{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp06_four_proposal_generalization60_20260803","cell_id":"bounded_rivalry_governance__human_computer_interaction","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"brg_hci_bounded_interruption_exchange_002","proposal_index":2,"version":0,"title":"Bounded Interruption Exchange for Application Notifications","problem":"Installed applications compete continuously for the same limited opportunity to interrupt a user. Each issuer can improve its own exposure by sending more messages, declaring routine events urgent, splitting campaigns across affiliated applications, or using visually coercive presentation. Because each issuer benefits from being noticed while the user bears the combined switching and evaluation burden, independent notification optimization can become a salience and frequency arms race. Blanket muting then suppresses both low-value messages and messages the user would have wanted to receive.","actors":["People receiving notifications","Applications and services issuing notifications","Affiliated application publishers","Operating-system notification service","Accessibility and interaction-design reviewers","Privacy and security reviewers","Independent contest-integrity reviewer","Developers appealing eligibility or foul decisions","Emergency and safety-notice authorities outside the contest arena"],"observable_state":"During user-defined protected work periods, several applications request immediate presentation within short intervals; routine messages use urgent labels, repeated reminders, badges, or takeover surfaces; affiliated applications receive separate notification allowances despite common control; the operating system exposes little explanation for why one message interrupted while another was deferred; and users respond by muting broad categories or disabling notifications altogether.","consequence":"The user must absorb repeated context switches or continually maintain complex allowlists. Legitimate urgency cues can lose meaning, coercive presentation can outperform useful timing, publishers with more applications can obtain more interruption opportunities, and broad defensive muting can delay wanted but nonemergency information.","affected_objective":"Allocate interruptive attention according to user-defined priorities while preserving applications' ability to signal which of their pending messages matters most, without rewarding frequency escalation, deceptive urgency, publisher fragmentation, or platform self-preferencing.","intervention":"Add an operating-system-level bounded interruption exchange for user-designated protected periods. Silent delivery remains available, but each time window contains a finite number of nonemergency interruption slots. Before entering, an issuer must declare its controlling publisher, notification category, user-facing purpose, expiry time, requested action, and urgency basis. The user sets category weights and exclusions; emergency, accessibility, authentication, and safety notices follow separately governed noncontestable channels. Eligible issuers receive periodic, nontransferable interruption credits under a publisher-level cap and submit sealed credit bids for pending messages. The winning rule combines the bid with the user's explicit category weight; ties use the earliest declared expiry and then a neutral lottery. A winning issuer spends its credits regardless of whether the user clicks, making interruption itself costly rather than rewarding engagement. The operating system controls visual salience so issuers cannot buy a louder surface. False urgency, undeclared common control, duplicate-message laundering, bid coordination, or attempts to bypass silent deferral are predefined fouls. Users can inspect why a message interrupted, change priorities, pause the exchange, or opt out. Issuers can appeal eligibility or foul findings but not ordinary lost bids. Fixed screens flag suspicious identity and bidding patterns for independent investigation rather than automatic punishment. Periodic review examines user overrides, deferred-message expiry, protected-channel misuse, publisher concentration, and platform self-preferencing, then adjusts credit endowments, eligibility, or the decision to retain the exchange.","structural_mapping":[{"archetype_element":"Rivalry purpose statement","domain_realization":"Use bounded competition to make each issuer reveal which of its own pending messages it considers worth spending a scarce interruption opportunity on, while keeping allocation subordinate to the user's expressed priorities."},{"archetype_element":"Scarce prize or selection constraint","domain_realization":"The prize is one of a finite number of interruptive display slots during a user-defined protected period; losing messages remain silently accessible rather than being deleted."},{"archetype_element":"Competitor eligibility boundary","domain_realization":"An issuer may bid only after declaring publisher control, category, purpose, requested action, expiry, and urgency basis and satisfying privacy, security, and accessibility requirements."