{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp11_mechanism_context_external20_20260804","research_id":"eoa_inverse_innovation_exp11_external_scrutiny_20260804","cell_id":"layer_decay_and_expiration_management__systems_cybernetics","opaque_id":"layer_decay_and_expiration_management__systems_cybernetics__A","search_lanes":{"direct_problem":{"queries":["supervisory control controller configuration version lifecycle obsolete fallback archive registry IEC 62443","legacy controller logic obsolete override remains active industrial control configuration audit incident","supervisory controller policy registry stale eligibility fallback replay archive","stale model production controller policy eligibility model registry"],"source_ids":["SRC1","SRC2","SRC7"],"no_result_note":"The retained sources support stale or regime-mismatched models, legacy control-system artifacts, and accumulating stale configuration records, but none measures stale eligibility in the nominated supervisory-controller family."},"closest_prior_art":{"queries":["official model lifecycle decommission retired archived approval workflow model registry fallback rollback model governance","model registry lifecycle stage archive deprecated models rollback production official documentation","site:ibm.com/docs model lifecycle retired deprecated model governance registry approval","model registry archive restore dependency fallback audit approval lifecycle"],"source_ids":["SRC5","SRC6","SRC7","SRC8"],"no_result_note":null},"historical_terminology":{"queries":["control software configuration management obsolete versions rollback fallback audit standard IEC 61508","configuration item retirement dependency impact analysis rollback preservation hold software asset lifecycle","site:nist.gov configuration management previous versions rollback operational technology control system NIST SP 800-53 CM-2","controller superseded fallback configuration management control system"],"source_ids":["SRC2","SRC3","SRC4","SRC6"],"no_result_note":null},"products_practices_standards":{"queries":["supervisory control controller configuration version lifecycle obsolete fallback archive registry IEC 62443","official model lifecycle decommission retired archived approval workflow model registry fallback rollback model governance","site:ibm.com/docs model lifecycle retired deprecated model governance registry approval","model registry archive restore dependency fallback audit approval lifecycle"],"source_ids":["SRC2","SRC3","SRC4","SRC5","SRC6","SRC7","SRC8"],"no_result_note":null},"non_english_regional":{"queries":["Steuerungssoftware Versionsverwaltung Altversionen Archivierung Rückfall Automatisierung BSI","site:bsi.bund.de ICS Konfigurationsmanagement Sicherung SPS Programm Version","控制器 模型 注册 生命周期 归档 版本 回滚 官方","旧模型 归档 恢复 模型注册表 生产 版本 审批"],"source_ids":["SRC8"],"no_result_note":"Chinese first-party documentation supplied a direct regional-language analogue for archiving and restoring model versions; the German searches mainly returned broader source-code and PLC configuration-management material."},"composition_subproblems":{"queries":["model registry archive restore dependency fallback audit approval lifecycle","supervisory controller policy registry stale eligibility fallback replay archive","configuration item retirement dependency impact analysis rollback preservation hold software asset lifecycle","model registry lifecycle stage archive deprecated models rollback production official documentation"],"source_ids":["SRC4","SRC5","SRC6","SRC7","SRC8"],"no_result_note":"No retained source combined regime-mismatch adjudication, sole-fallback and replay preservation, eligibility gating, and identical-event shadow replay for supervisory controllers."}},"sources":[{"source_id":"SRC1","title":"Quality Monitoring and Assessment of Deployed Deep Learning Models for Network AIOps","url":"https://arxiv.org/abs/2202.13642","publisher":"Lixuan Yang and Dario Rossi; arXiv version of IEEE Network research","date_or_year":"2021; arXiv version 2022","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Deployed models can become stale or cease to fit changing operating environments.","Model quality can be tracked over repeated inferences to trigger updating or model switching.","The paper experimentally evaluates techniques for detecting model-quality degradation in network-operations and image-recognition use cases."]},{"source_id":"SRC2","title":"IEC 62443-2-1:2024 — Security program requirements for IACS asset owners","url":"https://webstore.iec.ch/en/publication/62883","publisher":"International Electrotechnical Commission","date_or_year":"2024","source_type":"OFFICIAL_STANDARD","language":"English","claims_supported":["The IACS asset owner, expressly including the operator, is responsible for relevant security-program policies and procedures.","Industrial automation and control systems may remain operational for more than twenty years and contain unsupported legacy hardware and software.","Legacy-system limitations may require documented compensating measures."]},{"source_id":"SRC3","title":"IEEE Standard 828-2012 for Configuration Management in Systems and Software Engineering","url":"https://standards.ieee.org/ieee/828/10549/","publisher":"IEEE Standards Association","date_or_year":"2012","source_type":"OFFICIAL_STANDARD","language":"English","claims_supported":["Configuration management applies to any type of software or system.","Established configuration-management work includes identifying configuration items, controlling changes, reporting status, and managing builds and releases across the lifecycle."]