{"schema_version":1,"research_id":"eoa_inverse_innovation_exp06_external_evaluation_20260803","source_assessment_id":"bounded_rivalry_governance__human_computer_interaction:P2:v0","cell_id":"bounded_rivalry_governance__human_computer_interaction","search_queries":["notification attention auction credits applications interruptions research","CHI notification management app priority interruptibility user study notifications burden","site:developer.android.com notifications priority Do Not Disturb notification channels official","site:developer.apple.com notification interruption level Focus official","\"auction\" notifications attention user applications","\"attention\" \"notification\" bidding system application","notification system application declared utility cost interruption Horvitz","notification attention allocation mechanism app budgets credits","site:source.android.com notification cooldown repeated notifications Android official","site:support.google.com Android notification cooldown official repeated notifications","Pielot in situ study mobile phone notifications 63.5 notifications disable apps study","notification overload users disable notifications empirical study smartphone","Productive anxious lonely 24 hours without push notifications CHI paper DOI","batching smartphone notifications well being study primary paper notification batching","notification auction Instagram production paper ACM fair notification optimization","site:research.facebook.com \"Fair Notification Optimization\""],"sources":[{"source_id":"S1","title":"Fair Notification Optimization: An Auction Approach","publisher":"arXiv; authors affiliated with Columbia University and Meta","url":"https://arxiv.org/abs/2302.04835","source_class":"PRIMARY_RESEARCH","publication_date":"2023-02-09","accessed_at":"2026-08-03","claims_supported":["Notification opportunities have already been modeled as auction items, with notification types receiving faux-currency budgets.","The system used first- or second-price auctions with pacing.","A second-price version was A/B tested and launched in production for some Instagram notifications.","Decentralized notification teams can compete for user attention, over-send, induce habituation, and cause users to disable notifications."]},{"source_id":"S2","title":"Managing notifications","publisher":"Apple Developer","url":"https://developer.apple.com/design/human-interface-guidelines/managing-notifications?changes=_5","source_class":"OFFICIAL_GUIDANCE","publication_date":"Undated; current guidance accessed 2026-08-03","accessed_at":"2026-08-03","claims_supported":["Apple identifies the tension between timely information and unwanted interruption and provides Focus and scheduled delivery.","Developers assign Passive, Active, Time Sensitive, or Critical interruption levels, while the system controls delivery behavior.","Apple warns against overstating urgency and prohibits Time Sensitive treatment for marketing.","Critical alerts are narrowly distinguished from ordinary notifications, supporting a protected channel."]},{"source_id":"S3","title":"About notifications","publisher":"Android Developers","url":"https://developer.android.com/develop/ui/compose/notifications","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"2026-07-28","accessed_at":"2026-08-03","claims_supported":["Android centrally mediates notification presentation using system templates, channels, importance levels, and Do Not Disturb rules.","Users can retain silent notifications in the drawer while suppressing interruption.","Android notification cooldown reduces appearance, sound, and vibration for rapid repeated notifications while exempting critical notifications.","The operating system already has the technical control points needed for a non-production allocation prototype."]},{"source_id":"S4","title":"Control notifications on Android","publisher":"Google Android Help","url":"https://support.google.com/android/answer/9079661?hl=en-GB","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"Undated; current help page accessed 2026-08-03","accessed_at":"2026-08-03","claims_supported":["Google provides app-, category-, and whole-device notification controls but requires users to configure them.","Notification cooldown is explicitly intended to manage sudden notification influxes.","Calls, alarms, priority conversations, and emergency alerts are exempted from cooldown.","Silent delivery remains available, demonstrating a practical safety net distinct from deletion."]},{"source_id":"S5","title":"My Phone and Me: Understanding People’s Receptivity to Mobile Notifications","publisher":"ACM CHI; author-hosted research page","url":"https://jovermeulen.com/Research/NotificationsCHI2016","source_class":"PRIMARY_RESEARCH","publication_date":"2016-05-07","accessed_at":"2026-08-03","claims_supported":["An in-situ study logged 10,372 notifications and 474 experience-sampling responses from 20 participants.","Perceived disruption and response time varied with presentation, alert type, relationship, and ongoing task.","Even useful or important notification content could be disruptive, supporting context-dependent rather than blanket delivery."]