},{"archetype_element":"Contest arena boundary","domain_realization":"Issuers may choose which pending message to bid for and how many allotted credits to spend, but may not control visual salience, fabricate urgency, multiply identities, duplicate a message, transfer credits, or bypass deferral."},{"archetype_element":"Performance metric and scoring basis","domain_realization":"Slots are assigned by a frozen effective-bid rule combining nontransferable issuer credits with explicit user category weights, followed by declared-expiry and neutral-lottery tie-breaks."},{"archetype_element":"Fair process and due process layer","domain_realization":"The operating system publishes eligibility, credit, tie-break, foul, logging, and appeal rules; users can inspect allocation reasons, while issuers can challenge factual eligibility and misconduct findings."},{"archetype_element":"Anti-sabotage and anti-collusion guardrail","domain_realization":"Publisher identity, duplicate payloads, cross-application timing, bid rotation, and credit transfers are screened consistently; anomalies are referred for investigation and are not treated as verdicts."},{"archetype_element":"Externality and spillover boundary","domain_realization":"Every interruptive win consumes credits independent of clicks, so the issuer bears a scarce budget cost for imposing a context switch; silent queueing preserves access without imposing that externality."},{"archetype_element":"Escalation and arms-race damper","domain_realization":"Publisher-level credit caps, standardized visual presentation, and a fixed slot count prevent additional messages, affiliated applications, or louder cues from creating unlimited interruptive capacity."},{"archetype_element":"Winner power and lock-in review","domain_realization":"Credits expire and are periodically reissued, every slot is a new contest, common notification infrastructure remains open to eligible challengers, and the platform's own applications receive no rulemaking privilege."},{"archetype_element":"Protected floor or noncontestable domain","domain_realization":"Emergency, safety, authentication, and accessibility-critical notices do not compete with promotional or routine operational messages and are governed by separate narrow eligibility rules."},{"archetype_element":"Learning and recalibration loop","domain_realization":"Periodic review compares allocation records with explicit user overrides, expired deferred messages, foul investigations, and publisher concentration to revise or retire the arena."}],"mechanism_mapping":[{"mechanism_slug":"auction_with_eligibility_and_externality_rules","role":"Allocates each scarce interruption slot through sealed nonmonetary bids, admits only declared and qualified issuers, incorporates explicit user category weights, and charges credits for imposing an interruption.","counterfactual_removal":"Without the auction, the operating system would need a fixed priority order or opaque prediction model and would lose the opportunity-cost signal created when an issuer must choose which of its messages merits its limited credits."},{"mechanism_slug":"contest_rulebook","role":"Freezes publisher eligibility, bid syntax, user-weight application, tie-breaks, prohibited notification tactics, evidence standards, and appeal rights.","counterfactual_removal":"Without a binding rulebook, the platform could change priority treatment selectively, issuers could not distinguish legitimate optimization from a foul, and allocation or enforcement would not be contestable."},{"mechanism_slug":"spending_cap_or_resource_cap","role":"Sets a publisher-level ceiling on nontransferable interruption credits and counts affiliated applications together.","counterfactual_removal":"Without the cap, issuers could escalate bids or notification volume indefinitely, and a publisher could multiply applications to obtain more opportunities than a single competitor."},{"mechanism_slug":"sabotage_or_foul_penalty_schedule","role":"Defines graduated consequences for fabricated urgency, identity splitting, duplicate-message laundering, unauthorized takeover surfaces, credit transfer, and repeated bypass attempts.","counterfactual_removal":"Without predefined fouls and graduated consequences, deceptive salience and identity manipulation could remain cheaper routes to user attention than submitting a legitimate bid."},{"mechanism_slug":"anti_collusion_monitoring","role":"Screens the full field for undeclared common control, reciprocal bid suppression, rotating winners, synchronized duplicates, and off-ledger credit coordination, then refers anomalies to an independent reviewer.","counterfactual_removal":"Without cross-round monitoring, coordinated publishers could make repeated allocations appear competitive while quietly dividing time windows or crowding out unaffiliated issuers; examining one notification at a time would miss the pattern."