{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp05_complete_proposal_portfolio20_20260803","cell_id":"layer_decay_and_expiration_management__environmental_climate","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"climate-hazard-map-authority-lifecycle","proposal_index":2,"version":0,"title":"Expiring Authority for Climate Hazard Map Editions","problem":"A planning agency periodically produces climate-adjusted flood-hazard map layers from new elevation data, hydrologic models, climate scenarios, and infrastructure assumptions. Successive editions accumulate across shared GIS catalogs, dashboards, project folders, and derived analyses. An older edition can remain discoverable without a visible supersession or validity state and be mistaken for the map governing a current siting, adaptation, or funding decision. Deleting old editions indiscriminately would instead prevent reconstruction of earlier decisions and sever dependencies from permits, reports, and analyses that used them.","actors":["Climate-risk modeling team","GIS data steward","Floodplain or stormwater planner","Infrastructure and land-use planners","Permit and grant reviewers","Records or compliance officer","Consultants and partner agencies consuming map services","Analysts reconstructing prior decisions"],"observable_state":"For the same geographic extent and hazard measure, the agency holds multiple map editions with different model runs, climate horizons, terrain inputs, drainage assumptions, or publication dates. Some copies lack stable edition identifiers, expiration dates, supersession links, or machine-readable authority states. Current dashboards, saved projects, reports, and external services may reference different editions, while access logs and dependency records are incomplete.","consequence":"A stale map edition may continue shaping current screening or investment because users cannot distinguish historical evidence from current guidance. Conversely, cleanup based only on file age or storage pressure can erase the exact input needed to reproduce a past decision, interpret a report, audit a model change, or resolve a surviving reference.","affected_objective":"Keep current climate-hazard screening aligned with the designated map edition while preserving enough versioned evidence to reproduce and interpret decisions made under earlier editions.","intervention":"Create an edition-lifecycle service for one class of climate-adjusted flood-hazard maps. Every published edition receives a stable identifier, provenance manifest, geographic and scenario scope, publication date, review TTL, named owner, and lifecycle state: draft, authoritative, review-due, superseded-active-dependency, archived, held, or disposition-approved. A TTL or material input change triggers review but never automatic deletion. When a replacement is approved, catalogs and managed services demote the prior edition from current search results, attach a supersession marker, and redirect new use to the successor. Before archival or disposition, a dependency check traces managed dashboards, saved analyses, reports, permits, and model-reproduction packages that cite the edition. Editions with live dependencies remain reference-resolvable in an archived tier; sampled archive-restore drills test whether their data, metadata, symbology, and documented processing environment can still be recovered. Disposition decisions and surviving successor links remain in a separate audit register.","structural_mapping":[{"archetype_element":"Sequential deposits","domain_realization":"Successive climate-adjusted flood-map editions are deposited as models, observations, terrain data, infrastructure assumptions, and planning horizons change."},{"archetype_element":"Layer inventory and identity","domain_realization":"A registry resolves duplicate files and services to stable edition identifiers while recording scope, provenance, owner, and managed locations."},{"archetype_element":"Age and validity change","domain_realization":"Elapsed review time or changed model inputs can end an edition's authority for new decisions even though it remains valid evidence of an earlier decision context."},{"archetype_element":"Stale layer masquerading as current","domain_realization":"An older map remains searchable or embedded without a visible supersession state and can be selected as present guidance."},{"archetype_element":"Expiration trigger","domain_realization":"A review TTL, successor approval, or material input change moves an edition to review-due rather than destroying it."},{"archetype_element":"Retention classes and exceptions","domain_realization":"Current guidance, reproducibility evidence, decision-linked editions, temporary working copies, and held records receive different retention and access rules."},{"archetype_element":"Dependency and reconstruction check","domain_realization":"The service traces citations and managed references from dashboards, reports, permits, analyses, and reproduction packages before archival or disposition."},{"archetype_element":"Differentiated disposition","domain_realization":"An edition may remain authoritative, be refreshed, become reference-only, move to cold archive, be preserved under a hold, or receive disposition approval."},{"archetype_element":"Supersession marker","domain_realization":"A persistent record states that the prior edition is no longer authoritative for new use and identifies its approved successor."},{"archetype_element":"Archive recoverability","domain_realization":"Restore drills retrieve and reopen sampled archived editions with their metadata, symbology, and processing documentation."