},{"source_id":"S6","title":"Effects of Intelligent Notification Management on Users and Their Tasks","publisher":"Association for Computing Machinery","url":"https://doi.org/10.1145/1357054.1357070","source_class":"PRIMARY_RESEARCH","publication_date":"2008-04-06","accessed_at":"2026-08-03","claims_supported":["A notification-management system using defer-to-breakpoint policies was implemented and evaluated.","The work found breakpoint detection technically workable, though imperfect at differentiating breakpoint types.","The user study supplied evidence that managed deferral can be acceptable and useful, establishing adjacent technical prior art."]},{"source_id":"S7","title":"Batching Smartphone Notifications Can Improve Well-Being","publisher":"Elsevier, Computers in Human Behavior","url":"https://www.sciencedirect.com/science/article/pii/S0747563219302596","source_class":"PRIMARY_RESEARCH","publication_date":"2019-12-01","accessed_at":"2026-08-03","claims_supported":["A randomized field experiment with 237 participants modified Android notification delivery schedules.","Three-times-daily batching improved reported attentiveness, mood, control, and stress-related outcomes relative to usual delivery.","Completely suppressing alerts produced more anxiety and fear of missing out, supporting preservation of wanted information as a safety net.","Hourly batching showed little advantage, indicating that intervention parameters materially affect outcomes."]},{"source_id":"S8","title":"An In-Situ Study of Mobile Phone Notifications","publisher":"ACM MobileHCI; author-hosted paper","url":"https://pielot.org/pubs/Pielot2014-MobileHCI-Notifications.pdf","source_class":"PRIMARY_RESEARCH","publication_date":"2014-09-23","accessed_at":"2026-08-03","claims_supported":["A one-week in-situ study of 15 participants observed a median 63.5 notifications per day.","Notifications were commonly viewed within minutes even when phones were silent.","The study demonstrates visible notification volume and behavioral salience, while its small sample limits prevalence generalization."]}],"problem_evidence":{"support":"STRONG","rationale":"Multiple primary studies show frequent, context-sensitive interruption and measurable consequences, while Apple and Google have deployed Focus, category controls, silent delivery, and cooldown specifically to manage unwanted interruption. The evidence establishes a consequential notification-management problem and the inadequacy of blanket suppression. It does not establish how often cross-publisher strategic escalation, identity splitting, or false urgency occurs, so those narrower causal allegations remain unmeasured.","source_ids":["S2","S3","S4","S5","S6","S7","S8"]},"stakeholder_evidence":{"support":"MODERATE","rationale":"Apple and Google are identifiable operating-system authorizers and have expressed the underlying need through official notification-management guidance and product features. Their systems already preserve critical channels and silent queues. No source expresses interest in a cross-application credit exchange, publisher aggregation, issuer appeals, or independent contest review; adopter pull is therefore for the problem class, not the proposed mechanism.","source_ids":["S2","S3","S4"]},"prior_art":{"proximity":"SUBSTANTIAL_COLLISION","closest_analogues":[{"name":"Meta/Instagram Fair Notification Optimization auction","similarity":"Directly treats notification opportunities as auction items, gives competing notification types faux-currency budgets, applies auction pacing, and has been production-tested and launched for some Instagram notifications.","remaining_difference":"It allocates among notification types or internal teams within one platform and incorporates team/platform objectives. The candidate instead proposes operating-system-wide competition among independently controlled publishers, explicit user category weights, common-control aggregation, standardized salience, protected channels, issuer due process, anti-collusion review, and platform self-preference oversight.","source_ids":["S1"]},{"name":"Apple Focus and interruption levels","similarity":"Separates silent or scheduled delivery from interruption, lets users establish protected periods, distinguishes urgency levels, and reserves Critical alerts for narrowly defined cases.","remaining_difference":"It uses user settings and developer-declared interruption classes rather than finite slots, publisher-level nontransferable credits, sealed bids, common-control caps, or contest appeals.","source_ids":["S2"]},{"name":"Android channels, Do Not Disturb, importance, and notification cooldown","similarity":"The operating system centrally controls salience, supports category-specific