},{"mechanism_slug":"antitrust_or_competition_review","role":"Checks whether the operating-system provider favors its own applications, whether publisher identity splitting defeats the cap, and whether access to notification infrastructure remains available on equal terms.","counterfactual_removal":"Without competition review, the platform owner or a concentrated publisher could comply with individual bids while controlling eligibility, privileged channels, or identity definitions in ways that foreclose future rivalry."},{"mechanism_slug":"post_contest_impact_review","role":"Examines whether the exchange allocated wanted interruptions, displaced harm into silent queues or protected channels, encouraged new gaming strategies, or concentrated attention among a few publishers.","counterfactual_removal":"Without retrospective review, a formally compliant exchange could persist even if its bid rule no longer tracks user priorities or issuers adapt by moving manipulation outside the measured arena."}],"causal_chain":["Multiple issuers pursue the same scarce interruptive attention and can improve their private exposure by escalating frequency, salience, or claimed urgency.","The operating system converts unconstrained interruption into a finite, explicitly governed prize while preserving silent delivery as a non-rival alternative.","Publisher-level eligibility and identity aggregation prevent applications from obtaining extra standing merely by fragmenting into additional issuers.","Periodic credit caps force each publisher to choose among its own messages instead of bidding maximally on every event.","User-defined category weights keep issuer willingness to spend subordinate to the recipient's stated priorities.","Standardized presentation, foul rules, and monitoring block louder surfaces, false urgency, duplication, and coordination as alternative paths to winning.","Repeated reallocation prevents any single win from granting permanent attention rights, while independent review checks self-preferencing and access control.","User overrides and post-period evidence reveal whether the allocation rule remains coupled to wanted interruption rather than merely shifting the arms race into new tactics."],"baseline":"Applications independently decide when and how often to notify, subject to coarse operating-system permissions, per-application settings, and optional focus-mode allowlists. The user or a hidden relevance ranker resolves conflicts after issuers have already created them; applications do not face a shared interruption budget, publisher identities are not jointly counted, and allocation decisions lack a common contest and appeal structure.","nearest_rivals":["Focus mode or do-not-disturb: protects time through blanket suppression and static allowlists but does not elicit relative priority from several eligible issuers competing for a limited exception.","Machine-learned notification ranking: can order messages using predicted relevance but centralizes allocation in an opaque model and does not make issuers ration requests through a capped, auditable budget.","Per-application rate limits: constrain volume but generally treat each application separately, cannot discover which pending message the issuer values most, and are vulnerable to publisher identity splitting.","User notification preference centers: provide direct control but require the user to anticipate and maintain rules for many applications rather than governing issuers' strategic competition at each scarce interruption opportunity.","Chronological or first-arrival delivery: is legible but rewards early and repeated submission, coupling winning to timing aggression rather than user priority."],"remaining_contrastive_claim":"Even if focus modes add relevance ranking, rate limits, and explanation screens, the remaining distinction is a repeated governed rivalry in which publishers spend capped, nontransferable credits for finite interruption slots under user-weighted rules, common-control aggregation, due process, anti-collusion screens, and platform self-preference review. If issuer priority cannot be meaningfully expressed through opportunity cost, or if interruptions are not scarce and strategically contested, the proposal reduces to ordinary notification filtering.","authority_safety":{"decision_authority":"The operating-system notification product owner may authorize a non-production prototype with approval from privacy, security, accessibility, and human-subjects review leads. Only the user may set personal category weights or opt into protected periods. Emergency and safety authorities retain control of separately governed critical channels.","authorized_first_step":"A research lead may replay synthetic and participant-donated notification scenarios through a mock notification center, using fictitious issuer identities and nonmonetary credits, to test allocation logic, explanations, accessibility, gaming routes, and user comprehension without delaying or suppressing real notifications.","excluded_actions":["Intercepting, delaying, suppressing, or reprioritizing production notifications","Placing emergency, safety, authentication, or accessibility-critical notices into the competitive pool","Selling interruption credits for money or allowing credit transfer between publishers","Inferring category weights from sensitive content without