{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp09_archetype_breadth150_20260804","research_id":"eoa_inverse_innovation_exp09_light_prior_art_20260804","cell_id":"authority_legitimacy_and_consent_foundations__computer_science","search_lanes":{"direct_problem_and_intervention":{"queries":["automated rollback controller production service authorization policy audit logs appeal","automated rollback adoption engineers distrust false positives disable production","automated rollback trust engineers production"],"source_ids":["SRC1","SRC2"],"no_result_note":"No retained source directly documents teams disabling or bypassing a cross-service rollback controller specifically because its mandate or appeal path was disputed; the sources instead show adjacent trust, permission, approval, and authority problems."},"synonyms_and_historical_terms":{"queries":["software deployment automated rollback policy approval audit trail service owner","pre-authorized rollback procedures standing approval policy change authority","capability based authorization delegated authority caveats expiration revocation audit official standard"],"source_ids":["SRC1","SRC2","SRC4"],"no_result_note":null},"products_practices_and_standards":{"queries":["Kubernetes automated rollback progressive delivery controller","policy as code delegated authorization production changes approval expiration revocation","autonomous agent delegated authority mandate revocation audit log appeals software operations"],"source_ids":["SRC2","SRC3","SRC4"],"no_result_note":null},"component_combination":{"queries":["machine-readable delegation charter authorization expiry revocation audit reason service controller","autonomous rollback policy telemetry named approval audit trail","AI agent delegated mandate runtime validation signed evidence independent audit"],"source_ids":["SRC2","SRC3","SRC4"],"no_result_note":"No opened source combined service-specific rollback authority, controller-version qualification, affected-party representation, automatic expiration, clause-linked reasons, immediate suspension, and an outcome-changing appeal forum in one system."}},"sources":[{"source_id":"SRC1","title":"What is automated rollback?","publisher":"Firetiger","url":"https://www.firetiger.com/learning/change-management/what-is-automated-rollback","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["Automated rollback can itself be disruptive when triggered by false positives or applied to ambiguous and multi-service failures.","The source recommends beginning with human-approved recommendations and expanding automated permissions only after demonstrated performance builds trust.","It reports that unclear or unavailable rollback permission can delay incident response and identifies pre-authorized procedures and reviewable audit trails as prerequisites."]},{"source_id":"SRC2","title":"Vulnerability & Patch Management, Run as a Managed Service","publisher":"Patchly","url":"https://patchly.ai/services/vulnerability-management/","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["Patchly describes telemetry-triggered rollback operating under a customer-approved standing policy.","Its policy specifies device groups, maintenance windows, thresholds, and actions requiring named approval; qualifying low-priority updates may flow automatically.","Changes, approvers, telemetry results, rollback verification, and exceptions are recorded, while customers retain authority to initiate rollback."]},{"source_id":"SRC3","title":"Institutional Accountability for Autonomous AI","publisher":"MandateProof Ltd.","url":"https://www.mandateproof.com/","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["MandateProof describes explicit delegated authority whose permitted actions, conditions, and constraints are checked before every autonomous action.","It distinguishes access permission from proof of who authorized an action, what authority and constraints applied, and who remains accountable.","It claims cryptographically verifiable evidence linking authority, policy, action, and outcome."]},{"source_id":"SRC4","title":"An Architecture for Auditing AI Agent Delegation and Interactions","publisher":"Internet Engineering Task Force","url":"https://www.ietf.org/archive/id/draft-kuehlewind-audit-architecture-00.html","source_type":"OTHER","claims_supported":["This Internet-Draft identifies a gap in conventional logs: they do not consistently represent delegation, user intent, or changing authorization.","It proposes linking intent, approvals, delegation, authorization transitions, agent actions, and service-side execution through interoperable records and shared audit context.","It separates auditing from the agent, supports signed or transparently registered records, and gives an auditor responsibility for checking behavior against the authorization in force."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The operational setting and several constituent problems are visible: automated rollback can misfire, multi-service rollback requires judgment, permission delays impede incidents, standing approval policies are used to bound automation, and ordinary access or execution logs can fail to capture delegation and accountability. However, the bounded search did not directly establish the proposal's specific causal pattern—service teams disabling a nominally empowered rollback controller after jurisdictional disputes—so prevalence and causal materiality remain unverified.