{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp05_complete_proposal_portfolio20_20260803","cell_id":"computability_boundary_mapping__human_computer_interaction","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"cbm_hci_wizard_migration_boundary_003","proposal_index":3,"version":0,"title":"Wizard-to-Build Boundary for Accessible Interface Migration","problem":"A team uses a Wizard-of-Oz prototype to test an accessible replacement for a legacy interactive application. Behind the prototype, a human operator interprets events, consults the legacy application, and produces the replacement interface's responses. Successful scripted sessions are then treated as evidence that a future converter can accept any legacy application, generate an accessible replacement with the same declared task semantics, always terminate, and certify the two applications equivalent. That total-exact requirement ranges over arbitrary executable interfaces and unbounded event traces. A hidden operator's performance on finitely many sessions establishes neither a uniform conversion procedure nor a total equivalence decider. Under an unbounded program-semantics model, equivalence can encode whether an arbitrary computation halts, while a finite-state source and replacement can be compared by a terminating constructive procedure.","actors":["People with disabilities and assistive-technology users participating in prototype evaluation","Interaction and accessibility designers defining the replacement experience","Wizard-of-Oz operators supplying the prototype's hidden behavior","Legacy-application maintainers defining source behavior and task commitments","Migration engineers building the converter and replacement runtime","Quality-assurance and formal-methods reviewers assessing preservation claims","Product sponsors deciding whether and how to fund migration"],"observable_state":"The prototype convincingly performs selected tasks, but its records do not distinguish behavior produced by the planned converter from behavior supplied through human interpretation. Migration requirements say that all behavior will be preserved for arbitrary legacy applications, while validation consists of scripted tasks, screenshots, operator notes, or bounded traces. Differences are recorded only as pass or fail, so intentional accessibility improvements, witnessed semantic regressions, unexamined behavior, operator-dependent behavior, and formally established equivalence are not distinguishable.","consequence":"The organization can commit to a total automatic migration and certification goal that its declared input class does not support. A generated replacement may pass demonstrated tasks while omitting an untested commitment, error path, data transition, focus change, or assistive-technology announcement. Conversely, a useful accessible redesign may be rejected because superficial visual differences are mistaken for semantic inequivalence. Prototype participants may also be led to believe they evaluated an automated capability when decisive behavior came from an undeclared human operator.","affected_objective":"Make the build and scope decision for accessible interface migration on an honest account of what can be generated and certified, while preserving separate evidence about whether the replacement is usable and accessible to people rather than merely equivalent to a formal model.","intervention":"Create a Wizard-to-Build Realizability Gate before committing to the converter. First, publish a task-semantic observation contract covering declared inputs, task outcomes, persistent data effects, irreversible commitments, errors, focus behavior, and assistive-technology announcements; pixel identity is explicitly excluded, permitting intentional accessible redesign. Tag every prototype response by provenance: planned mechanism, fixed script, legacy-system lookup, or human judgment. Formalize the universal equivalence claim for arbitrary executable interfaces and independently check a halting-based reduction before classifying it. Establish an enforceable finite-state migration profile with bounded data, terminating transitions, and explicit environment inputs; for source-replacement pairs inside that profile, run an exact product-state equivalence procedure. For unrestricted pairs, fairly search event traces and simulations for a replayable semantic divergence. Return WITNESSED_DIVERGENCE when one is found and UNKNOWN_EQUIVALENCE when the bound is reached; never upgrade bounded conformance to equivalent. Record HUMAN_DEPENDENT whenever the behavior requires operator interpretation, and OUT_OF_SCOPE_CONTRACT when the observation contract cannot represent a material task. Gate the build decision on a versioned boundary record, while continuing participatory accessibility evaluation as evidence about human experience rather than universal behavioral preservation.","structural_mapping":[{"archetype_element":"Problem-Class Specification","domain_realization":"The unrestricted class contains pairs of arbitrary executable legacy and replacement interfaces; the decision question asks whether their declared task-semantic observations agree for every valid event trace."},{"archetype_element":"Instance Representation Contract","domain_realization":"Each comparison instance includes both executable models, the event alphabet, initial states, persistent-data semantics, termination and timing observations, environment inputs, and the versioned task-semantic observation contract."},{"archetype_element":"Computation Model Contract","domain_realization":"The analysis separates idealized unbounded executable semantics, enforceable finite-state migration profiles, bounded trace experiments, and behavior relative to a fallible human operator."},{"archetype_element":"Solvability Guarantee Profile","domain_realization":"EXACT_EQUIVALENT and EXACT_DIVERGENT are available only within the checked finite profile; unrestricted analysis may issue a witnessed divergence or explicit unknown but cannot certify universal equivalence."