{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp05_complete_proposal_portfolio20_20260803","cell_id":"computability_boundary_mapping__economics_finance","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"cbm-ef-oracle-relative-policy-model-passports-004","proposal_index":4,"version":0,"title":"Oracle-Relative Guarantee Passports for Macroeconomic Policy Models","problem":"A policy-analysis platform accepts executable models of households, firms, markets, and policy rules, then is asked to decide whether every admissible trajectory under a proposed rule terminates at a unique stable equilibrium satisfying a declared economic target. Model code may contain unbounded agent logic, continuous-state routines, external equilibrium solvers, live-data services, or human selection among solution branches. These capabilities are not represented in the computational guarantee, so an equilibrium chosen by an analyst or returned by an external service can be described as though the base platform computed a universal answer. Timeouts, solver abstentions, and unresolved branches can likewise be hidden behind one policy-ranking output.","actors":["Macroeconomic model developers","Economic-policy analysts","Policy-model validation function","Policy decision committee","Human equilibrium or branch-selection experts","External solver and data-service operators","Independent computational-methods reviewer"],"observable_state":"A model run reaches an unresolved equilibrium-search branch. An analyst supplies an initial condition, selects one candidate equilibrium, or invokes an external service, after which the platform reports that the policy model converged. The result record does not state whether the base program could have produced and verified that answer, what the external capability promised, what would happen if it abstained, or whether other branches remained open.","consequence":"A conditional or assisted model result can be treated as an unconditional computational guarantee, obscuring unresolved trajectories and making the policy comparison dependent on capabilities whose latency, correctness, refusal, and version changes are not governed.","affected_objective":"Traceable policy-model conclusions whose solvability status and economic guarantee remain explicitly relative to the computation model, external capabilities, promise conditions, and unresolved trajectories actually used.","intervention":"Require a capability-relative guarantee passport for every policy model before its convergence or equilibrium output is used in formal policy comparison. Freeze the model language, state and shock encoding, time domain, equilibrium definition, stability criterion, policy target, and exact quantifiers. Define a base computation model and register every equilibrium service, real-number routine, live-data source, certificate producer, interactive environment, and human selection step as a named oracle contract with inputs, outputs, promise conditions, latency, abstention, error, accountability, and version behavior. Use Turing-reduction analysis to state which policy query the base procedure can answer given which oracle, without promoting an oracle-relative result to unconditional decidability. For unrestricted agent scripts, separately attempt a checked reduction from a known undecidable source; until its mapping and assumptions are validated, retain UNRESOLVED rather than invoking a halting analogy. Test each oracle by withdrawal, abstention, invalid response, and promise violation. In parallel, fairly search executable trajectories for finite counterexamples to convergence or target attainment; a checked witness produces COUNTEREXAMPLE_FOUND, while a declared resource bound produces UNKNOWN rather than STABLE. Route results as BASE_CERTIFIED, ORACLE_RELATIVE, COUNTEREXAMPLE_FOUND, BOUNDED_ONLY, UNKNOWN, OUT_OF_MODEL, or SYSTEM_FAILURE. Publish bounded scenario maps when universal status is unavailable, and version-link every conclusion to its model, oracle, promises, evidence, and recheck triggers.","structural_mapping":[{"archetype_element":"Implicit computation model","domain_realization":"External solvers, live information, interactive environments, and human equilibrium choices silently add capabilities to the policy-model platform."},{"archetype_element":"Open-ended universal problem class","domain_realization":"The requested guarantee quantifies over arbitrary executable agent rules, initial states, shock sequences, and potentially unbounded trajectories."},{"archetype_element":"Model-relative solvability classification","domain_realization":"Each conclusion identifies what the base machine decides, what becomes decidable only with named oracles, and what remains unresolved."},{"archetype_element":"Promise and scope enforcement","domain_realization":"An external solver's result inherits its guarantee only when the model satisfies the solver's declared and checkable preconditions."},{"archetype_element":"Instance-level counterevidence","domain_realization":"One verified admissible trajectory that fails convergence or the economic target refutes the corresponding universal claim without deciding the entire class."},{"archetype_element":"Honest bounded fallback","domain_realization":"Finite-horizon scenario maps and bounded searches disclose their horizon and coverage and return UNKNOWN outside them."},{"archetype_element":"Traceable boundary maintenance","domain_realization":"Model, oracle, human role, promise, evidence, and guarantee versions are linked, and changes trigger reclassification."}],"mechanism_mapping":[{"mechanism_slug":"turing_reduction_analysis","role":"Represents equilibrium solvers, live information, interactive environments, and human selectors as explicit oracles and classifies which policy questions become solvable relative to each capability.","counterfactual_removal":"Without relative-computability analysis, an assisted answer could be reported as a result of the base algorithm, concealing the capability that made the computation possible."