{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp05_complete_proposal_portfolio20_20260803","cell_id":"layer_decay_and_expiration_management__physics","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"physics_validity_leased_detector_calibration_payloads","proposal_index":3,"version":0,"title":"Validity-Leased Calibration Payloads for Long-Lived Physics Detectors","problem":"A long-lived detector accumulates successive alignment, gain, timing, field-map, channel-mask, and response-calibration payloads as hardware state and reconstruction knowledge change. Payloads can remain eligible for default resolution after the run range or detector state for which they were validated, especially when a missing newer payload causes fallback to an older layer. Removing old payloads is also hazardous because past reconstruction campaigns, derived datasets, and published analyses may depend on their exact correction stack. Without explicit expiration, supersession, dependency, and archival states, obsolete corrections can retain operational authority while custodians hesitate to retire any historical payload.","actors":["detector calibration physicist","subsystem calibration or alignment convener","event-reconstruction software maintainer","physics analyst selecting reconstruction conditions","conditions-database administrator","research data steward","analysis-preservation reviewer"],"observable_state":"For each calibration payload, the inspectable state includes payload identity and type, creation and validation dates, detector configuration, run and time validity interval, parent calibration, superseding payload, validation evidence, default-resolution eligibility, global tags and reconstruction campaigns that reference it, derived datasets produced with it, preservation holds, last access, storage tier, restore-test result, and lifecycle state. The failure state is observable when a payload lacks a bounded validity lease, an older payload silently resolves for an uncovered detector interval, two payloads claim overlapping authority without adjudication, or custodians cannot distinguish an unreferenced obsolete payload from one required to reconstruct a past result.","consequence":"A stale calibration layer selected during event reconstruction can apply corrections inconsistent with the detector state being interpreted, changing reconstructed quantities without an explicit analysis decision. Conversely, overwriting or deleting a historical payload can make an earlier reconstruction stack unavailable for audit, comparison, or reproduction. Indefinite active retention also enlarges the set of apparently usable corrections and makes authoritative selection harder to inspect.","affected_objective":"Ensure that only explicitly validated calibration payloads can resolve by default for a detector state while preserving the exact historical correction stacks required for reconstruction, audit, and authorized reanalysis.","intervention":"Give every newly validated calibration payload a bounded authority lease separate from its byte-retention period. The lease specifies the detector configuration and run or time interval for which the payload may resolve by default, its review date, and its expiration action. Expiration removes the payload from default resolution and routes it to review; it does not destroy it. A lifecycle registry detects uncovered intervals, conflicting validity claims, stale fallbacks, superseded payloads, and unowned exceptions. Before demotion or removal, a dependency gate traces global tags, reconstruction manifests, derived datasets, active analyses, and preservation packages. Historical payloads then move among active, review, warm replica, cold archive, quarantine, and disposed states according to class-specific retention rules. Sampled archived stacks are periodically restored by reconstructing a bounded reference event set. A tombstone remains after disposal and identifies the payload, validity interval, decision, retained validation record, and successor.","structural_mapping":[{"archetype_element":"Sequential layers accumulate after their validity changes","domain_realization":"Each detector recalibration deposits another correction payload over earlier alignment, gain, timing, masking, or response layers; older payloads retain historical value but may no longer describe the current detector."},{"archetype_element":"Layer inventory and identity map","domain_realization":"A registry resolves payload identities across conditions objects, global tags, validation records, reconstruction campaigns, and archived preservation packages."},{"archetype_element":"Age and access index","domain_realization":"Creation time, validation age, lease-review date, last resolution, and last reconstruction use remain inspectable without treating chronological age as proof of invalidity."},{"archetype_element":"Expiration trigger","domain_realization":"Lease expiry, detector reconfiguration, supersession, uncovered validity intervals, or failed revalidation trigger review and removal from default resolution rather than automatic destruction."},{"archetype_element":"Differentiated lifecycle states","domain_realization":"A payload can remain authoritative, become review-only, move to a historical storage tier, enter recoverable quarantine, or be disposed while retaining a marker."