user choices, preserves silent access, dampens rapid repeated alerts, and exempts critical categories.","remaining_difference":"Cooldown attenuates repetition and current controls filter by app or category; they do not require issuers to reveal relative priority by spending a capped budget or aggregate affiliated applications under one publisher cap.","source_ids":["S3","S4"]},{"name":"Batching and context-aware deferral systems","similarity":"These systems defer or batch notifications to reduce interruption while retaining later access, with experimental evidence that timing policy affects acceptability and well-being.","remaining_difference":"They optimize delivery timing from schedules or inferred interruptibility rather than governing strategic rivalry among issuers through opportunity-cost bids and anti-evasion rules.","source_ids":["S5","S6","S7"]}],"distinctive_claim_remaining":"Relative to chronological delivery, static Focus allowlists, context/relevance ranking without issuer budgets, and Meta-like notification auctions confined to one platform, an operating-system mechanism that aggregates applications by controlling publisher and allocates finite protected-period interruption slots using capped nontransferable bids plus explicit user category weights will increase the proportion of interruptions users retrospectively endorse and reduce broad muting or reversal, without increasing critical-message misses or configuration burden. The claim fails if bids add no information beyond user rules or arrival time, affiliated publishers can materially gain share by splitting identities or categories, protected-channel exceptions absorb routine traffic, or explanation and configuration costs erase the reduction in interruption burden.","confidence":"HIGH"},"implementation_evidence":{"support":"MODERATE","rationale":"Production use of a faux-currency notification auction establishes algorithmic feasibility, and Apple/Android demonstrate that operating systems can centrally standardize presentation, defer alerts, apply category rules, and preserve critical channels. A mock replay is technically straightforward. Production feasibility remains uncertain because publisher common-control attribution, cross-app metadata handling, protected-channel adjudication, appeals, anti-collusion investigation, and neutral treatment of first-party applications are untested. Those functions require privacy, accessibility, security, competition-governance, and developer-policy authority beyond an ordinary application team.","source_ids":["S1","S2","S3","S4","S6","S7"]},"scores":{"meaningful_impact":{"score":4,"rationale":"The problem is frequent and affects attention, stress, control, and access to wanted information; successful selective interruption could improve a broadly used operating-system surface.","source_ids":["S5","S7","S8"]},"stakeholder_pull":{"score":3,"rationale":"Both major mobile operating-system ecosystems actively manage the problem, but no identified authorizer has requested an issuer-credit exchange.","source_ids":["S2","S3","S4"]},"incremental_advantage":{"score":2,"rationale":"The central auction-with-faux-budgets mechanism substantially collides with deployed Instagram prior art. Incremental value depends on cross-publisher governance, user weighting, identity aggregation, and protected-channel integrity rather than the auction itself.","source_ids":["S1"]},"distinctiveness_plausibility":{"score":3,"rationale":"The cross-application, publisher-aggregated, user-subordinate governance bundle is contrastive and testable, but its advantage over simpler OS controls or a relevance ranker is not yet demonstrated.","source_ids":["S1","S2","S3","S4"]},"technical_implementability":{"score":3,"rationale":"Mock allocation and explanation interfaces are straightforward and core auction and deferral components have precedents. Reliable common-control attribution, exception governance, privacy-preserving monitoring, and OS-scale integration are materially harder.","source_ids":["S1","S3","S6","S7"]},"adoption_authority_feasibility":{"score":2,"rationale":"Only an operating-system vendor can safely and comprehensively mediate cross-app interruptions. Apple and Google possess that authority, but the proposal would require coordinated product, developer-policy, privacy, security, accessibility, and competition-governance approval.","source_ids":["S2","S3","S4"]},"evidence_readiness":{"score":3,"rationale":"A synthetic replay can test allocation coherence, comprehension, and obvious evasion routes immediately, but user benefit, publisher behavior, and production safety require new empirical evidence.","source_ids":["S1","S5","S7"]},"safety_net_benefit":{"score":4,"rationale":"Silent queueing and separately governed critical channels preserve access better than blanket suppression, and experimental evidence indicates complete suppression can increase anxiety and fear of missing out. Misclassification risk