},{"archetype_element":"Deletion audit","domain_realization":"A separate register retains who approved disposition, when it occurred, why it was permitted, and how surviving references should resolve."}],"mechanism_mapping":[{"mechanism_slug":"stale_layer_detection_dashboard","role":"Maintains the identity-resolved edition inventory and surfaces maps whose review TTL elapsed, inputs changed, owner disappeared, references broke, or authority state conflicts across managed catalogs.","counterfactual_removal":"Without the inventory and staleness monitor, duplicate editions and inconsistent authority labels remain distributed, so lifecycle review cannot reliably identify what exists or which copy is misleading."},{"mechanism_slug":"time_to_live_ttl_policy","role":"Stamps each published edition with a review lifetime. Expiry changes its state to review-due and prompts owner action, but does not delete it or independently revoke an approved authority designation.","counterfactual_removal":"Without a precommitted review trigger, editions can remain current by inertia after their assumptions or intended review window have changed."},{"mechanism_slug":"retention_schedule","role":"Maps edition classes to minimum evidence-retention periods, active-access rules, archival pathways, disposition conditions, and litigation, regulatory, or decision-reconstruction holds.","counterfactual_removal":"Without class-specific governance, temporary exports, authoritative editions, and decision-linked evidence are treated alike, producing either indiscriminate retention or unsafe cleanup."},{"mechanism_slug":"dependency_safe_delete_check","role":"Blocks disposition until managed inbound references and known reconstruction requirements have been traced and either migrated, preserved with the edition, or explicitly adjudicated.","counterfactual_removal":"Without this gate, removing an apparently obsolete edition can break a dashboard, report, permit record, or reproduction chain that still depends on its stable identity."},{"mechanism_slug":"lifecycle_storage_tiering_policy","role":"Moves superseded but required editions from active GIS services to lower-cost reference and archive tiers while retaining their identities and retrieval instructions.","counterfactual_removal":"Without differentiated access tiers, the agency must either leave every retained edition prominent in active systems or delete history to reduce operational clutter."},{"mechanism_slug":"archive_restore_test","role":"Periodically exercises the actual recovery path for sampled archived editions, including retrieval, integrity validation, metadata parsing, symbology loading, and reconnection to a controlled GIS environment.","counterfactual_removal":"Without end-to-end restore tests, archival status may conceal unreadable formats, incomplete manifests, missing credentials, or obsolete tooling until reconstruction is urgently required."},{"mechanism_slug":"tombstone_or_deletion_marker","role":"Leaves a durable authority and disposition marker at the retired edition's identity, identifying its historical status, disposition, and approved successor where one exists.","counterfactual_removal":"Without the marker, a failed lookup cannot distinguish a disposed edition from a mistyped or never-published one, and cached copies may continue circulating without a supersession signal."}],"causal_chain":["Modeling cycles deposit multiple flood-hazard map editions and derived copies over time.","Absent explicit lifecycle states, older editions remain visible beside current guidance while their reconstruction value discourages cleanup.","Users can therefore select stale editions for new work, while administrators cannot tell which historical editions remain dependency-bearing.","The lifecycle service resolves editions and assigns owners, review triggers, authority states, retention classes, and successor relations.","TTL expiry or a material input change generates review; approval of a successor demotes the earlier edition from current discovery without erasing it.","The dependency gate determines whether the superseded edition must remain reference-resolvable for reports, permits, analyses, or model reconstruction.","Qualified editions move to an archive tier, while current catalogs expose the successor and a tombstone communicates the earlier edition's status.","Restore drills test whether archived evidence remains usable, and failed drills trigger remediation or a revised preservation decision.","The active catalog becomes bounded and interpretable while historical decision contexts remain recoverable under explicit rules."],"baseline":"Teams distinguish map editions through filenames, folder conventions, publication dates, staff knowledge, and manually updated service descriptions. Old layers may be retained in place to protect reproducibility, copied into project packages, or deleted during occasional storage cleanup. Authority, supersession, dependency, archival, and restore status are not governed as one lifecycle.","nearest_rivals":["A naming convention that appends publication dates or version numbers to map files.","A general geospatial metadata catalog that inventories layers but does not expire authority or govern disposition.","Immediate replacement of old map services with the newest edition while retaining no reference-resolvable predecessor.","Permanent retention of every edition in the active GIS environment for reproducibility.","User training instructing analysts to check publication dates before selecting a layer.","A conventional backup system that preserves files but does not distinguish current guidance from historical evidence."],"remaining_contrastive_claim":"The proposal governs the decay of an edition's decision authority separately from the retention of its evidentiary content. Its distinctive