},{"archetype_element":"Dependency and reconstruction check","domain_realization":"Demotion from recoverable storage or disposal is blocked while a global tag, reconstruction manifest, derived dataset, analysis, or preservation package requires the exact payload."},{"archetype_element":"Preservation exception register","domain_realization":"Named payloads can receive time-bounded holds for published-result reconstruction, detector-anomaly investigation, cross-calibration, or validation disputes."},{"archetype_element":"Supersession marker","domain_realization":"A successor edge states that an older payload has lost default authority for a defined interval while preserving the distinction between superseded, invalid, and never applicable."},{"archetype_element":"Reversible cleanup and archive validation","domain_realization":"Removal candidates remain recoverable in quarantine, while restore drills test whether archived correction stacks can still be retrieved, parsed, and applied."},{"archetype_element":"Deletion evidence survives deletion","domain_realization":"A tombstone retains identity, applicability, lineage, rationale, dependencies checked, and successor resolution after payload bytes are destroyed."}],"mechanism_mapping":[{"mechanism_slug":"time_to_live_ttl_policy","role":"Implements a bounded authority lease stamped at validation. When it expires, the payload becomes ineligible for default resolution and enters review; retention and destruction remain separate decisions.","counterfactual_removal":"Without the lease, a payload can remain operationally current merely because no one has explicitly revoked it, allowing outdated fallbacks and unreviewed exceptions to persist."},{"mechanism_slug":"stale_layer_detection_dashboard","role":"Maintains the payload inventory and surfaces expired leases, uncovered detector intervals, overlapping authority, stale fallbacks, missing owners, and conflicts between payload context and current detector state.","counterfactual_removal":"Without this surface, inconsistencies remain distributed across conditions tables, release notes, validation plots, and analysis configurations, so expiration failures may remain invisible."},{"mechanism_slug":"age_weighted_value_score","role":"Ranks non-authoritative payloads for storage review using validation age, last use, uniqueness, regeneration feasibility, reconstruction value, and maintenance burden. Scientific or preservation dependencies act as vetoes, and the score cannot revoke validity or delete data.","counterfactual_removal":"Without a common review ranking, custodians must inspect the historical payload stack ad hoc or rely on age alone, obscuring old but irreplaceable correction states."},{"mechanism_slug":"retention_schedule","role":"Assigns payload classes their minimum retention, review cadence, archival path, maximum ordinary retention where authorized, and preservation-hold procedure.","counterfactual_removal":"Without class-specific rules, temporary calibrations, canonical global-tag components, validation drafts, and published-analysis payloads receive inconsistent treatment, while exceptions can become permanent by neglect."},{"mechanism_slug":"dependency_safe_delete_check","role":"Acts as a hard pre-disposition gate by tracing inbound references from global tags, reconstruction campaigns, derived datasets, active analyses, and preservation manifests.","counterfactual_removal":"Without the gate, an apparently superseded payload could be destroyed even though an existing dataset or reproducibility package still requires its exact correction stack."},{"mechanism_slug":"lifecycle_storage_tiering_policy","role":"Moves historical but retained payloads and associated validation artifacts from operational conditions storage to warm replicas and cold preservation archives as access cools.","counterfactual_removal":"Without tiering, loss of default authority leaves only two choices: keep every historical payload in operational infrastructure or delete it despite legitimate reconstruction value."},{"mechanism_slug":"soft_delete_quarantine_window","role":"Hides an approved removal candidate from ordinary selection while retaining a recoverable copy for a grace period based on reconstruction impact and regeneration difficulty.","counterfactual_removal":"Without quarantine, a missed dependency or mistaken successor relationship becomes irreversible immediately upon deletion."},{"mechanism_slug":"archive_restore_test","role":"Periodically restores sampled historical global-tag stacks, parses the payloads, reconnects them to a controlled reconstruction release, and processes a bounded reference event set.","counterfactual_removal":"Without an end-to-end restore, archive presence and checksums cannot establish that the payload stack remains interpretable and usable by a reconstruction path."},{"mechanism_slug":"tombstone_or_deletion_marker","role":"Leaves a durable resolution record after disposal, distinguishing an intentionally removed payload from a missing or never-created one and directing references to its successor or retained preservation record.","counterfactual_removal":"Without the marker, historical identifiers become ambiguous, dangling references cannot resolve consistently, and an obsolete replica could be mistaken for an authoritative payload."