{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp04_retrieval_first_paired20_20260802","cell_id":"layer_decay_and_expiration_management__logistics_supply_chain","arm":"RETRIEVAL_FIRST","candidate_id":"H5-C0","hypothesis_id":"H5","version":0,"title":"Renewable, Dependency-Gated Expiry for Planning Overrides","problem":"Manual forecast, safety-stock, and allocation overrides can remain active after the disruption or planning condition that justified them has ended, allowing an unreviewed legacy override at the SKU-location-period level to continue shaping later planning runs and replenishment releases.","actors":["Demand planners who create or own overrides","Supply planners who review replenishment effects","Allocation planners who manage customer commitments","Planning-system administrators who configure lifecycle controls","Planning governance or operations leads who authorize policy changes","Downstream customers affected by inventory and allocation decisions"],"observable_state":"For each planning override × SKU-location-period, the planning system can expose its owner, creation time, expiry time, current rationale and supporting evidence, renewal history, lifecycle state, affected planning outputs, and any live committed-order or allocation dependency that would block deactivation.","consequence":"Overrides lacking a current rationale can silently distort forecasts, safety stock, orders, inventory, or customer allocation, while indiscriminate expiry can remove beneficial adjustments or disrupt commitments that still depend on them.","affected_objective":"Reduce active planning overrides that lack a current operational rationale without increasing service failures attributable to override expiry, while preserving accountable recovery and continuity for dependent commitments.","intervention":"At override creation, assign a bounded lease and named owner. Before lease expiry, require that owner to submit fresh evidence and an updated rationale for renewal. At expiry, check the override against live committed-order and allocation dependencies; block and escalate expiry when a dependency exists or cannot be resolved. Otherwise deactivate the override, fall back to the regenerated or base planning value, and retain the prior override in a time-bounded, access-controlled quarantine from which an authorized planner can restore it before permanent removal. Record creation, renewal, blocking, deactivation, restoration, and final disposition events.","structural_mapping":[{"archetype_element":"Accumulated temporal layers","domain_realization":"Successive manual forecast, safety-stock, and allocation overrides attached to planning runs at the SKU-location-period level."},{"archetype_element":"Age and expiration trigger","domain_realization":"A creation-time lease gives each override an explicit expiry timestamp instead of indefinite cross-cycle persistence."},{"archetype_element":"Revalidation loop","domain_realization":"Continuation requires affirmative renewal by the named owner with fresh evidence and an updated rationale."},{"archetype_element":"Dependency and reconstruction check","domain_realization":"Expiry is blocked when a live committed order or allocation still relies on the override, or when dependency status is unresolved."},{"archetype_element":"Differentiated disposition path","domain_realization":"An override may be renewed, temporarily blocked and escalated, deactivated into quarantine, restored, or permanently removed after the quarantine window."},{"archetype_element":"Reversible cleanup and auditability","domain_realization":"Deactivated override values and their histories remain recoverable during quarantine, while lifecycle decisions are recorded separately."},{"archetype_element":"Preservation exception","domain_realization":"A documented live-commitment dependency temporarily preserves the override but does not silently convert it into a permanent hold."}],"mechanism_mapping":[{"mechanism_slug":"time_to_live_ttl_policy","role":"Stamps each override with a bounded lease at creation and makes continued activation contingent on an explicit, evidence-backed renewal rather than passive persistence.","counterfactual_removal":"Without the TTL mechanism, overrides can remain active across planning cycles by default, so owner renewal never becomes a required decision point."},{"mechanism_slug":"dependency_safe_delete_check","role":"Gates deactivation by inspecting live committed-order and allocation dependencies and blocks expiry when removal could disrupt an active commitment.","counterfactual_removal":"Without the dependency gate, a correctly timed expiry could still break a downstream commitment, making blanket expiration unsafe."},{"mechanism_slug":"soft_delete_quarantine_window","role":"Separates deactivation from permanent removal so an authorized planner can restore an expired override when an error or previously unseen dependency appears.","counterfactual_removal":"Without quarantine, expiry becomes immediately irreversible, increasing the operational harm of mistaken deactivation and reducing willingness to use expiry at all."}],"causal_chain":["A planner creates an override with a named owner, rationale, evidence, scope, and expiry timestamp.","The lease makes the override's continued authority time-bounded rather than persistent by default.","Before expiry, the owner must either provide fresh evidence and renew the lease or allow it to lapse.","A dependency check tests whether committed orders or allocations still rely on the override.","Overrides with live or unresolved dependencies are blocked from deactivation and escalated for review.","Eligible expired overrides are removed from active planning and the system falls back to the regenerated or base value.","The expired value and lifecycle record enter a recoverable quarantine rather than immediate destruction.","Overrides shown to be necessary can be restored during the window; the remainder become eligible for authorized final disposition.","Fewer rationale-less overrides remain active, reducing policy residue and planning distortion while dependency gating and recovery limit expiry-attributable service failures."],"baseline":"The baseline is existing periodic manual review or plan-level retention behavior: overrides may carry dates, reasons, attribution, or selective overwrite settings, but