remains.","source_ids":["S2","S3","S4","S7"]},"scalability":{"score":4,"rationale":"Once built into an operating system, the allocation computation is lightweight and applies across applications. Governance, publisher attribution, investigation, and appeals—not auction computation—are the scaling constraints.","source_ids":["S1","S3"]}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"10K_TO_50K","scope":"Preregistered three-week mock replay for approximately 24–40 consented participants, including synthetic scenario generation, a clickable notification-center prototype, accessibility checks, red-team scripts, participant compensation, and analysis.","confidence":"MODERATE","assumptions":["No production notifications are intercepted.","One HCI researcher, one prototype engineer, and part-time accessibility/statistical support contribute roughly 6–10 person-weeks.","Existing institutional review and participant-recruitment infrastructure are available."],"source_ids":["S5","S7"]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"OS-vendor research prototype with local event schema, sealed-credit allocator, publisher-identity test registry, explanations, audit logs, simulated protected channels, privacy/security review, and internal dogfood tooling.","confidence":"LOW","assumptions":["Approximately 4–8 FTE-years are not required; scope is limited to an internal prototype and controlled dogfood.","No external developer policy, appeals operation, or production common-control registry is launched.","Cost is a resource-equivalent engineering and review estimate, not a vendor quote."],"source_ids":["S1","S2","S3"]},"operational_launch":{"band_2026_usd":"5M_TO_25M","scope":"Phased mobile-OS launch including framework APIs, settings UX, on-device allocation, developer documentation, publisher-control registry, abuse detection, accessibility and localization, privacy/security validation, first-party neutrality audit, telemetry, support, and rollback infrastructure.","confidence":"LOW","assumptions":["A major operating-system vendor leads the launch.","The feature spans at least two annual OS release cycles and requires multidisciplinary engineering, policy, legal, trust-and-safety, and developer-relations work.","The range excludes compensation paid to publishers and any monetary credit market."],"source_ids":["S1","S2","S3","S4"]},"annual_recurring":{"band_2026_usd":"1M_TO_5M","scope":"Ongoing abuse-screen maintenance, publisher-identity disputes, protected-channel audits, developer appeals, accessibility regression testing, first-party neutrality review, telemetry analysis, policy updates, and user support.","confidence":"LOW","assumptions":["Most allocation runs on-device using existing notification infrastructure.","A small permanent governance and engineering team handles exceptions and investigations.","Appeal volume remains bounded and anomaly screens never impose automatic penalties."],"source_ids":["S1","S2","S3"]}},"verified_pipeline_gates":{"externally_supported_problem":{"status":"YES","reason":"Primary field and experimental studies plus official OS interventions independently support frequent, disruptive notifications and the need to preserve wanted alerts.","source_ids":["S2","S3","S5","S7","S8"]},"externally_credible_adopter_or_authorizer":{"status":"YES","reason":"Apple and Google/Android are identifiable OS authorizers already exercising central control over interruption, salience, categories, Focus/DND, cooldown, and critical exceptions.","source_ids":["S2","S3","S4"]},"distinct_testable_incremental_claim":{"status":"YES","reason":"After accounting for the Instagram auction collision, the remaining claim concerns cross-publisher common-control aggregation, user-weighted capped bids, protected-channel integrity, and resistance to identity splitting, all measurable against explicit comparators.","source_ids":["S1","S2","S3"]},"bounded_next_evidence_step":{"status":"YES","reason":"A preregistered mock replay can compare four allocation policies without touching real notifications and can include predefined benefit, burden, comprehension, and adversarial-evasion falsifiers.","source_ids":["S5","S7"]},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The next step can use only synthetic notifications and fictitious publishers, exclude every real critical channel, obtain participant consent, preserve chronological fallback, and halt on data or accessibility violations. Production deployment is not authorized by this gate.","source_ids":["S2","S3","S4"]},"credible_cost_scope_and_range":{"status":"YES","reason":"Four resource-equivalent bands are scoped by stage and staffing assumptions. Prototype costs have moderate confidence; OS launch and recurring governance estimates remain low-confidence because no vendor quote or proprietary staffing data were available.","source_ids":["S1","S2","S3"]}},"next_evidence_step":"Run a preregistered, three-week, within-participant mock replay