{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp05_complete_proposal_portfolio20_20260803","cell_id":"layer_decay_and_expiration_management__environmental_climate","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"drought-rule-patch-lifecycle","proposal_index":4,"version":0,"title":"Expiring Emergency Patches in Drought-Operations Rule Stacks","problem":"During droughts and water-supply emergencies, reservoir and watershed operators may add temporary release exceptions, pumping priorities, conservation-stage triggers, environmental-flow adjustments, and implementation clarifications to standing operating plans. Successive directives can persist across manuals, spreadsheets, control-system parameters, shift instructions, and model configurations after their initiating emergency or assumptions have changed. An obsolete patch may therefore remain operational or be mistaken for current authority. Deleting old directives indiscriminately can instead break a live dependency, erase the basis for past water decisions, or discard a condition that must be preserved under a permit or settlement.","actors":["Reservoir or water-supply operator","Drought-response coordinator","Water-resources hydrologist","Environmental-flow specialist","Operations-control engineer","Water-law or compliance officer","Authorizing water board or incident authority","Downstream water users and ecological receptors"],"observable_state":"For one drought-stage rule family, multiple directives or parameter sets govern the same release, pumping, or conservation decision. Copies differ across approved plans, emergency orders, shift instructions, spreadsheets, models, and operational configurations. Some lack a named owner, activation event, expiration condition, supersession link, dependency list, or unambiguous status showing whether they are executable, reference-only, held, or obsolete.","consequence":"Operators may apply conflicting or expired instructions to current water conditions, or retain unnecessary restrictions because their authority is unclear. Conversely, cleanup based only on date or document location may disable a rule still required by an approved plan, permit, automated calculation, downstream commitment, or reconstruction of past operations.","affected_objective":"Keep drought and reservoir operations aligned with currently authorized rules and current hydrologic and ecological conditions while retaining a reconstructable record of prior emergency directives and their effects on operational decisions.","intervention":"Create a lifecycle register for temporary drought-operation rule patches within one bounded rule family. Resolve each directive and deployed parameter set to a stable identity containing its authorizing instrument, scope, activation event, assumptions, owner, issue date, review TTL, dependencies, implementation locations, and lifecycle state: proposed, authorized-inactive, active, review-due, expired-pending-safe-disable, quarantined-reference, archived, held, or disposition-approved. Future temporary directives receive a TTL at authorization; expiration triggers review and prevents unreviewed reuse but cannot directly alter production controls. A stale-rule monitor compares registered authority with manuals, models, shift instructions, and operational configurations. Before disabling or archiving a rule, a dependency check traces permits, control logic, calculations, reports, downstream commitments, and other rules that invoke it. Authorized retirement first removes the patch from executable guidance while preserving it intact in a recoverable configuration quarantine. After a defined rollback window and operational review, it moves to an archive with a tombstone pointing to the successor or governing baseline. Periodic restore-and-simulation drills test whether an archived rule and its decision context can be reconstructed without reconnecting it to production.","structural_mapping":[{"archetype_element":"Sequential deposits","domain_realization":"Successive drought orders, operating exceptions, parameter overrides, and implementation clarifications are layered onto standing water-operation rules."},{"archetype_element":"Layer inventory and identity","domain_realization":"A register resolves each directive and deployed copy to a stable rule-patch identity, authority source, scope, owner, and implementation locations."},{"archetype_element":"Changed validity or usefulness","domain_realization":"A patch authorized for a particular emergency, forecast, infrastructure condition, or ecological constraint may no longer govern later conditions."},{"archetype_element":"Stale layer remaining active","domain_realization":"An expired directive or parameter override remains in a runbook, spreadsheet, model, or operational configuration and can still shape decisions."},{"archetype_element":"Expiration trigger","domain_realization":"A review TTL, emergency termination, superseding order, or material assumption change moves the patch to mandatory review without automatically changing physical operations."},{"archetype_element":"Value and risk triage","domain_realization":"Legacy patches are ranked for review using age, current invocation, authority clarity, operational impact, reconstruction value, and uncertainty, with safety and legal vetoes."},{"archetype_element":"Dependency and reconstruction check","domain_realization":"Review traces inbound references from control logic, permits, models, reports, commitments, and other operating rules before retirement."},{"archetype_element":"Differentiated disposition","domain_realization":"A patch may remain active, be renewed, return to authorized-inactive status, enter recoverable quarantine, move to historical archive, or remain under a named hold."},{"archetype_element":"Preservation exception","domain_realization":"Rules remain preserved when required for legal compliance, incident investigation, decision reconstruction, safety fallback, or an unresolved downstream obligation."},{"archetype_element":"Reversible cleanup","domain_realization":"Retired patches remain intact but non-executable in configuration quarantine during a time-bounded rollback period."},{"archetype_element":"Supersession and deletion marker","domain_realization":"A tombstone records that a patch no longer governs, why it was retired, and which baseline or successor now resolves its former references."