},{"mechanism_slug":"promise_problem_restriction","role":"States the preconditions under which an external solver or expert procedure owes a correct answer and requires those preconditions to be mechanically enforced or conservatively screened.","counterfactual_removal":"Without promise enforcement, out-of-contract model instances could receive authoritative-looking outputs even though the external capability owed them no guarantee."},{"mechanism_slug":"enumeration_and_dovetailing","role":"Fairly interleaves searches across encoded initial states, shock traces, execution branches, and candidate counterexamples so one divergent trajectory cannot starve all others.","counterfactual_removal":"Without fair scheduling, an early nonterminating model branch could prevent discovery of a finite admissible trajectory that already refutes the universal claim."},{"mechanism_slug":"semi_decision_with_explicit_unknown","role":"Places a declared resource or horizon bound around counterexample search and returns UNKNOWN when no witness has been found, never STABLE solely because the search ended.","counterfactual_removal":"Without an explicit unknown state, a finite stress horizon or timeout could be misread as proof of convergence or target attainment."},{"mechanism_slug":"proof_by_counterexample","role":"Validates one well-formed trajectory that cycles, diverges, reaches multiple admissible equilibria, or violates the declared target, thereby refuting the matching universal model claim.","counterfactual_removal":"Without counterexample validation, an adverse trajectory would remain a suggestive simulation rather than decisive evidence against the precise universal statement."},{"mechanism_slug":"proof_checking","role":"Independently verifies any constructive base-procedure proof, unrestricted-class reduction, counterexample witness, and formal correspondence between the model query and the economic claim.","counterfactual_removal":"Without checking, the passport could give durable authority to an incorrectly directed reduction, a defective witness, or a proof of a weaker formal statement."},{"mechanism_slug":"computability_boundary_decision_record","role":"Stores the base and oracle-relative classifications, promise conditions, open obligations, bounded fallback, human responsibilities, and triggers requiring re-evaluation.","counterfactual_removal":"Without a supersedable record, later changes to an external solver, data source, model language, or expert procedure could silently invalidate the conclusion while its original label remained in circulation."}],"causal_chain":["Formalizing the model language, economic target, equilibrium criterion, and universal quantifiers reveals the actual decision problem rather than treating numerical convergence as its definition.","Declaring a base computation model separates results produced internally from information or choices supplied by external services and people.","Turing-reduction analysis expresses assisted solvability as conditional on named capabilities instead of laundering it into an unconditional algorithmic guarantee.","Promise checks prevent an oracle result from being relied upon when its documented input conditions are absent or unenforceable.","Withdrawal and abstention tests expose which conclusions disappear, remain unresolved, or change when an external capability is unavailable.","Fair bounded search can produce checked countertrajectories while preserving UNKNOWN when no witness appears within the declared horizon.","The router presents BASE_CERTIFIED, ORACLE_RELATIVE, bounded, and unresolved outputs with different claims, so the policy committee can distinguish computation from assistance and scenario evidence from universality.","The passport records human choices and bounded scenario maps as assumptions or fallbacks rather than proofs of unique convergence.","Version and capability changes trigger reclassification before an earlier policy-model guarantee is reused."],"baseline":"Evaluation baseline: numerical convergence checks on selected initial conditions and shocks, economic review by model validators, and analyst intervention when equilibrium search stalls or yields multiple branches. External solver outputs and human choices are retained in working files, but the final policy-comparison result has no standard field distinguishing base-computable, externally assisted, bounded, and unresolved conclusions.","nearest_rivals":["Require every model to use one approved equilibrium solver and treat that solver's output as authoritative.","Increase simulation horizons, initial-condition coverage, and computing capacity without changing the universal convergence claim.","Use a committee of economists to select among equilibria and document the choice narratively.","Restrict the platform to a fixed finite-state model family with an exact solver.","Compare an ensemble of models and treat agreement as a substitute for a computation-model guarantee.","Remove all external services and human interventions, accepting failed or incomplete runs without classifying why they failed."],"remaining_contrastive_claim":"The intervention governs where the answer's computational power and information came from. A standard validation review assesses economic plausibility; larger simulations increase bounded coverage; a fixed model family regains decidability through restriction; and an expert committee supplies judgment. The passport instead makes each of those capabilities part of the formal guarantee, tests its withdrawal and failure modes, and prevents an oracle-relative or human-assisted conclusion from inheriting the base platform's authority.","authority_safety":{"decision_authority":"The relevant policy committee retains authority over policy choices. The model-governance function owns passport acceptance, external capability registration, and result-label rules; an independent reviewer must accept formal classifications before BASE_CERTIFIED or ORACLE_RELATIVE is used in a formal comparison.","authorized_first_step":"The director of