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"closest_prior_art":[{"name":"Patchly governed automated rollback workflow","source_ids":["SRC2"],"overlap":"Customer-approved policy bounds target groups, windows, thresholds, and named approvals; telemetry can initiate rollback; customers retain intervention authority; actions and verification are audited.","remaining_difference":"The source does not describe controller-version qualification, joint service/governance charters with automatic expiry, downstream-party representation, clause-linked public reasons, or an empowered jurisdictional appeal forum."},{"name":"MandateProof delegated-authority enforcement and evidence layer","source_ids":["SRC3"],"overlap":"Defines delegated autonomous authority, validates actions against the mandate before execution, and produces cryptographic evidence of authorization, constraints, action, and accountability.","remaining_difference":"It is domain-general and does not disclose the rollback-specific consent workflow, telemetry predicates, service boundaries, competence replay, suspension control, or appeal procedure proposed here."},{"name":"IETF Agent Auditing Architecture Internet-Draft","source_ids":["SRC4"],"overlap":"Links user intent, approvals, delegation, evolving authorization, actions, execution, independent auditing, and verifiable records across autonomous-agent interactions.","remaining_difference":"It is an audit architecture rather than a rollback-control charter; it does not itself define who may authorize a service rollback, qualification requirements, renewal rules, downstream representation, or an outcome-changing appeal process."},{"name":"Firetiger staged trust and pre-authorized rollback practice","source_ids":["SRC1"],"overlap":"Uses shadow-like recommendations and human approval before widening automated rollback permissions, with explicit health signals, pre-authorization, and reviewable audit trails.","remaining_difference":"Trust is framed primarily around demonstrated technical accuracy and operational permissions, not affected-party legitimacy, expiring delegation, public reason-giving, or independent review."}],"prior_art_disposition":"ADJACENT_PRIOR_ART","contrastive_claim_remaining":"For cross-service automated rollback, a jointly approved, service-specific, expiring charter that binds a qualified controller version to telemetry and blast-radius limits, records affected-party representation, emits clause-linked signed reasons, and provides immediate suspension plus outcome-changing independent appeal will improve reviewer agreement about authorization and reduce authority-based bypass beyond what standing approval policies, access control, technical validation, or generic delegation auditing achieve.","contrastive_claim_falsifier":"The claim is falsified if opened or subsequently found practice already integrates those rollback-specific elements, or if blinded incident evidence shows bypass is fully explained by false recommendations, latency, or missing integrations and the charter produces no improvement in authorization agreement, boundary reproducibility, or willingness to enable technically correct recommendations.","gates":{"adequate_source_search":{"status":"PASS","rationale":"The screen searched direct wording, trust and permission synonyms, deployment and rollback practices, delegated-authority systems, audit architecture, and component combinations. Exactly four opened sources from four publishers were retained, including three first-party sources and an IETF-hosted technical draft. This is adequate for a coarse screen, though not for patent or world-novelty conclusions.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"supported_problem":{"status":"PASS","rationale":"The exact disputed-jurisdiction-and-bypass pattern is not directly demonstrated, but adjacent evidence supports a material operational problem involving rollback trust, authorization, approval boundaries, auditability, and incident delay; therefore the problem is partly supported.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"distinct_testable_claim":{"status":"PASS","rationale":"Prior art substantially covers individual mechanisms, but the proposal retains a specific, falsifiable contrast: service-level joint delegation plus version qualification, expiry, affected-party representation, clause-linked reasons, suspension, and empowered appeal for automated rollback. Agreement and enablement outcomes can be compared with a standing-policy baseline.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"bounded_next_test":{"status":"PASS","rationale":"The proposed four-week shadow study is bounded to three consenting teams and 24 historical incidents, specifies classifications and disagreement measures, and prohibits production API access. It can test authorization clarity and review reproducibility without claiming operational benefit prematurely.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"no_obvious_safety_or_authority_stop":{"status":"PASS","rationale":"The first test is retrospective and non-production, requires explicit participation, withholds production credentials, preserves incident-command authority, excludes self-adjudication, and includes halt conditions for restricted data, missing representation, or irreproducible interpretation. Sensitive reason packets and incident records still require access control and minimization.","source_ids":["SRC2","SRC3","SRC4"]}},"screen_survival":true,"world_novelty_boundary":"This bounded public-web screen found adjacent governed-rollback, delegated-mandate, staged-trust, and agent-auditing practices but no opened source containing the full proposed combination. That result establishes only screen survival; it does not establish world novelty, patentability, market size, expert acceptance, organizational prevalence, causal effect, or realized value."}