{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp06_four_proposal_generalization60_20260803","cell_id":"bounded_rivalry_governance__criminology_forensic","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"brg_contestable_digital_forensics_tool_lease_p2_v0","proposal_index":2,"version":0,"title":"Contestable Digital-Forensics Tool Lease","problem":"A regional justice consortium must select a small number of digital-forensics platforms for shared laboratory use. Vendors compete for a scarce, multi-year purchasing position, but demonstrations on vendor-chosen devices and feature-heavy proposals permit winning through benchmark tailoring, unsupported recovery claims, low introductory pricing, proprietary evidence formats, or costly data egress. A winner can then convert initial selection into control over stored examinations, analyst workflows, and future procurement rather than continuing to win through verifiable forensic performance.","actors":["Digital-forensics software and appliance vendors","Public forensic laboratory analysts and quality managers","Regional justice consortium procurement board","Independent benchmark designers and reproducibility auditors","Information-security and privacy officers","Prosecution and defense disclosure representatives","Courts and case parties dependent on reviewable forensic outputs","Future vendors seeking entry"],"observable_state":"Before procurement, the board can observe vendor-controlled demonstrations, inconsistent definitions of successful recovery, limited independent reproduction of claimed results, proposed licenses with different export and migration terms, scoring criteria that emphasize feature counts or acquisition price, and bids for a small number of long-term deployment positions. It can also inspect whether losing vendors have a realistic future entry path and whether exported evidence remains reviewable without the winning vendor's system.","consequence":"The award may select the vendor best at demonstrations, bid construction, or lock-in rather than the platform that produces reproducible, provenance-preserving, reviewable results. Subsequent switching costs can weaken future rivalry, while false artifacts, excessive data capture, unavailable defense-review formats, or security failures impose costs outside the procurement arena.","affected_objective":"Select a bounded portfolio of digital-forensics tools whose outputs are reproducible, minimally intrusive, independently reviewable, and portable, while preserving future vendor entry and limiting procurement-driven lock-in.","intervention":"Replace the conventional long-term platform award with a contestable, time-limited tool lease. The consortium publishes a frozen solicitation and rulebook for two conditional deployment slots. Qualified vendors run their unmodified release candidates against sealed synthetic and consented known-reference device images containing documented files, deleted artifacts, corrupted structures, timestamps, encrypted containers, and decoy material. Independent operators—not vendor demonstrators—execute scripted workflows. Scoring combines verified recovery, false-artifact rate, provenance completeness, repeatability, privacy minimization, security controls, analyst workload, standardized export, migration cost, and total bounded cost. Leaders undergo reproduction on a held-out image set. Vendors must support a nonproprietary evidence-export floor and post performance security for promised migration, remediation, and incident-response obligations. Awards are time-limited, divided across complementary tool families, and reopened through scheduled challenger windows. Bid-pattern screens may refer suspected coordination for separate review but cannot determine guilt. A post-lease review compares benchmark performance with controlled operational observations before renewal or redesign.","structural_mapping":[{"archetype_element":"Rivalry purpose statement","domain_realization":"Use vendor rivalry to discover comparatively reliable, reviewable, and portable digital-forensics capabilities rather than to maximize feature claims or minimize introductory price."},{"archetype_element":"Scarce prize or selection constraint","domain_realization":"Two time-limited deployment leases, associated purchase commitments, and access to the consortium's shared forensic workflow."},{"archetype_element":"Competitor eligibility boundary","domain_realization":"Vendors must provide a supportable release candidate, disclose relevant dependencies and conflicts, permit scripted independent operation, meet security prerequisites, and accept export, audit, and performance-security terms."},{"archetype_element":"Contest arena boundary","domain_realization":"Permitted competition consists of price, verifiable tool performance, usability, security, and support terms. Benchmark tampering, undisclosed remote assistance, contact with scorers, competitor interference, sensitive-data retention, collusive bidding, and post-award obstruction of export are prohibited."