causal path is explicit expiration-to-review, controlled supersession, dependency-gated tiering, durable reference resolution, and tested restoration; inventory, backup, naming, or user training alone does not provide that lifecycle.","authority_safety":{"decision_authority":"The designated flood-risk program owner approves which edition is authoritative for new agency use. The GIS data steward may implement approved state changes and tier transitions. The records officer or other designated authority must approve disposition, holds, and retention exceptions. This service cannot itself change regulatory flood boundaries or legally controlling maps.","authorized_first_step":"For one flood-hazard product family, create a read-only inventory of managed editions, duplicates, metadata, existing citations, and apparent authority conflicts; assign only provisional lifecycle states in a shadow register.","excluded_actions":["Deleting, overwriting, unpublishing, or moving any map edition during the inventory step","Declaring an edition authoritative or obsolete without approval from the named program owner","Changing regulatory boundaries, permit standards, or completed planning decisions","Automatically deleting an edition when its TTL expires","Assuming absence from managed citation searches proves absence of external dependencies","Breaking stable identifiers used by reports, permits, dashboards, or partner systems","Publishing sensitive infrastructure inputs or restricted model artifacts through the lifecycle catalog","Treating archive availability as proven without an end-to-end restore test"],"halt_rollback":"Halt if inventory reconciliation produces ambiguous edition identities, conflicting authority claims, restricted-data exposure, or evidence that a managed service could be altered by the scan. Disable the affected connector or shadow entry, preserve original metadata and access controls, and refer the conflict to the program owner and records officer. Because the first step is read-only and provisional, rollback removes shadow classifications without changing source maps or their published services."},"negative_tests":{"strongest_counterevidence":"The bounded inventory shows that all editions already have stable identifiers, unambiguous authority and supersession states, controlled discovery, complete decision citations, tested recovery packages, and governed disposition records; observed selection errors are attributable to something other than accumulated editions.","problem_falsifier":"For the selected product family, there is only one discoverable edition for current use, every historical edition is intentionally segregated and reference-resolvable, and no managed dashboard, project, or report contains an ambiguous or undocumented map dependency.","intervention_falsifier":"The shadow register cannot resolve copies to editions with acceptable reviewer agreement, dependency tracing leaves most significant uses unknowable, or users presented with lifecycle states and successor links still cannot reliably identify the edition authorized for new work.","risks":["A visible authoritative label may create false confidence in the underlying model or scenario assumptions.","Incomplete dependency discovery may incorrectly classify a historical edition as safe for disposition.","External partners may retain detached copies that never receive supersession markers.","TTL settings may become arbitrary deadlines rather than prompts for substantive scientific review.","Archive tiering may delay legitimate reconstruction or emergency access.","Restore sampling may miss an unreadable edition, format, or dependency not included in the drill.","Preserving full model packages may conflict with licensing, confidentiality, security, or storage constraints.","Lifecycle metadata can itself become stale when ownership, services, or policy authority changes.","Users may confuse an agency-designated current edition with a legally controlling regulatory map." ]},"next_evidence_step":"Within one flood-hazard product family, reconcile the managed GIS catalog, publication folder, service registry, and a bounded sample of reports and dashboards into a provisional edition graph. Ask two reviewers independently to identify the current edition, superseded editions, duplicates, live dependencies, missing provenance, and proposed retention class using only existing records. Then conduct a non-production restore of one already archived sample if current authority permits. Evaluate identity resolution, reviewer agreement, dependency coverage, restore completeness, and whether the proposed states distinguish current guidance from historical evidence without changing any published map.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 governs successive physical erosion-control mats embedded in wetland or streambank habitat, where retirement can alter sediment, roots, and wildlife exposure. This proposal instead governs successive digital climate-hazard map editions whose active authority can decay while their informational content remains necessary for decision reconstruction. Its actors are modeling, GIS, planning, and records teams; its intervention is an edition-identity, supersession, dependency, archival, and restore service; and its causal path removes stale guidance from current discovery while preserving reference-resolvable evidence. It neither extends the mat registry nor substitutes a different site or material population, and it is independently adoptable by an agency that manages climate-map editions without managing erosion-control installations.","revision_record":{"parent_version":null,"progress_targets_addressed":[],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}