{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp06_four_proposal_generalization60_20260803","cell_id":"representation_independent_interface_contract__religious_studies_theology","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"ric-ritual-evidence-record-001","proposal_index":1,"version":0,"title":"Behavioral Contract for Comparative Ritual Evidence Records","problem":"A comparative-religion archive stores observations of rituals using project-specific tables, category hierarchies, tag orders, and coding workflows. Researchers’ queries and teaching materials come to depend on those internal choices—for example, treating an omitted field as evidence of absence or using a database’s tag order as ritual sequence. When the archive adopts a different ontology, repository, or coding method, results change even when the underlying observations and scholarly qualifications have not. The archive lacks a representation-independent definition of what a usable ritual evidence record must do.","actors":["Comparative-religion researchers who query or cite records","Archivists and digital-humanities staff who maintain implementations","Field researchers and source curators who supply observations and provenance","Tradition specialists or community advisers who review sensitive descriptions","Research-integrity or ethics officers overseeing access restrictions"],"observable_state":"The same bounded pilot corpus is encoded in two independently structured repositories. Identical public operations—retrieve cited source segments, distinguish reported emic terms from analyst-applied categories, filter by declared attributes, compare records, expose uncertainty and access restrictions, and export citation-stable results—produce divergent answers. Observable discrepancies include absent versus unknown values being conflated, emic terms being replaced by comparative categories, source links being dropped, tag order appearing as event order, and restricted material appearing in one export but not the other.","consequence":"Repository migrations or alternative coding systems can silently alter comparative claims, citations, and access behavior. Researchers cannot tell whether two repositories are valid substitutes, while maintainers either freeze incidental structures or require every downstream analysis to be manually repaired.","affected_objective":"Preserve source-grounded scholarly meaning, qualification, and access constraints while allowing the archive’s ontology, storage schema, indexing method, and coding workflow to change.","intervention":"Create a versioned public contract for an abstract Ritual Evidence Record. Define its abstract states and operations without naming a database schema: construct a record from authorized source segments; attach emic terms and analyst categories as distinct assertions; declare assertion provenance, scope, confidence, and access class; retrieve and filter assertions; compare records only on explicitly requested dimensions; and export stable citations. Require invariants that every analytic assertion retains a source or declared interpretive provenance, unknown remains distinct from absent, emic and etic labels cannot overwrite one another, access restrictions survive every operation, and unordered tags never imply temporal sequence. Specify preconditions, postconditions, allowed errors, and side-effect limits. Hide tables, ontology-node identifiers, tag order, NLP models, and manual-coding workflow behind the boundary. Admit a repository implementation only after it passes the same black-box fixtures and operation-sequence tests. Pilot this on copied, non-public records rather than replacing the archive.","structural_mapping":[{"archetype_element":"Abstract behavioral surface","domain_realization":"Operations for constructing, retrieving, filtering, comparing, and exporting ritual evidence records, with explicit outputs, errors, and access behavior."},{"archetype_element":"Hidden representation","domain_realization":"Database tables, ontology hierarchy, internal identifiers, indexing, tag order, automated classifiers, and curator workflow remain non-contractual."},{"archetype_element":"Behavioral laws and invariants","domain_realization":"Provenance is preserved; unknown is not absence; emic terms remain distinguishable from analyst categories; access classifications cannot weaken through transformation; unordered annotations do not acquire sequence."},{"archetype_element":"Conformance oracle","domain_realization":"A shared set of synthetic and permission-cleared fixtures plus generated operation sequences checks only public results, state transitions, errors, provenance, and access outcomes."},{"archetype_element":"Substitutability rule","domain_realization":"A repository is a candidate substitute only if it passes the contract suite without exposing or requiring its internal schema; passing supports the bounded pilot decision but is not proof of interpretive adequacy for every corpus."},{"archetype_element":"Version and leakage governance","domain_realization":"Contract changes are recorded and reviewed, while audits identify observable but unpromised behavior such as tag order, raw ontology IDs, error wording, or export row order."}],"mechanism_mapping":[{"mechanism_slug":"abstract_data_type_specification","role":"Defines the abstract value as a set of source-linked assertions, qualifications, relations, and access constraints; maps each valid repository state to that value and states representation invariants independently of storage.","counterfactual_removal":"Without the abstract value, invariant, and mapping, the proposal becomes a list of repository functions and cannot determine whether differently structured records mean the same thing."},{"mechanism_slug":"design_by_contract_clause","role":"Assigns obligations for each operation, including required authorization and valid comparison dimensions, promised provenance preservation, unchanged state after rejected calls, and explicit unknown, restricted, or unsupported-result errors.","counterfactual_removal":"Without per-operation clauses, edge cases and fault allocation remain informal, so nominally identical repositories may diverge while both claim compliance."},{"mechanism_slug":"opaque_type_or_module_boundary","role":"Exposes record handles and sanctioned operations while withholding raw tables, internal ontology-node identifiers, classifier state, and mutable annotation collections.","counterfactual_removal":"Without enforced opacity, clients can continue depending directly on schema fields and tag order, defeating representation independence."},{"mechanism_slug":"black_box_contract_test_suite","role":"Runs one contract-derived battery against both the incumbent and pilot repositories using only public operations and observable results.","counterfactual_removal":"Without a common black-box oracle, substitutability remains a judgment based on examples or implementation inspection rather than shared acceptance criteria."},{"mechanism_slug":"property_based_conformance_test","role":"Generates valid operation sequences to test that provenance, emic/etic separation, access class, and unknown-versus-absent distinctions survive repeated filtering, comparison, and export.","counterfactual_removal":"Without sequence-based properties, hand-picked fixtures may miss invariant failures that emerge only after several transformations."