},{"archetype_element":"Performance metric and scoring basis","domain_realization":"A composite rubric balances correct recovery against false artifacts, provenance gaps, repeatability failures, unnecessary data exposure, analyst burden, security, portability, migration cost, and bounded total cost."},{"archetype_element":"Fair process and due process layer","domain_realization":"Requirements, weights, tie-breaks, operator scripts, conflict rules, and protest deadlines are fixed before submissions; vendors receive auditable score explanations and may challenge execution or calculation errors before an independent reviewer."},{"archetype_element":"Anti-sabotage and anti-collusion guardrail","domain_realization":"Access logging, isolated evaluation environments, submission hashing, communication restrictions, bid-pattern screening, and graduated disqualification rules protect the comparison without treating statistical anomalies as verdicts."},{"archetype_element":"Externality and spillover boundary","domain_realization":"Synthetic and consented reference images keep live case data outside the contest; privacy minimization and defense-review exports enter the score; performance security covers specified remediation and migration obligations."},{"archetype_element":"Escalation and arms-race damper","domain_realization":"Each vendor receives the same evaluation time, operator support, hardware class, clarification opportunities, and limited benchmark queries, preventing success through unlimited tuning or demonstration staffing."},{"archetype_element":"Winner power and lock-in review","domain_realization":"A mandatory export floor, two complementary awards, contractually bounded switching terms, scheduled challenger windows, and pre-renewal impact review prevent an initial victory from becoming permanent control of evidence access or future rules."}],"mechanism_mapping":[{"mechanism_slug":"tender_or_rfp_process","role":"Publishes eligibility, requirements, evidence standards, evaluation weights, conflict disclosures, sealed bid procedures, debriefs, and protests around the scarce leases.","counterfactual_removal":"Without the structured and contestable solicitation, benchmark results could be overridden by discretionary vendor preference or criteria tailored after bids are known."},{"mechanism_slug":"contest_rulebook","role":"Freezes allowed assistance, operator procedures, scoring, tie-breaks, prohibited conduct, confidentiality, and appeal rules before testing begins.","counterfactual_removal":"Without a binding rulebook, vendors could receive unequal help, scorers could reinterpret successful recovery, and enforcement could vary by competitor."},{"mechanism_slug":"ranked_leaderboard_with_audit","role":"Produces a criterion-level comparison and requires independent reproduction of leading results on held-out device images before selection.","counterfactual_removal":"Without held-out audit, benchmark-specific tuning, unstable extraction, or fabricated performance could determine the award."},{"mechanism_slug":"multiple_award_or_portfolio_selection","role":"Selects two complementary tool families based on the resilience and evidentiary coverage of the combined portfolio rather than naming one universal winner.","counterfactual_removal":"A single winner would create a forensic monoculture and gain disproportionate control over stored examinations, analyst training, and future switching."},{"mechanism_slug":"externality_bond_or_liability_rule","role":"Requires performance security for defined migration, data-export, security-response, and remediation obligations that could otherwise fall on laboratories and case parties after vendor exit or failure.","counterfactual_removal":"A vendor could offer low entry costs while leaving the consortium to finance evidence conversion, incident response, or abandoned support later."},{"mechanism_slug":"challenger_access_window","role":"Reopens a bounded portion of the deployment portfolio on a fixed cadence and specifies qualification and unseat thresholds in advance.","counterfactual_removal":"The incumbent could turn accumulated data formats, trained users, and integrations into an effectively permanent position even when a later tool performs better."},{"mechanism_slug":"anti_collusion_monitoring","role":"Applies the same structural and bid-pattern screens across the field and refers suspicious coordination for separate investigation.","counterfactual_removal":"Vendors could coordinate prices, divide deployment slots, or submit cover bids while preserving the appearance of an active contest."},{"mechanism_slug":"post_contest_impact_review","role":"Compares controlled operational observations with the original purpose, including reproducibility, privacy, export usability, switching burden, and field concentration, before renewal.","counterfactual_removal":"The consortium could repeatedly renew a benchmark winner even after the metric ceased to represent safe forensic contribution or the lease produced lock-in."