with 24–40 consented participants, six fictitious applications controlled by four declared publishers, and no real notification delivery. Counterbalance four policies: chronological delivery; static Focus allowlists; a user-weighted relevance/expiry ranker with no issuer budget; and the proposed publisher-aggregated capped-credit exchange. Include duplicate payloads, false expiry, category inflation, affiliated-app splitting, coordinated bid rotation, maximal bidding, and first-party self-preference probes. The primary endpoint is the proportion of displayed interruptions participants say should have interrupted, with secondary endpoints of reversed deferrals, missed wanted-but-noncritical messages, configuration time, explanation comprehension with keyboard and screen-reader use, and concentration by publisher. Predeclare failure if the exchange does not improve endorsed-interruption precision by at least 10 percentage points over the best comparator without worsening wanted-message recall by more than 5 percentage points; if configuration/review time exceeds time saved from avoided interruptions; if fewer than 80% of participants correctly explain representative allocation outcomes; if protected-channel misuse exceeds 1% of adversarial routine messages; or if identity splitting raises an affiliated publisher's interruption share by more than 5 percentage points. Treat results only as evidence about rule coherence and user-facing allocation, not production safety or realized impact.","blocking_evidence":["No external evidence shows that cross-application publisher bids encode user-valued urgency better than arrival time, user rules, or relevance ranking.","The production Instagram auction demonstrates substantial prior-art collision; incremental benefit from publisher aggregation and user weighting is untested.","No field evidence establishes the prevalence of common-control splitting, bid coordination, or protected-channel laundering among independent notification publishers.","No evidence shows that ordinary users can configure category weights and understand allocation explanations with acceptable cognitive and accessibility burden.","No operating-system vendor has expressed willingness to create publisher identity, appeals, independent review, or first-party neutrality infrastructure.","Production effects on missed time-sensitive information, user trust, privacy, developer adaptation, and migration to off-arena channels remain unknown."],"research_disposition":"PARTNERED_RESEARCH_PROGRAM","world_novelty_boundary":"This evaluation does not measure world novelty, patentability, freedom to operate, market size, or realized impact. The bounded search found a direct auction-and-faux-budget notification system deployed for some Instagram notifications, so the auction core cannot be treated as novel. The only remaining evaluated boundary is the contrast between that internal-platform practice and an OS-wide, user-weighted, publisher-aggregated governance layer with protected channels, due process, anti-evasion controls, and first-party neutrality review. Patent literature, proprietary OS experiments, unpublished systems, and implementations outside the eight direct sources were not assessed.","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_version":0,"controller_recommendation":{"action":"STOP_EMPIRICAL_RESEARCH_NEEDED","repairable":false,"material_progress_observed":true,"progress_targets":["Demonstrate that capped publisher bids add predictive information about wanted interruption beyond chronological order, static Focus rules, and user-weighted relevance ranking.","Show that configuration and explanation burden is smaller than the interruption burden avoided, including for keyboard and screen-reader users.","Verify that common-control aggregation prevents affiliated-app splitting and that protected-channel misuse remains below preregistered thresholds.","Establish that wanted-message recall and noncritical time-sensitive delivery are not materially degraded.","Obtain documented interest and authority boundaries from an operating-system notification owner plus privacy, security, accessibility, and competition-governance reviewers before any production trial.","Differentiate the cross-publisher governance claim from Meta's deployed notification auction using empirical ablations rather than architectural description alone."],"reason":"Web research established the problem, credible OS authorizers, technical precedents, and a substantial collision with Meta's production notification auction. The residual value claim—cross-publisher user benefit, resistance to identity and category evasion, acceptable comprehension burden, and safe exception handling—cannot be resolved by further bounded web search. It requires participant testing and later proprietary OS-partner evidence; under the controller rule this is an empirical-research stop, with repairable set to false."},"proposal_index":2}