},{"archetype_element":"Computability Impossibility Certificate","domain_realization":"A checked construction embeds an arbitrary computation into one interface so that a declared observation differs exactly according to its halting behavior, testing the impossibility of a total unrestricted equivalence certifier."},{"archetype_element":"Decidable Subclass Map","domain_realization":"A mechanically checked profile identifies finite state variables, bounded data, terminating event handlers, declared environment inputs, and prohibited executable escape hatches for which exact comparison is available."},{"archetype_element":"One-Sided Recognition Contract","domain_realization":"For unrestricted pairs, a finite trace producing different declared observations is a checkable counterexample, while failure to find such a trace does not prove equivalence."},{"archetype_element":"Model Transparency","domain_realization":"Every prototype response identifies whether it came from the planned mechanism, a script, a legacy lookup, or human interpretation, making the hidden operator's computational and epistemic contribution visible."},{"archetype_element":"Fallback Solution Contract","domain_realization":"Bounded conformance testing and participatory accessibility evaluation remain useful but retain their own labels and never inherit the universal equivalence claim."},{"archetype_element":"Decision Record and Recheck Trigger","domain_realization":"A supersedable record links the observation contract, provenance ledger, reduction, finite profile, checker, residual unknowns, and triggers such as new scripting features, task commitments, assistive technologies, or environment inputs."}],"mechanism_mapping":[{"mechanism_slug":"halting_problem_reduction","role":"Test the unrestricted equivalence claim by constructing an interface pair whose declared observational relationship reveals whether an embedded arbitrary computation halts.","counterfactual_removal":"Without a property-preserving reduction, the team could infer impossibility from failed implementations or invoke the halting problem despite mismatched observations, encodings, or computation models."},{"mechanism_slug":"proof_checking","role":"Have a reviewer independent of the converter team verify the reduction, the observation semantics, the direction of transfer, and every assumption used to classify unrestricted equivalence.","counterfactual_removal":"Without independent checking, a valid proof about termination, visual identity, or another weaker property could be mistaken for a proof about task-semantic equivalence."},{"mechanism_slug":"language_fragment_restriction","role":"Define an enforceable finite-state migration profile for legacy interfaces and generated replacements, excluding unbounded data and executable escape hatches from the exact certification mode.","counterfactual_removal":"Without a syntactically enforceable profile, the project would identify an unrestricted boundary without providing a reliable exact region for migration."},{"mechanism_slug":"constructive_algorithm_and_correctness_proof","role":"Supply a product-state comparison algorithm for the finite profile and prove that it terminates and correctly returns equivalence or a divergent state trace.","counterfactual_removal":"Without a constructive witness, the finite profile would be described as decidable without demonstrating the total procedure on which its certification depends."},{"mechanism_slug":"enumeration_and_dovetailing","role":"Fairly interleave event traces and simulations of potentially nonterminating handlers when searching unrestricted pairs for an observable divergence.","counterfactual_removal":"Without dovetailing, one nonterminating handler could prevent examination of later traces containing a finite, replayable divergence."},{"mechanism_slug":"proof_by_counterexample","role":"Use one well-formed replay trace with different declared task-semantic observations to refute an over-broad equivalence claim.","counterfactual_removal":"Without counterexample discipline, a demonstrated regression could be dismissed as anecdotal or, conversely, the absence of a found regression could be treated as proof of equivalence."},{"mechanism_slug":"bounded_domain_exhaustive_search","role":"Check every event trace and bounded data valuation inside a frozen finite test envelope, issuing a certificate limited to that envelope.","counterfactual_removal":"Without explicit finite enumeration and encoding, ordinary scripted testing could be described as exhaustive without defining which cases were covered."},{"mechanism_slug":"semi_decision_with_explicit_unknown","role":"Return WITNESSED_DIVERGENCE with a replay trace when search succeeds and UNKNOWN_EQUIVALENCE at the declared resource bound when it does not.","counterfactual_removal":"Without an explicit unknown output, bounded non-finding would tend to be reported as equivalent."},{"mechanism_slug":"computational_complexity_analysis","role":"Assess product-state growth and comparison cost after a pair qualifies for the finite profile, separating exact decidability from practical migration throughput.","counterfactual_removal":"Without the complexity gate, finite-state equivalence could be promised at operational scales where its exact procedure is unusable."},{"mechanism_slug":"computability_boundary_decision_record","role":"Record the chosen migration boundary, prototype provenance, observation contract, guarantees, open residue, and changes that require reclassification before further investment.","counterfactual_removal":"Without the record, a later change to either interface language or the preservation contract could silently invalidate an earlier build decision."