}],"causal_chain":["A small number of shared deployment positions and purchase commitments create vendor rivalry.","Vendor-controlled demonstrations and weakly bounded scoring allow strategic advantage through tailored examples, feature inflation, introductory pricing, or proprietary dependence.","A frozen solicitation converts the rivalry into a common comparison using independently operated tools and sealed reference images.","Balanced scoring makes false artifacts, provenance failures, excessive collection, analyst burden, and migration costs subtract from apparent recovery performance.","Held-out reproduction makes stable forensic output a more reliable route to selection than demonstration-specific tuning.","Equal evaluation resources, conduct rules, appeals, and collusion referral constrain spending races, favoritism, sabotage, and coordinated noncompetition.","Portfolio selection and an export floor prevent one award from controlling all forensic workflows or future access to examination records.","Performance security keeps specified failure and exit costs with the vendor rather than case stakeholders.","Challenger windows and post-lease review preserve future rivalry and revise or retire the arena when its score no longer tracks the stated purpose."],"baseline":"Use a conventional feature-and-price RFP followed by vendor demonstrations and a multi-year award. Procurement staff check minimum technical requirements, analysts provide usability feedback, and contract negotiations address support. This baseline can select an acceptable product but does not necessarily use common hidden evidence, independent operation, reproducibility audits, scored portability, bounded evaluation resources, or a credible route for future challengers.","nearest_rivals":["A conventional best-value RFP, which offers procedural comparison but can select proposal quality and vendor-controlled demonstrations rather than independently reproduced forensic output.","A pass/fail technical certification, which can exclude unsafe tools but does not compare qualified products for the scarce deployment positions or govern winner lock-in.","An in-house open-source tool build, which can increase inspectability and control but substitutes internal development for vendor rivalry and transfers maintenance risk to the consortium.","Purchasing several tools without portfolio scoring, which reduces single-vendor dependence but may duplicate capabilities, omit important evidence classes, and leave interoperability untested.","A short proof-of-concept deployment on live work, which provides realistic observations but exposes case data and case timelines before the contest's safety and disclosure boundaries have been validated."],"remaining_contrastive_claim":"The proposal's bounded claim is that a consortium already choosing among rival digital-forensics vendors can couple winning more closely to reproducible and reviewable forensic contribution by combining sealed comparative testing with portability obligations, divided leases, and real re-entry windows. It does not assert that competitive procurement is preferable where rights, security, or evidentiary duties cannot be protected by the arena.","authority_safety":{"decision_authority":"The regional procurement board may authorize the controlled evaluation and conditional lease process. Laboratory quality authorities retain validation decisions; courts and designated legal officials retain authority over admissibility, discovery, disclosure, and case use; competition or misconduct findings remain with the appropriate independent authority.","authorized_first_step":"Approve a no-award dry run using archived software releases, isolated hardware, synthetic and consented known-reference images, independent operators, preregistered scoring, and a held-out reproduction set. The dry run evaluates the rulebook and score without processing live evidence or changing an existing contract.","excluded_actions":["Processing live criminal-case evidence during the dry run","Treating benchmark selection as a finding of legal admissibility or scientific validity for every use","Awarding or cancelling a production contract from the dry-run ranking","Publishing exploitable security weaknesses, proprietary submissions, or vendor identities without agreed review","Allowing vendors to retain benchmark images or evaluation telemetry outside the isolated environment","Using anomalous bid or communication patterns as proof of collusion","Restricting defense access to reviewable exports because of vendor licensing","Permitting the procurement board to alter evidence, disclosure obligations, or case outcomes","Requiring reverse engineering beyond the access and audit terms accepted before entry"],"halt_rollback":"Stop testing and isolate the affected submission upon benchmark leakage, unauthorized network activity, malicious code behavior, identity or consent failure in reference data, unequal operator assistance, scorer conflict, or inability to reproduce the environment. Preserve signed logs for independent review, revoke credentials, withhold rankings, and invalidate affected runs. Because the first step changes no contract and uses copied reference materials, rollback returns to the existing procurement process without operational evidence conversion."