}],"causal_chain":["Detector operation and recalibration create a temporal stack of correction payloads with differing applicability and historical value.","The registry binds each payload to its detector context, validity interval, validation evidence, successor, consumers, and lifecycle state.","A bounded authority lease prevents continued default use from being inferred solely from continued existence.","Lease expiry or detected context conflict removes the payload from automatic resolution and initiates review without erasing it.","Dependency tracing and preservation holds identify payloads that remain necessary for reconstruction, audit, or adjudication.","Class rules and the operational-value ranking route non-authoritative payloads to warm storage, cold archive, quarantine, or approved disposal.","Quarantine permits recovery from a missed dependency before irreversible destruction.","Archive drills test that retained historical stacks can still reconstruct a reference event set.","Tombstones and successor edges preserve lineage and unambiguous resolution after disposition, while recurring lease review bounds the active correction stack."],"baseline":"The baseline uses validity intervals, manually assembled global tags, release notes, and expert review to select calibration payloads. Historical objects remain in the operational conditions system or are migrated manually, and an older payload may serve as a fallback when a newer interval is absent. Retention, default authority, analysis dependency, preservation status, and archival usability are managed separately rather than as one lifecycle.","nearest_rivals":["Validity intervals alone: constrain intended applicability but do not require periodic revalidation, prevent permissive fallback, govern historical storage, or test reconstruction dependencies.","Immutable global tags retained indefinitely: preserve exact historical stacks but leave every referenced payload in continuing retention and do not control which tags remain eligible for ordinary use.","Overwrite-in-place calibration tables: simplify current selection but destroy lineage and prevent exact reconstruction of earlier correction states.","Per-analysis containers or database snapshots: preserve an analysis-specific stack but duplicate payloads and do not govern expiration, supersession, or authority in the central resolver.","Manual calibration-convener signoff: supplies expert judgment but depends on recurring attention and does not itself provide quarantine, dependency tracing, archive testing, or durable deletion resolution.","Reject all fallback and fail on every uncovered interval: prevents silent use of an old payload but does not decide how historical corrections should be retained, restored, superseded, or disposed."],"remaining_contrastive_claim":"The proposal's contrastive claim is that a calibration payload's authority to resolve by default must expire independently of its physical retention. Validity leases bound active authority, while dependency-aware tiering, quarantine, restore tests, and tombstones preserve historical reconstruction without allowing continued existence to masquerade as current scientific validity.","authority_safety":{"decision_authority":"The subsystem calibration convener authorizes scientific validity and lease renewal; the reconstruction conditions coordinator approves default-resolution and successor changes; the data steward authorizes storage transitions; irreversible disposal requires a cleared dependency verdict and joint approval from the conditions coordinator and data steward. Analysis owners control named preservation holds for their registered packages.","authorized_first_step":"Build a read-only shadow registry for one retired detector subsystem and a bounded historical run interval. Simulate lease expiration and resolver outcomes without changing production tags, then restore one already archived correction stack into an isolated reconstruction environment and process an existing reference event sample.","excluded_actions":["changing an active production global tag or conditions resolver","automatically revoking payload authority from age or score alone","deleting or migrating production payloads during the first evidence step","altering historical payload bytes, validity intervals, or validation records","treating absence from the central registry as proof that no external analysis depends on a payload","retroactively changing the correction stack attributed to a published or frozen derived dataset","using an isolated restore result as authorization for production reconstruction"],"halt_rollback":"Halt if the shadow registry cannot reproduce known global-tag resolution, reports a false uncovered interval for a validated run, misses a known analysis dependency, or requires modification of source archives. Preserve production configuration unchanged, discard only ordinary isolated scratch outputs, mark all simulated leases non-authoritative, and retain the original reference manifests for comparison."