explicit user configuration","Rewarding or replenishing credits solely from clicks, dwell time, or other engagement proxies","Sharing one issuer's message content, bid, or user-specific outcome with competitors","Automatically penalizing an issuer from an anomaly screen without investigation and appeal","Using the prototype to favor applications owned by the operating-system provider"],"halt_rollback":"Halt the study if any real notification enters the prototype, participant-donated content exceeds consent, a simulated critical notice is routed into the contest pool, accessibility prevents a participant from inspecting or overriding an allocation, issuer identity is exposed across participants, or scoring rules change after replay begins. Disable the mock scheduler, restore chronological mock display, quarantine affected logs, notify the review leads, and resume only under a corrected preregistered protocol."},"negative_tests":{"strongest_counterevidence":"In blinded scenario review, users' wanted interruptions are explained by stable personal allowlists or message arrival time, while issuer bidding adds no decision-relevant information; observed notification burden persists when messages come from one noncompeting issuer. That would indicate a preference-management or interaction-design problem rather than a rivalry-governance problem.","problem_falsifier":"Users do not face a scarce interruption constraint, issuers cannot strategically alter their share of attention, or messages can be presented concurrently without context-switching, salience, or evaluation costs.","intervention_falsifier":"Capped bids fail to correspond to any user-recognized priority, publishers can cheaply evade caps through identity or category manipulation, protected-channel exceptions absorb ordinary competition, explanations and appeals are unusable, or the exchange produces more user configuration and monitoring burden than the conflicts it governs.","risks":["Issuers may treat credits as a license to send deceptive messages rather than as a meaningful constraint.","A uniform publisher cap may disadvantage services whose legitimate event volume differs substantially from that of other issuers.","Publisher-control attribution can be incomplete, enabling identity splitting, or overbroad, combining genuinely independent services.","Explicit category weights can become stale and impose continuing configuration work on users.","Ties and low-credit periods may defer time-sensitive but noncritical information.","Standardized salience can make distinct categories harder to recognize or can conflict with accessibility needs.","Foul monitoring can expose message metadata or create cross-application surveillance.","The operating-system provider may manipulate eligibility, protected categories, or credit endowments to favor its own applications.","Issuers may move the arms race into email, badges, in-application prompts, or other channels outside the arena.","User feedback collected for review may itself become an interruption burden."]},"next_evidence_step":"Conduct a preregistered three-week mock replay with synthetic notification streams from six fictitious applications controlled by four declared publishers and a bounded set of consented participants. Each participant configures protected periods and broad category weights, then reviews counterbalanced timelines produced by chronological delivery, static focus rules, and the proposed exchange without receiving real interruptions. Record which messages participants say should have interrupted, which deferrals they reverse, whether allocation explanations are understood with keyboard and screen-reader use, and how often protected-channel classifications are disputed. Red-team publisher splitting, duplicate payloads, false expiry, coordinated bid rotation, maximal bidding, and platform self-preferencing. Treat the exercise only as evidence about rule coherence and observable gaming routes, not production effects.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 governs an episodic contest among internal interface-design teams for one reversible default deployment in an AI-assisted document-review workflow; its evidence object is competing prototypes, and its causal path runs through common usability tasks, multidimensional scoring, evaluator audit, and a later challenger window. Proposal 2 addresses continuous runtime competition among installed notification issuers for a person's interruptive attention. Its prize is a recurring display slot, its intervention is a user-weighted sealed credit exchange with publisher-level budgets and standardized salience, and its causal path works by forcing issuers to ration interruption requests while preventing identity, urgency, and presentation escalation. It can be adopted as notification infrastructure without running a design-selection contest, changing the AI-review interface, or selecting any interface team, so it is not a feature or population variant of proposal 1.","revision_record":{"parent_version":null,"progress_targets_addressed":[],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}