},{"archetype_element":"Archive revalidation","domain_realization":"Controlled drills retrieve archived rule bundles and reproduce their logic in an isolated simulation environment."}],"mechanism_mapping":[{"mechanism_slug":"stale_layer_detection_dashboard","role":"Maintains the rule-patch inventory and flags mismatches between authorized states and copies found in manuals, models, shift instructions, spreadsheets, and operational configurations.","counterfactual_removal":"Without identity resolution and stale-state monitoring, an obsolete implementation copy can remain hidden even when the authoritative document has been superseded."},{"mechanism_slug":"time_to_live_ttl_policy","role":"Assigns future temporary directives a review lifetime at authorization. Expiry marks a patch review-due or ineligible for unreviewed reactivation; it never commands valves, pumps, releases, or production systems.","counterfactual_removal":"Without a precommitted review trigger, emergency patches can remain available or active through inertia after their initiating conditions end."},{"mechanism_slug":"age_weighted_value_score","role":"Orders legacy patches for review using age-discounted standing value together with current invocation, operational impact, authority clarity, reconstruction value, and uncertainty. Legal, ecological, and safety dependencies veto automated disposition.","counterfactual_removal":"Without a comparable triage input, review effort may focus on well-documented or visible patches while obscure high-impact overrides remain unresolved."},{"mechanism_slug":"retention_schedule","role":"Maps emergency directives, approved operating rules, implementation copies, simulations, and decision records to review periods, archival requirements, disposition conditions, and legal or investigative holds.","counterfactual_removal":"Without class-specific retention authority, temporary instructions and binding operating requirements can be treated alike, encouraging either unsafe deletion or indefinite active retention."},{"mechanism_slug":"dependency_safe_delete_check","role":"Blocks retirement or disposition until references from permits, control logic, models, downstream commitments, reports, and other rules have been traced and resolved.","counterfactual_removal":"Without the gate, removing an apparently expired patch could alter an automated calculation, violate an obligation, or make a prior operating decision irreproducible."},{"mechanism_slug":"soft_delete_quarantine_window","role":"Separates removal from executable guidance from final archival or disposition by holding the intact rule bundle in a non-production, recoverable quarantine for an impact-sized grace period.","counterfactual_removal":"Without quarantine, a mistaken retirement becomes difficult to reverse during an emergency or after a previously unknown dependency appears."},{"mechanism_slug":"archive_restore_test","role":"Retrieves sampled archived patches, restores their referenced inputs and logic in an isolated environment, and verifies that the former decision path can be interpreted and simulated.","counterfactual_removal":"Without an end-to-end drill, archived files may appear adequate while missing parameters, software, authority records, or dependency context make reconstruction impossible."},{"mechanism_slug":"tombstone_or_deletion_marker","role":"Leaves a durable non-executable marker at the retired patch's identity, recording its former authority, retirement reason, effective interval, and successor or restored baseline.","counterfactual_removal":"Without a tombstone, a missing rule can be confused with a catalog error, old copies can be reintroduced, and surviving references cannot resolve to an authoritative status."}],"causal_chain":["Drought emergencies generate temporary operational directives layered onto standing reservoir and water-allocation rules.","Copies of each directive propagate into documents, models, spreadsheets, shift practices, and production configurations.","When emergencies end or assumptions change, absent expiration and dependency rules leave some patches active or reusable by default.","The lifecycle register resolves rule identities, authority sources, deployed copies, review triggers, and explicit states.","TTL expiry and stale-state discrepancies produce a review worklist without directly modifying production operations.","Dependency tracing determines whether each patch remains connected to legal authority, control logic, ecological commitments, calculations, or reconstruction needs.","Authorized retirement removes a patch from executable guidance but preserves it intact in recoverable quarantine.","A rollback window allows restoration if an overlooked dependency or operational problem appears; otherwise the patch moves to historical archive or approved disposition.","A tombstone redirects surviving references to the governing baseline or successor and prevents an old copy from silently regaining authority.","Restore-and-simulation drills preserve accountability while the executable rule stack remains bounded and interpretable."],"baseline":"Temporary directives are issued and implemented through existing emergency procedures, then reconciled during later plan updates, staff reviews, or system maintenance. Teams rely on filenames, approval dates, comments, institutional memory, and manual configuration comparison. Version history may preserve copies, but it does not consistently establish per-patch expiration, executable status, dependency gates, quarantine, successor resolution, or tested reconstruction.","nearest_rivals":["A comprehensive rewrite that periodically consolidates all drought rules into a new operating plan.","Document or configuration version control that records changes without governing whether an old rule remains executable.","A calendar reminder for staff to review emergency directives after each drought season.","Operator training that instructs staff to consult only the latest approved manual.","Immediate deletion or disabling of every temporary rule when an emergency declaration ends.","A control-system configuration audit focused on technical consistency rather than authority, retention, and historical reconstruction."],"remaining_contrastive_claim":"The proposal manages each emergency rule patch as an aging, dependency-bearing layer whose executable authority, recoverable configuration, and historical evidence can occupy different lifecycle states. Its causal contribution is the