},"negative_tests":{"strongest_counterevidence":"The existing conditions system already enforces closed applicability intervals, forbids stale fallback, preserves immutable global tags with complete dependency manifests, and demonstrably restores every required historical stack without imposing a relevant maintenance or interpretive constraint. In that state, an additional lifecycle controller would not address the proposed failure.","problem_falsifier":"The problem is falsified for the pilot scope if no obsolete payload can resolve outside its validated detector context, every historical consumer is explicitly traceable, authoritative and archival states are already distinct, and continued retention requires no unresolved lifecycle decision.","intervention_falsifier":"The intervention is falsified if shadow leases reject payloads that the authoritative validation record requires, fail to detect known stale fallbacks or conflicting intervals, cannot trace registered consumers, or add no decision-relevant distinction beyond strict validity intervals plus immutable global tags. A sampled archived stack that cannot be restored through the documented procedure also falsifies the claimed preservation safeguard until corrected.","risks":["An incorrectly specified lease can suppress a valid calibration and create an uncovered reconstruction interval.","A clean expiration label may project false certainty onto disputed detector-state boundaries.","Incomplete manifests can omit private analyses, exported datasets, or external preservation copies.","Successor edges can oversimplify cases where multiple calibrations remain valid for different reconstruction methods.","Archive formats, database clients, authentication, or reconstruction software can become incompatible.","Quarantine retains data that an approved destruction rule might require to be removed promptly.","The age-weighted score can conceal value judgments behind a numerical ranking.","Tombstones can themselves accumulate or expose more historical metadata than retention policy permits."]},"next_evidence_step":"For a retired subsystem and bounded run interval, enumerate payloads, validity intervals, global tags, successor claims, and registered derived datasets. Replay the resolver in shadow mode with proposed leases and compare every selection against authoritative reconstruction manifests. Seed the test with known uncovered intervals, overlaps, and superseded payloads to measure whether the registry surfaces them. Independently audit a sample of dependency verdicts, then restore one historical stack into isolation and reproduce an already documented reference reconstruction. Record false expirations, missed conflicts, unresolved identities, missing dependencies, and restore failures; make no production or retention changes.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 manages physical debris films deposited on optical shields, where accumulated matter changes transmission and the intervention governs cartridge measurement, handling, cleaning, and specimen preservation. This proposal manages digital detector-correction payloads whose continued resolver authority can outlive their validated detector context; it requires no debris shield, deposit measurement, or physical cleaning. Proposal 2 manages raw Markov-chain field configurations, separating statistical ensemble membership from storage and restart value. This proposal instead governs executable calibration layers applied to many detector events, separating default correction authority from historical retention through validity leases and resolver semantics. Its primary causal path is detector change to stale correction resolution to reconstructed-quantity inconsistency, followed by lease expiration and preservation-aware archival; it is not the simulation-sample selection and thinning path of proposal 2. Each proposal can be adopted independently because they govern different assets, authorities, triggers, and scientific failure modes.","revision_record":{"parent_version":null,"progress_targets_addressed":["Created one complete proposal at index 3.","Addressed a problem materially different from proposals 1 and 2.","Specified a distinct, independently adoptable intervention and causal path.","Provided explicit diversity comparisons with every earlier sealed proposal.","Included operational authority, safeguards, rivals, falsifiers, and bounded first evidence."],"conceptual_changes":["Initial formulation; no parent version.","Instantiated accumulated layers as successive detector calibration and alignment payloads.","Separated payload authority to resolve by default from byte retention and historical reconstruction value."],"operational_changes":["Initial formulation; no parent version.","Introduced bounded validity leases, resolver conflict detection, dependency-gated tiering, quarantine, archive reconstruction tests, and tombstones.","Restricted the first step to a shadow registry and isolated reconstruction for a retired subsystem."],"evidence_changes":["Initial formulation; no parent version.","Specified resolver replay, seeded conflict cases, dependency auditing, and restoration of an existing reference reconstruction."],"claim_changes":["Initial formulation; no parent version.","Limited the contrastive claim to independently expiring calibration authority while preserving dependency-bearing historical payloads.","Made no claim of novelty, prevalence, demand, or effect size."]}}