}],"causal_chain":["A hidden operator makes the proposed accessible replacement behave convincingly during a bounded set of user-facing prototype sessions.","The operator interprets context and supplies behavior that the planned converter does not yet implement, while the prototype surface conceals that distinction.","Passing selected sessions is generalized into a requirement to convert every arbitrary legacy interface and certify preservation over all valid event traces.","Once task-semantic observations, encodings, and computation models are explicit, the certification requirement becomes a class-wide program-equivalence question.","A checked halting-based construction can place unrestricted exact equivalence beyond a total terminating certifier under the declared unbounded model.","The boundary does not apply to an enforceable finite-state profile, for which product-state comparison supplies an exact constructive decision procedure.","For unrestricted pairs, fair trace and simulation search can still find a finite semantic divergence, but bounded non-finding remains UNKNOWN_EQUIVALENCE.","Prototype provenance labels prevent human-supplied behavior from being counted as evidence that the planned interior is computable or implemented.","Bounded conformance and participatory accessibility findings retain useful but weaker claims about tested traces and human experience.","A versioned realizability record converts those distinctions into a scoped build decision and forces reconsideration when the languages, environment, or observation contract change."],"baseline":"The team runs Wizard-of-Oz sessions on selected legacy tasks, manually compares screens and outcomes, records usability or accessibility findings, and treats successful demonstrations as the migration proof of concept. The operator's contribution is described informally, the preservation relation is not machine-stated, and a finite scenario suite supplies the only evidence for the planned universal converter and equivalence certificate.","nearest_rivals":["Task-based manual migration validation: directly examines important user journeys but cannot turn finitely many passing tasks into universal behavioral equivalence.","Screenshot or visual-regression comparison: can identify visible differences but confuses intentional accessible redesign with error and misses nonvisual task state, focus, assistive-technology announcements, and latent behavior.","Accessibility conformance auditing: evaluates specified accessibility properties but does not establish preservation of every task-semantic behavior of an arbitrary legacy application.","A full manual accessible rewrite: can deliver a replacement through human engineering but does not demonstrate a uniform automatic converter or a total equivalence certifier for the declared application class.","Exact equivalence checking on a manually abstracted finite model: can prove a result about that model, but without enforceable profile membership and semantic-fidelity review it may certify the wrong boundary or observation contract.","Continuing Wizard-of-Oz trials until no new divergence is observed: may improve the prototype but cannot convert absence of an observed counterexample into a universal equivalence proof."],"remaining_contrastive_claim":"The proposal's contrastive claim is limited to the build-decision structure: it exposes the wizard's contribution, defines preservation at the task-semantic rather than pixel level, separates unrestricted equivalence from an enforceable finite exact region, and retains counterexample search and bounded conformance without overstating them. It does not claim that the finite profile covers enough legacy behavior, that equivalent behavior is accessible, or that users will prefer the replacement.","authority_safety":{"decision_authority":"The product sponsor retains authority over migration investment, jointly constrained by an accessibility lead's judgment about the observation contract and an independent formal reviewer’s approval of boundary evidence. Prototype participants provide experiential evidence but are not assigned responsibility for proving buildability. The converter, checker, and Wizard-of-Oz operator have no autonomous production-migration authority during the first evidence step.","authorized_first_step":"Before further converter implementation, run one offline realizability audit on a single nonproduction migration fixture containing a frozen legacy model, a proposed replacement model, a declared task-semantic observation contract, and a scripted Wizard-of-Oz transcript. Tag every transcript response by provenance, construct the finite-profile comparison, and test unrestricted fallback labels without modifying or deploying either application.","excluded_actions":["Migrating or replacing a production interface from the audit result","Representing human-supplied prototype behavior as generated behavior","Claiming universal equivalence from scripted sessions, bounded trace checks, screenshots, or absence of a discovered divergence","Issuing EXACT_EQUIVALENT for a pair that has not passed enforceable finite-profile membership checks","Treating intentional accessibility changes as defects solely because pixels or interaction sequences differ","Treating formal equivalence as evidence that users can perceive, understand, or operate the replacement","Concealing UNKNOWN_EQUIVALENCE, OUT_OF_SCOPE_CONTRACT, HUMAN_DEPENDENT, or TOOL_FAILURE behind a pass result","Expanding the impossibility conclusion to restricted languages or fixed bounded systems without re-analysis"],"halt_rollback":"Halt the audit if the observation contract omits a material task commitment identified by reviewers, provenance cannot distinguish human and planned behavior, finite-profile membership can be bypassed, the exact checker misclassifies a seeded pair, a divergence trace cannot be replayed, or bounded non-finding is displayed as equivalence. Withdraw all audit guarantee labels, return the migration decision to the unchanged prototype-and-review baseline, retain the fixture and discrepancy record, and require a revised contract before resuming."