},"negative_tests":{"strongest_counterevidence":"Performance rankings reverse on fresh held-out images or under a second independent operator; high-ranked tools create more false artifacts, privacy exposure, or unusable exports; vendors circumvent resource limits; qualified entrants withdraw because audit or security terms are infeasible; or divided leases increase complexity without preserving practical switching.","problem_falsifier":"The inferred problem is unsupported if the current procurement already uses sealed common images, independent operators, reproducibility audits, scored export and migration obligations, bounded evaluation resources, periodic credible re-entry, and evidence showing that proprietary dependence cannot affect future competition or forensic review.","intervention_falsifier":"The intervention fails if its ranking is no more reproducible or purpose-aligned than the conventional evaluation, if benchmark performance does not transfer to a fresh controlled corpus, if the export floor cannot support independent review, or if gaming, exclusion, security risk, collusion, or administrative burden defeats the bounded rivalry.","risks":["Vendors may infer and optimize the benchmark's production signature rather than improve general performance.","Synthetic or consented images may omit device conditions encountered in operational examinations.","Composite scoring weights may hide unacceptable weakness behind strength on unrelated criteria.","Mandatory audit access or performance security may exclude capable smaller vendors.","Two-tool portfolios may increase training, validation, and evidence-management complexity.","A standardized export floor may lose tool-specific context or lag new artifact types.","Benchmark disclosure could reveal exploitable tool or platform weaknesses.","Incumbents may exploit installed integrations even when formal challenger rules appear open.","Statistical bid screens may create false suspicion if treated as more than referrals."]},"next_evidence_step":"Conduct the no-award dry run with at least two independently operated archived tool releases and matched synthetic device images. Pre-register artifact-level ground truth, scoring weights, operator scripts, permitted clarifications, false-artifact definitions, export checks, privacy measurements, and stop conditions. After initial scoring, rerun the leading workflows with a different operator on an unseen image set and attempt to review the exported record without the originating tool. Record ranking stability, false artifacts, provenance completeness, unnecessary data capture, operator time, export loss, rule disputes, and security events. Use the results only to decide whether the evaluation protocol is sufficiently interpretable and safe for a later authorized procurement stage.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 addressed rivalry among forensic laboratory teams whose standing and development resources could reward low reported-error counts; it redirected that rivalry into a synthetic error-discovery league. This proposal addresses commercial vendors competing for scarce digital-forensics deployment leases, where demonstrations, proprietary formats, and installed dependence can disconnect winning from reproducible performance. Its intervention is a time-limited procurement arena with independent tool execution, evidence-portability obligations, performance security, portfolio awards, and challenger entry—not an analyst error-finding contest. Its causal path runs from vendor comparison through held-out reproduction and anti-lock-in contract structure to contestable tool selection, rather than from laboratory reputation incentives through rewarded defect disclosure to corrective learning. It is independently adoptable by a procurement consortium without establishing Proposal 1's league.","revision_record":{"parent_version":null,"progress_targets_addressed":["Materially different problem from proposal 1","Distinct actors, scarce prize, intervention, and causal path","Complete arena, scoring, authority, safeguards, rivals, falsifiers, and first evidence","Explicit contrast with every earlier sealed proposal"],"conceptual_changes":["Initial proposal focused on governing commercial tool-selection rivalry and post-award lock-in rather than rivalry over laboratory error reporting."],"operational_changes":["Specified two conditional leases, sealed reference images, independent operators, held-out reproduction, standardized export, performance security, and challenger windows."],"evidence_changes":["Defined a reversible no-award dry run that tests ranking stability, reviewable export, and protocol safety without live evidence."],"claim_changes":["Restricted the claim to purpose-alignment and contestability within an already-rivalrous procurement decision; made no claim of novelty, prevalence, demand, effect size, or established efficacy."]}}