combination of expiration-to-review, cross-location stale detection, dependency-gated retirement, reversible non-production quarantine, successor tombstones, and isolated reconstruction testing—not merely plan consolidation, version control, or staff reminders.","authority_safety":{"decision_authority":"The designated water board, incident authority, or other legally empowered official authorizes activation, renewal, or retirement of an operating directive. Operations and control engineers may implement only approved changes. Compliance personnel adjudicate permit and retention constraints, while the lifecycle steward may inventory, flag, and recommend but cannot change operational authority.","authorized_first_step":"For one drought-stage release or pumping rule family, build a read-only shadow register from approved plans, emergency orders, runbooks, models, and configuration exports; identify apparent copies, authority conflicts, expiration gaps, and dependency questions without changing any live document or system.","excluded_actions":["Changing a valve, gate, pump, release schedule, conservation stage, alarm, model input, or production configuration","Automatically disabling a rule when its TTL expires","Declaring an order, permit condition, settlement term, or approved operating plan superseded without competent authority","Writing lifecycle states back into production systems during the shadow inventory","Treating absence from the reviewed repositories as proof that no operational or external copy exists","Deleting or overwriting historical directives, configuration snapshots, logs, or decision records","Restoring an archived rule into a production environment during a test","Using a composite score to authorize activation, retirement, or disposition","Disclosing restricted infrastructure, security, ecological, or customer information through the register"],"halt_rollback":"Stop reconciliation if a discovered artifact appears to control live operations, conflicts with a current emergency instruction, exposes restricted control information, or has uncertain legal authority. Do not test, edit, disable, or reconnect it. Preserve the read-only evidence, restrict the provisional registry entry, and escalate to the authorized operations and compliance leads. Rollback removes shadow classifications and simulations while leaving every production configuration and governing document unchanged."},"negative_tests":{"strongest_counterevidence":"The bounded rule family already has stable patch identities, a single reconciled authority state across every implementation location, enforced review or termination conditions, complete dependency records, controlled historical access, and tested reconstruction; no obsolete directive remains executable or ambiguously reusable.","problem_falsifier":"Reconciliation finds no sequential patch stack: every apparent directive is either part of one current consolidated rule, explicitly terminated and segregated, or retained solely as clearly marked historical evidence, with no conflicting copy or unresolved live dependency.","intervention_falsifier":"Reviewers cannot reliably resolve directives and parameter sets into patch identities, material operational dependencies remain undiscoverable, or shadow retirement simulations repeatedly reveal unexplained changes that the proposed states and dependency checks cannot bound safely.","risks":["An expiration label may be mistaken for authority to stop a rule or alter physical operations.","Incomplete discovery may miss informal shift practices, external spreadsheets, or embedded control parameters.","A lifecycle score may create false precision around legally or operationally contextual decisions.","Removing an obsolete patch from normal guidance may expose an undocumented dependency during an emergency.","Conflicting legal, operational, and ecological authorities may prevent a single lifecycle state from being assigned.","Quarantined configurations may be accidentally reintroduced into production.","Archive simulations may omit the historical data, software, or institutional context needed to reproduce a past decision.","The registry may expose sensitive water-system or control-system information.","Extra lifecycle states may increase operator cognitive load if they are shown in emergency-facing interfaces.","A hold or expired-pending-review state may persist indefinitely and reproduce the accumulation problem." ]},"next_evidence_step":"Select one drought-stage release or pumping rule family and reconcile a bounded set of approved directives, runbook instructions, model rules, and read-only configuration exports into a provisional patch graph. Have two qualified reviewers independently identify patch boundaries, authority sources, active states, expiry triggers, successors, and dependencies. In an isolated tabletop or non-production model, compare the registered current baseline with one proposed retirement scenario, recording unexplained output changes and missing dependencies. The step authorizes no production modification, rule retirement, or operational decision.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 manages physical erosion-control mats embedded in habitat, using ecological and sediment-stability checks before material retirement. Proposal 2 manages digital climate-hazard map editions, separating current informational authority from historical decision evidence. Proposal 3 manages stored environmental specimens, balancing freezer capacity against scientific irreplaceability, chain of custody, and destructive disposition. This proposal instead manages executable drought-operation directives distributed across organizational and technical rule stacks. Its actors are water-operation authorities, control engineers, hydrologists, and compliance officials; its intervention is patch-level expiration, cross-location reconciliation, dependency-gated disablement, configuration quarantine, and isolated simulation; and its causal path prevents an emergency exception from continuing to govern physical water operations after its context changes. It is not a maintenance feature for installed materials, a map-edition extension, or a specimen-archive workflow, and it can be adopted independently by a water operator that uses none of those earlier interventions.","revision_record":{"parent_version":null,"progress_targets_addressed":[],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}