},"negative_tests":{"strongest_counterevidence":"A mechanically checked constructive procedure that terminates and correctly decides the declared task-semantic equivalence relation for every pair in the same unrestricted executable model would refute the proposed boundary. Alternatively, evidence that the intended migration class is already mechanically confined to a finite-state language would show that the unrestricted impossibility question is not the operative problem.","problem_falsifier":"The inferred problem is falsified if the project claims only to support a fixed enumerated task set, labels the prototype as human-operated, makes no universal conversion or equivalence claim, and already distinguishes bounded task preservation from accessibility and usability findings. The remaining challenge would then be ordinary implementation, coverage selection, or complexity rather than confused computability.","intervention_falsifier":"The intervention fails if finite-profile membership is not enforceable, the constructive checker is wrong or nonterminating on a well-formed finite pair, the observation contract cannot represent behavior stakeholders consider material, a replayable divergent trace is ignored, human-supplied behavior enters the planned-mechanism evidence, or UNKNOWN_EQUIVALENCE is consumed as equivalent.","risks":["The observation contract may omit timing, error recovery, focus order, announcements, social context, or persistent effects that matter to users.","A formally equivalent replacement may remain inaccessible or difficult to use; participatory evaluation must remain independent.","Requiring literal behavioral preservation could reproduce inaccessible legacy behavior unless intentional task-semantic changes are explicitly authorized.","The finite profile may exclude applications important to the migration decision.","Product-state comparison may be decidable yet operationally infeasible because of state growth.","Fair divergence search may produce many unknown results or fail to find a late counterexample within its bound.","A human operator may interpret provenance categories inconsistently or provide undeclared external knowledge.","Participants may misunderstand the prototype as automated unless the study disclosure clearly identifies its Wizard-of-Oz character.","A bounded conformance certificate may be detached from its bound when communicated to sponsors or downstream teams."]},"next_evidence_step":"Create one fixed offline fixture family around a single protected task-semantic contract, including: exactly equivalent finite pairs with different visual presentations; finite pairs with seeded differences in persistent outcome, error behavior, focus, and assistive-technology announcement; unrestricted pairs with early and delayed divergent traces; a nonterminating handler placed before a finite divergent trace; bounded pairs with no divergence inside the envelope; and transcript responses supplied separately by scripts, legacy lookup, and human judgment. Freeze the observation contract, finite profile, event encoding, search bound, provenance categories, and output alphabet before execution. Require an independent check of the reduction and finite comparison proof plus an accessibility review of semantic fidelity. Continue only if profile membership is enforced, exact finite verdicts match the fixtures, every witnessed divergence replays, the nonterminating handler does not starve later traces, bounded non-finding remains UNKNOWN_EQUIVALENCE, and provenance is preserved in sponsor-facing output. This step tests the boundary and evidence semantics only and estimates neither prevalence nor effect size.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 addressed release-time safety verification for protected actions inside extensible interfaces. It asked whether a forbidden interaction state could ever occur and intervened through a protected-action monitor, an exact declarative fragment, sound over-approximation, and release labels. Proposal 3 instead addresses prototype-to-build inference for automatic accessible migration and asks whether two complete interactive behaviors are equivalent; its defining intervention is a Wizard-of-Oz provenance ledger, task-semantic observation contract, finite-pair equivalence gate, and one-sided divergence search. It can be adopted before funding a migration converter without becoming part of protected-action release assurance. Proposal 2 addressed runtime help about whether a desired task state is reachable from the user's current workspace, using positive plan witnesses, a closed-world promise for exact unreachability, and explicit collaborator dependencies. Proposal 3 neither guides a user toward a goal nor decides current-state feasibility: it evaluates whether a proposed replacement preserves declared behavior and whether a human-mediated prototype supports the planned automation claim. The migration realizability gate, protected-action release checker, and task-feasibility help broker therefore have different decision owners, evidence objects, consequences, operating times, and adoption paths.","revision_record":{"parent_version":null,"progress_targets_addressed":["Created a third independently adoptable opportunity for the same archetype-domain cell","Selected Wizard-of-Oz prototype-to-build inference and accessible interface migration rather than safety verification or task guidance","Specified a distinct equivalence boundary, provenance intervention, causal chain, operating authority, safeguards, falsifiers, and bounded evidence step","Explicitly contrasted the candidate with both earlier sealed proposals"],"conceptual_changes":["Initial version; realized computability boundary mapping as a gate between a human-mediated accessible migration prototype and a claimed universal automatic converter.","Separated task-semantic behavioral equivalence, accessibility quality, bounded conformance, and human-supplied prototype capability."],"operational_changes":["Initial version; defined the observation contract, provenance ledger, finite migration profile, exact comparison mode, divergence-search mode, status alphabet, decision authority, and rollback conditions."],"evidence_changes":["Initial version; defined an offline fixture audit covering visual variation, semantic divergence, nontermination, bounded non-finding, proof review, accessibility review, and provenance preservation."],"claim_changes":["Initial version; limited the claim to an honest realizability and migration-scope decision and made no claim of novelty, prevalence, demand, or effect size."]}}