{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp04_retrieval_first_paired20_20260802","cell_id":"layer_decay_and_expiration_management__aviation_aeronautics","arm":"RETRIEVAL_FIRST","candidate_id":"C-H2-DEPENDENCY-GATED-SIM-ARCHIVE-V0","hypothesis_id":"H2","version":0,"title":"Dependency-Gated Lifecycle for Certification-Linked CFD Bundles","problem":"Aerodynamic simulation programs accumulate provenance-linked CAD, meshes, solver inputs, states, results, and reports after design iterations close. Keeping every bundle on active storage is burdensome, but cleanup based only on age or access can remove an input or environment needed to reproduce a result cited in certification or anomaly analysis.","actors":["Aerodynamics engineers who create and reuse simulation bundles","Certification engineers who identify analyses cited as substantiation evidence","Simulation-data or SPDM administrators who maintain provenance and bundle identity","Storage operators who execute approved tier transitions and quarantine actions","Certification-record custodians who apply preservation requirements and holds"],"observable_state":"For each provenance-linked simulation artifact bundle, the pilot inventory exposes identity, creation and last-access times, size, artifact classes, provenance roots, derived outputs, inbound references from cited results or active workflows, regeneration status and estimated cost, certification-record or preservation-hold status, current hot/warm/cold state, quarantine status, and sampled restore outcome. Aggregate observables are hot-storage volume, percentage of bundles with resolved dependencies, blocked disposition attempts, restore latency, and the percentage of sampled cited runs reproduced to the pilot's predeclared checksum or result-comparison criterion.","consequence":"Without a governed lifecycle, low-use derived artifacts remain on expensive active storage indefinitely, while indiscriminate deletion can sever lineage and prevent later reconstruction of consequential aerodynamic analyses.","affected_objective":"Reduce the active-storage burden of completed aerodynamic simulation work while preserving timely, auditable reproducibility of certification-linked analyses.","intervention":"Run a bounded lifecycle pilot over a defined set of closed CFD projects. Resolve artifacts into provenance-linked bundles; apply certification and preservation overrides; rank only eligible bundles using age, access, size, graph position, and regeneration cost; trace live inbound dependencies before any disposition; demote approved bundles through hot, warm, and cold tiers; place deletion candidates in a recoverable, audited quarantine rather than destroying them; and periodically restore a stratified sample of archived cited runs end to end. Treat scores as ranking inputs, any unresolved or live dependency as a disposition block, and restore failures as reasons to halt further transitions and repair the archive path.","structural_mapping":[{"archetype_element":"Accumulated temporal layers","domain_realization":"Successive CFD artifact bundles containing geometry, meshes, solver inputs and states, derived fields, figures, and reports."},{"archetype_element":"Layer inventory and identity map","domain_realization":"A bundle registry connecting each artifact to its simulation run, provenance roots, derived outputs, cited result, owner, and current lifecycle state."},{"archetype_element":"Age, value, and decay signals","domain_realization":"Bundle age and access are combined with size, graph position, regeneration status, and reproduction cost to rank eligible bundles without treating age as an automatic deletion rule."},{"archetype_element":"Dependency and reconstruction check","domain_realization":"Inbound references from certification evidence, active workflows, downstream results, and reconstruction paths are traced; any live or unresolved reference blocks deletion."},{"archetype_element":"Retention and preservation exceptions","domain_realization":"Certification records, non-regenerable roots, active investigations, and named holds remain protected irrespective of rank until the responsible custodian releases them."},{"archetype_element":"Differentiated disposition pathway","domain_realization":"Bundles may remain hot, move to warm or cold archive, be compacted where fidelity is preserved, enter quarantine, or remain protected by exception."},{"archetype_element":"Deletion audit and rollback window","domain_realization":"A proposed deletion first hides the bundle from ordinary use while retaining recoverable bytes and recording who approved it, why, and when the quarantine expires."},{"archetype_element":"Review and revalidation loop","domain_realization":"Scheduled end-to-end restores test retrieval, readability, reconnection to the recorded environment, and reproduction of sampled cited outputs before the lifecycle policy expands."