model governance may authorize an offline pilot on synthetic policy models and stubbed oracle services, including scripted human-response cases, with no connection to live policy instruments, confidential economic feeds, public forecasts, or production decision materials.","excluded_actions":["Change an interest rate, tax, reserve, spending, lending, or market-intervention policy","Publish a pilot result as an official forecast or policy recommendation","Treat ORACLE_RELATIVE, BOUNDED_ONLY, UNKNOWN, OUT_OF_MODEL, or SYSTEM_FAILURE as BASE_CERTIFIED","Treat an oracle's abstention or a search timeout as evidence of equilibrium nonexistence or stability","Represent a human branch selection as a total algorithm or an independently verified equilibrium proof","Send confidential model data to an unapproved external capability","Reuse a passport after an unreviewed change to model semantics, oracle version, promise conditions, or human procedure"],"halt_rollback":"Halt the pilot if any undeclared external or human capability affects an output, an oracle-relative label is lost downstream, a BASE_CERTIFIED claim is contradicted by a checked in-model trajectory, promise violations are not detected, or formal and executable model semantics diverge. Withdraw the affected passports and return all pilot models to their prior unclassified validation status; the offline pilot changes no policy setting and requires no policy reversal."},"negative_tests":{"strongest_counterevidence":"The strongest counterevidence would be a checked specification showing that every admitted model is finite-state, all external routines are ordinary total computable subroutines with proved contracts, all human inputs are fixed parameters supplied before computation rather than adaptive decisions, and a constructive total procedure decides the declared convergence property. The remaining issues would concern complexity, empirical validity, and model choice rather than oracle-relative computability.","problem_falsifier":"The problem is falsified if the existing model-governance system already declares every external and human capability, enforces its promise conditions, preserves oracle-relative and unknown statuses through policy review, and makes no universal convergence claim from bounded runs.","intervention_falsifier":"The intervention fails if the economic query cannot be formalized without removing the property decision-makers intend to assess, capability contracts cannot distinguish supplied information from computation, withdrawal tests cannot identify dependency on an oracle, or a passport issues BASE_CERTIFIED for a model with a checked admissible countertrajectory. It also fails operationally if downstream materials collapse all passport statuses into one policy ranking.","risks":["The formal equilibrium or policy-target definition may not preserve the intended economic question.","Oracle labels may become paperwork without changing how assisted outputs are interpreted.","Human analysts may continue making unlogged adaptive choices outside the registered procedure.","An external service may change behavior without a visible version change.","Promise conditions may be semantic or empirical and therefore not mechanically enforceable.","Bounded counterexample search may overproduce UNKNOWN or miss policy-relevant trajectories outside its encoding.","A BASE_CERTIFIED computation can still rely on an empirically poor economic model.","Users may confuse oracle-relative computability with forecast accuracy or causal validity.","Logging human and external inputs may expose confidential model information.","A valid unrestricted-class impossibility result may be overstated as applying to finite or promised subclasses."]},"next_evidence_step":"Run one offline passport exercise on six synthetic policy models: a finite model with an internally checked terminal state, a model with a finite countercycle, a model containing a divergent agent branch, a model invoking a stubbed equilibrium service, a model requiring scripted human branch selection, and a model violating an external solver's stated promise. Freeze rational-valued state encoding and a bounded ten-step trace search for the pilot. Produce the exact convergence query, base computation contract, capability register, one proposed unrestricted-class reduction, oracle-withdrawal and abstention results, one checked countertrajectory, every required result label, and a versioned decision record. An independent reviewer must verify the reduction direction, witness validity, promise routing, dependency labels, and preservation of UNKNOWN. No live data, official forecast, or policy decision enters the exercise.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 concerned universal solvency analysis for programmable derivatives and intervened through an enforceable finite-state contract fragment, exhaustive or sound abstract analysis, and guarantee-based listing routes. Proposal 2 concerned termination and strategic truthfulness of executable auction mechanisms and used proof-carrying admission, certificate checking, and one-sided proof-versus-counterexample search. Proposal 3 concerned finite intraday collateral assignments and established a positive total decider before handing practical difficulty to complexity and cutoff management. Proposal 4 concerns equilibrium and convergence claims in macroeconomic policy models whose answers may depend on external solvers, live information, interactive environments, or human choices. Its primary intervention is capability-relative classification, promise enforcement, and oracle-withdrawal testing: it neither narrows programmable contracts as its main remedy, requires auction designers to carry proofs, nor enumerates a finite collateral assignment space. It is independently adoptable by policy-model governance without any dependency on the listing or treasury systems in proposals 1 through 3.","revision_record":{"parent_version":null,"progress_targets_addressed":[],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}