping":"Make solvability relative to the declared machine-and-human system, preserve status distinctions, and reclassify whenever expressive power or external capability changes.","expected_value":"Could reduce stale methodological claims and expose when operational changes invalidate prior assurances.","falsifiable_claim":"During seeded model, codebook, and staffing changes, teams using the boundary record will identify more invalidated guarantees before release and carry forward fewer unsupported claims than teams using ordinary model cards.","diversity_rationale":"Targets longitudinal release governance, with a versioned system-guarantee unit and reclassification trigger rather than instance-level checking.","mechanism_slugs":["computability_boundary_decision_record","proof_checking","turing_reduction_analysis","computational_complexity_analysis"],"search_questions":["What guarantee records accompany AI-assisted qualitative coding systems today?","Which system changes trigger renewed methodological validation in practice?","How are human escalation latency, competence, refusal, and accountability represented in existing assurance claims?"]}]}