can persist into later planning runs without mandatory evidence-based owner renewal, an automated live-commitment expiry gate, and a recoverable post-expiry quarantine operating as one linked workflow.","nearest_rivals":["AWS Supply Chain Demand Planning override lifecycle: supports start and end dates, reasons, actor attribution, history, time-period scope, retained overrides across cycles, and visible hierarchical effects, but the supplied documentation does not establish all three linked controls in the residual claim.","Oracle Service Parts Planning manual-override retention controls: retains, ignores, or time-fence-limits overrides on later plan runs and can propagate retained changes into replenishment, but uses plan-level overwrite behavior rather than the proposed per-override renewable lease workflow.","Validity-bounded scenario override snapshot chains in EP 4528530 A1: represent overrides through versioned snapshots and validity periods with fallback and dependent-value propagation, but address scenario representation rather than the proposed accountable operational-expiry workflow."],"remaining_contrastive_claim":"The bounded-search distinction is a default-expiring planning-override lease whose continuation requires fresh evidence from a named owner, whose expiry is blocked by live committed-order or allocation dependencies, and whose expired value is quarantined for reversible recovery before permanent removal.","authority_safety":{"decision_authority":"Planning governance and the accountable demand, supply, or allocation process owner may approve lease rules and any production pilot; named override owners may request renewal or restoration, but system administrators may not infer business justification or authorize permanent removal on their behalf.","authorized_first_step":"Run a read-only retrospective inventory and shadow simulation on a bounded sample of historical overrides; calculate which overrides would have reached expiry, requested renewal, encountered a visible commitment dependency, or entered quarantine, without changing forecasts, orders, allocations, or production override states.","excluded_actions":["Autonomously deactivate or delete production overrides during the first evidence step","Change released purchase orders, replenishment orders, customer allocations, or committed-order dates","Treat missing dependency data as proof that no dependency exists","Renew an override without a named owner, fresh evidence, and an updated rationale","Permanently remove quarantined values or audit records without separately authorized disposition rules","Use forecast accuracy alone to judge treatment value while ignoring service and operational outcomes","Apply one lease duration indiscriminately to every override class before evidence review"],"halt_rollback":"Halt the shadow study if override identity, owner attribution, rationale, expiry, or commitment-dependency data cannot be resolved reliably, or if simulated expiries show plausible service-critical dependencies that the gate misses. Because the first step is read-only, rollback consists of discarding simulated lifecycle labels and leaving all production overrides and planning outputs unchanged; any later live pilot must support immediate restoration from quarantine and suspension of further expiries."},"negative_tests":{"strongest_counterevidence":"The strongest supplied counterevidence is that overrides are not uniformly harmful: a large-scale field experiment reported an average profitability gain from forecast-input overrides in one spare-parts setting, with value varying by SKU margin, lifecycle, and supplier size. This makes blanket expiration or evaluation by forecast accuracy alone inappropriate.","problem_falsifier":"The problem would be falsified for the sampled workflow if a complete inventory shows that materially all active overrides already have current rationales and accountable owners, cease when their justifying conditions end, and do not produce measurable downstream planning or allocation distortion.","intervention_falsifier":"The intervention would be falsified if a controlled operational trial shows that the linked lease, renewal, dependency-gating, and quarantine controls do not reduce active overrides lacking a current rationale, or increase service failures attributable to expired overrides. The remaining contrastive claim would also be falsified by a preexisting product manual, patent, standard, or documented deployment showing all three linked controls: mandatory evidence-based owner renewal, automated dependency gating against live commitments, and recoverable post-expiry quarantine.","risks":["A lease may expire a beneficial override whose value is not captured by the renewal evidence template.","Incomplete dependency visibility may classify a load-bearing override as safe to deactivate.","Owners may rubber-stamp renewals, converting expiry into administrative churn without reducing policy residue.","Quarantine may retain sensitive or obsolete planning data longer than an applicable disposition rule permits.","Fallback to a regenerated or base value may itself be unsuitable during an unresolved disruption.","Renewal reminders and review work may create planner burden or shift overrides into less visible channels.","A fixed lease rule may perform unevenly across SKU, lifecycle, supplier, and demand contexts.","Restoration after downstream releases may not fully reverse consequences already introduced by a mistaken expiry."]},"next_evidence_step":"Conduct a time-bounded read-only retrospective plus shadow replay over one planning cycle for a capped, stratified sample of forecast, safety-stock, and allocation overrides. Record owner and rationale completeness, age, renewal evidence availability, visible committed-order or allocation dependencies, simulated disposition, and disagreements found by planner review. Compare the shadow workflow with the existing review process on the proportion of active overrides lacking a current rationale and count plausible expiry-attributable service hazards. Do not deactivate anything; use the results only to decide whether a small reversible live pilot is justified.","prior_art_status":"SEARCHED_BOUNDED","revision_record":{"parent_version":null,"progress_targets_addressed":[],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}