}],"mechanism_mapping":[{"mechanism_slug":"age_weighted_value_score","role":"Ranks otherwise eligible bundles for review using aging plus access, size, graph position, and regeneration cost; it does not authorize movement or deletion.","counterfactual_removal":"Without ranking, reviewers must inspect bundles ad hoc, so low-value hot-storage candidates are harder to prioritize and cleanup is less repeatable."},{"mechanism_slug":"dependency_safe_delete_check","role":"Acts as a hard pre-disposition gate by tracing live inbound references and protecting certification evidence, non-regenerable roots, and unresolved reconstruction paths.","counterfactual_removal":"Without the gate, an old or low-ranked input could be removed even though a cited result or downstream artifact still depends on it."},{"mechanism_slug":"lifecycle_storage_tiering_policy","role":"Moves approved bundles from hot to warm or cold storage as use cools, reducing active-storage demand without equating expiration with destruction.","counterfactual_removal":"Without tiering, the workflow retains bundles hot or proceeds directly toward deletion, losing the lower-risk middle path of cheaper recoverable storage."},{"mechanism_slug":"soft_delete_quarantine_window","role":"Makes an approved deletion reversible for a predeclared period and records the decision before any permanent destruction is considered.","counterfactual_removal":"Without quarantine, a classification, dependency-map, or operator error can become immediately irreversible."},{"mechanism_slug":"archive_restore_test","role":"Exercises retrieval, parsing, environment reconnection, and result reproduction on sampled archived cited runs, measuring both fidelity and restore time.","counterfactual_removal":"Without restore drills, successful archival is inferred from metadata or transfer completion, and an unreadable or unreconstructable archive may remain undetected until urgently needed."}],"causal_chain":["Completed CFD iterations create growing provenance-linked artifact bundles whose active value and reconstruction importance diverge over time.","The inventory makes bundle identity, age, access, provenance, citation status, and lifecycle state inspectable.","Preservation overrides and the inbound-dependency gate remove certification-linked, non-regenerable, actively referenced, or unresolved bundles from automated disposition.","Value ranking prioritizes the remaining candidates for accountable human review instead of deciding deletion by age alone.","Approved tier transitions move infrequently used but recoverable bundles off hot storage while retaining lineage and audit metadata.","Deletion candidates enter reversible quarantine, allowing mistaken classifications or missed uses to be restored before any irreversible action.","Sampled end-to-end restores reveal whether archived cited runs remain readable, reconnectable, and reproducible within the specified restore time.","If the gates and restore tests perform as intended, hot-storage volume falls without a corresponding loss of reconstructability; failures halt expansion and trigger correction."],"baseline":"The relevant baseline is the existing choice between retaining completed simulation artifacts on active storage and performing ad hoc age-, project-, or capacity-based cleanup. Existing SPDM practice already provides centralized traceability and version history; AWS CFD guidance already provides hot/warm/cold lifecycle transitions; PRUNE already provides provenance-graph-aware eviction and regeneration; and FAA guidance already imposes preservation and retrievability constraints. The candidate therefore tests only whether adding the specified closed-loop combination in one certification-linked workflow improves the measured storage/reproducibility trade-off.","nearest_rivals":["PRUNE preserving run environment: already combines workflow dependency graphs, regenerable-versus-irreplaceable classification, multi-factor eviction priorities, retained metadata, and validated regeneration.","Airbus Helicopters SPDM and commercial simulation-data management practice: already centralize simulation inputs and results, version and approval history, repeatability, and certification-oriented traceability.","AWS CFD hot-warm-cold lifecycle: already moves completed CAD, mesh, input, and output data from active compute storage into object and archival tiers through lifecycle rules.","FAA AC 20-179 certification-data retention practice: already requires protected certification records to remain stored, readable, accessible, backed up, and retrievable across legacy-media changes."],"remaining_contrastive_claim":"The bounded residual claim is that one aerospace-certification workflow can combine value-ranked bundle aging, a hard inbound-dependency disposition gate, reversible deletion quarantine, and scheduled end-to-end restore tests to reduce hot CFD storage by at least 40% while at least 95% of sampled cited runs remain reproducible within a specified restore