},{"mechanism_slug":"representation_leakage_probe","role":"Checks outputs for useful but unpromised signals—including internal IDs, row or tag order, error text, timing classes, and raw classifier scores—and either seals each leak or deliberately adds it to the contract.","counterfactual_removal":"Without leakage review, clients may reconstruct and depend on the hidden representation despite nominally using the public operations."}],"causal_chain":["Researchers currently consume schema fields, ontology positions, tag order, and exports as if those observations were scholarly promises.","The contract restates the component in terms of source-linked assertions, qualifications, permitted operations, invariant-preserving transitions, errors, and access effects.","The opaque boundary prevents direct use of internal repository structures, while leakage review catches indirect exposure through public results.","Each repository maps its concrete states to the same abstract record and is exercised by the same black-box and operation-sequence oracle.","Detected divergences are classified as implementation defects, contract underspecification, or contested scholarly judgments requiring human review rather than being silently normalized.","Repositories that satisfy the bounded oracle can be exchanged in the pilot without requiring pilot clients to know their storage or coding representation.","This permits implementation change while reducing representation-driven changes to citations, comparative outputs, and access behavior."],"baseline":"For a permission-cleared pilot corpus, run a fixed set of retrieval, filtering, comparison, and export tasks directly against the incumbent repository. Record outputs, provenance links, unknown/absent treatment, emic/etic distinctions, access decisions, and every instance where a task relies on a raw field, internal ID, ontology path, or ordering convention. This is a dependency inventory and divergence baseline, not an estimate of prevalence or effect.","nearest_rivals":["Adopt one fixed cross-tradition ontology and require every project to encode records in it.","Publish a common exchange format or schema while leaving operation semantics and invariants informal.","Maintain pairwise crosswalks between each repository’s fields and categories.","Freeze the incumbent repository structure and repair downstream analyses manually after changes.","Have expert reviewers compare a small set of repository outputs without a reusable behavioral oracle."],"remaining_contrastive_claim":"Unlike a shared ontology or exchange schema, this intervention does not require identical categories or storage shapes. Its distinctive claim is that repository substitution should be governed by observable scholarly behavior—especially provenance, qualification, category separation, state transitions, errors, and access effects—while internal encodings remain replaceable. It complements rather than replaces expert review of interpretive validity.","authority_safety":{"decision_authority":"The archive’s designated data steward may authorize a copied-corpus pilot; the principal investigator controls research use; ethics or access officers control restricted materials; tradition specialists or community advisers retain their existing consultative or approval roles for sensitive description. The contract team has no authority to settle theological truth or override source-community restrictions.","authorized_first_step":"On a read-only copy of 20 permission-cleared records, inventory current client dependencies and draft the abstract operations and invariants with one archivist, one comparative-religion researcher, and the relevant access reviewer; create synthetic fixtures before connecting a second repository.","excluded_actions":["Reclassifying original archival records without curator approval","Treating contract conformance as validation of a theological or comparative interpretation","Exposing restricted, sacred, personally identifying, or community-controlled material in fixtures or tests","Replacing the production repository or redirecting live users during the first evidence step","Collapsing tradition-specific terms into comparative categories without retaining the original term and provenance","Using opaque implementation boundaries to prevent authorized scholarly or ethical audit"],"halt_rollback":"Stop if any test fixture reveals restricted content, an operation weakens an access class, a mapping loses provenance or the emic/etic distinction, or participants cannot agree on an abstract value without encoding a disputed interpretation as mandatory. Delete derivative pilot exports, revoke pilot credentials, retain the production archive unchanged, and return disputed clauses for authorized human review."},"negative_tests":{"strongest_counterevidence":"Independent implementations can pass the proposed suite yet expert reviewers find that the abstract model systematically erases distinctions needed to interpret the pilot records, or clients still require representation-specific information for legitimate scholarly work that cannot be expressed as a stable public operation.","problem_falsifier":"The dependency inventory finds no downstream reliance on internal fields, IDs, ordering, ontology paths, or coding workflow, and two differently represented pilot repositories already yield equivalent public results, provenance, qualifications, and access decisions for all bounded tasks.","intervention_falsifier":"After revising only demonstrably underspecified clauses, an independently structured pilot repository still cannot pass the contract without reproducing the incumbent schema, or suite passage fails to predict agreement on the predeclared observable tasks and expert-reviewed invariants.","risks":["The abstract model may smuggle one comparative theory into what appears to be neutral infrastructure.","Tests may freeze accidental incumbent behavior as a scholarly requirement.","A green suite may be mistaken for interpretive or theological correctness.","Opacity may obstruct legitimate audit unless sanctioned inspection is preserved.","Synthetic or copied fixtures may still disclose sensitive material.","Maintaining mappings and contract versions may impose more work than the bounded use justifies.","Generated tests may explore technically valid but religiously or ethically inappropriate combinations unless generators encode access constraints."]},"next_evidence_step":"Using the 20-record read-only pilot, predeclare 12 observable tasks spanning retrieval, emic/etic separation, unknown versus absent, comparison, citation export, and access denial. Implement the contract against the incumbent repository and one deliberately simple independent in-memory representation. Run identical black-box fixtures and generated operation sequences, then have two authorized domain reviewers inspect only divergences and a stratified sample of agreements. Record whether each divergence reflects an implementation defect, an underspecified clause, or a contested interpretation. Do not infer general effectiveness from this bounded exercise.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Not assessed against prior proposals; comparison is excluded by the sealed, single-proposal instruction. This candidate is developed solely from the supplied archetype, mechanisms, and domain card.","revision_record":{"parent_version":null,"progress_targets_addressed":[],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}