time.","authority_safety":{"decision_authority":"The simulation-data owner may propose rankings and tier transitions; the certification-record custodian determines preservation or hold status; and movement into quarantine requires joint approval from the accountable engineering owner and data custodian. Storage operators may execute only approved state changes. Permanent destruction remains outside the pilot and requires the organization's existing records and certification authority.","authorized_first_step":"Create a read-only inventory and dependency graph for a bounded set of completed CFD projects, declare the reproduction comparison and restore-time target, classify holds with the certification-record custodian, and dry-run rankings and restore procedures on copies without changing live artifact states.","excluded_actions":["Automatic deletion based solely on age, access frequency, rank, or storage pressure","Movement or deletion of certification records, non-regenerable roots, held evidence, active-project artifacts, or bundles with unresolved dependencies","Permanent destruction during the first evidence step","Changing simulation inputs, recorded environments, lineage, approval history, or cited results","Treating a successful file retrieval or checksum alone as proof that a cited run is reproducible","Allowing a composite score to override a dependency block or preservation decision","Applying the pilot to operational flight systems or making flight-safety decisions from its rankings"],"halt_rollback":"Halt new transitions if any protected artifact is misclassified, any dependency cannot be resolved, a quarantined bundle is requested unexpectedly, or sampled restore fidelity or timing misses the predeclared criterion. Restore quarantined or demoted bundles to their prior lifecycle state from retained copies, preserve the audit record, correct the inventory or procedure, and require renewed joint approval before resuming."},"negative_tests":{"strongest_counterevidence":"PRUNE already demonstrates the closest technical combination: provenance graphs, multi-factor eviction ranking, protection of roots, deletion of regenerable derived files, retained metadata, and validated regeneration. SPDM, CFD storage tiering, and certification-retention practice separately cover most other elements, so the proposal has only a narrow residual distinction unless the quarantine-and-recurring-restore loop produces the claimed measured trade-off in a certification-linked workflow.","problem_falsifier":"The problem is falsified for the pilot population if completed CFD bundles occupy no material hot-storage capacity, are already fully classified and tiered, and audits show that existing cleanup has not impaired reconstruction or created unresolved retention risk.","intervention_falsifier":"The intervention is falsified if the bounded pilot cannot reduce hot storage by at least 40% while at least 95% of the sampled cited runs meet the predeclared reproduction criterion within the specified restore time, or if dependency mapping and preservation review leave too few eligible bundles for the closed loop to affect storage materially.","risks":["Incomplete dependency discovery can falsely label a load-bearing artifact as disposable.","A composite value score can create false precision or encode disputed weights.","Tiering can impose unacceptable retrieval delay or cost when an archived run is suddenly needed.","Archived formats, solver versions, credentials, or execution environments may become unreadable or unusable despite intact files.","Quarantine retains data and may conflict with a requirement for immediate destruction outside this pilot.","Restore sampling may miss failing artifact classes, age bands, or environments.","Certification holds can become hidden permanent exceptions if they are not revalidated.","The lifecycle's metadata, quarantines, and copies can themselves accumulate and erode expected storage savings."]},"next_evidence_step":"Conduct a non-destructive retrospective pilot on one bounded collection of closed CFD projects: inventory bundle size and hot-storage residency; resolve provenance and certification references; have the custodian classify holds; predeclare the cited-run sample across artifact and age bands, the reproduction comparison, and the restore-time limit; dry-run the ranking and dependency gate; copy eligible bundles into the proposed archive path; and perform end-to-end restores. Estimate the hot-storage reduction that approved demotions would produce and report the fraction and timing of successfully reproduced cited runs. Do not alter live storage or permanently delete artifacts; proceed to a reversible live pilot only if the dependency review is complete and the predeclared 40%/95% criteria are met.","prior_art_status":"SEARCHED_BOUNDED","revision_record":{"parent_version":null,"progress_targets_addressed":[],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}