},{"source_id":"SRC4","title":"CASS Guide 508: IEC 61508-3 Software Techniques for Evaluation of Evidence, Version 3.3","url":"https://61508.org/wp-content/uploads/2023/12/CASS-GUIDE-508-SW-IEC61508-3-Software-TOES-v3.3.pdf","publisher":"CASS Scheme Ltd.","date_or_year":"2023","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Software configuration items, states, and versions should be identified, controlled, documented, and subject to impact analysis and authorization.","Earlier baselines must remain rebuildable, while runtime loading must replace earlier versions completely and correctly.","Master copies, documentation, and release information are retained throughout operational life, demonstrating why retirement and preservation cannot be based on age alone."]},{"source_id":"SRC5","title":"Model Registry Workflows","url":"https://www.mlflow.org/docs/latest/ml/model-registry/workflow/","publisher":"MLflow Project, Linux Foundation AI & Data","date_or_year":"Current documentation accessed 2026-08-04","source_type":"FIRST_PARTY_PRODUCT","language":"English","claims_supported":["A deployed-model registry can version artifacts and use aliases or tags to govern which version is selected by production workloads.","Earlier MLflow stages explicitly moved model versions from staging and production to archived status.","Aliases can be reassigned independently of serving code, and access-controlled environments and validation-status tags support lifecycle gating."]},{"source_id":"SRC6","title":"Asset Development and Lifecycles","url":"https://www.ibm.com/docs/en/ram/7.5.4?topic=governance-asset-development-lifecycles","publisher":"IBM","date_or_year":"IBM Rational Asset Manager 7.5.4 documentation","source_type":"FIRST_PARTY_PRODUCT","language":"English","claims_supported":["Asset lifecycle transitions can be conditioned on policies, tests, reviewer votes, and authorized roles.","Pre-retirement notifies owners, reviewers, related-asset owners, and prior downloaders.","Retired assets remain restricted but restorable, and policies can block deletion, retirement, or archival."]},{"source_id":"SRC7","title":"Dependent CIs Management","url":"https://www.servicenow.com/docs/r/servicenow-platform/configuration-management-database-cmdb/manage-dependent-ci.html","publisher":"ServiceNow","date_or_year":"2026-03-12","source_type":"FIRST_PARTY_PRODUCT","language":"English","claims_supported":["A commercial CMDB product performs dependency-aware retire, archive, and delete workflows with approval tasks and auditability.","The system detects orphan dependent configuration items and applies exclusions for multiple parents, unresolved duplicates, and excluded classes before archival or deletion.","ServiceNow explicitly describes the purpose as preventing accumulation of stale configuration data after lifecycle changes."]},{"source_id":"SRC8","title":"恢复模型版本 (Restoring a Model Version) — Red Hat OpenShift AI Cloud Service","url":"https://docs.redhat.com/zh-cn/documentation/red_hat_openshift_ai_cloud_service/1/html/working_with_model_registries/restoring-a-model-version_model-registry","publisher":"Red Hat","date_or_year":"2025 documentation, accessed 2026-08-04","source_type":"FIRST_PARTY_PRODUCT","language":"Chinese","claims_supported":["Archived model versions can be restored to the active model-version list.","Restoration requires access to the relevant model registry and an existing archived version.","The product provides distinct archive and restore operations for models and individual model versions."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The problem class exists: research demonstrates that deployed models can become stale or environmentally mismatched, IEC identifies long-lived IACS with legacy software, and ServiceNow documents stale configuration records accumulating after lifecycle changes. The specific prevalence claim remains unverified because no source or registry audit establishes that superseded or regime-mismatched artifacts remain eligible in the nominated supervisory-controller family.","source_ids":["SRC1","SRC2","SRC7"],"uncertainty":"Evidence spans network ML, general IACS, and configuration databases rather than the proposed controller family. It supports plausibility, not the pilot's baseline rate or causal contribution to observed control problems."},"adopter_evidence":{"status":"SUPPORTED","finding":"An identifiable adopter and authorizer exist. IEC assigns IACS security-program responsibility to the asset owner, including the operator; established lifecycle products assign decisions to lifecycle managers, reviewers, administrators, and managed groups. These map directly to an accountable control-system owner with operator, safety, compliance, and incident-review participation.","source_ids":["SRC2","SRC4","SRC6","SRC7"],"uncertainty":"The particular organization and named accountable owner are not yet identified; they must be designated at enrollment."},"implementation_evidence":{"status":"PARTLY_SUPPORTED","finding":"The component mechanisms are implementable and substantially demonstrated separately: registries and aliases control model selection; lifecycle states archive versions; policy and reviewer gates authorize transitions; dependency systems inspect relationships and exceptions; and archived versions can be restored. No retained source demonstrates the complete supervisory-controller package or its identical-event shadow replay with sole-fallback and incident-replay preservation.","source_ids":["SRC4","SRC5","SRC6","SRC7","SRC8"],"uncertainty":"Integration feasibility is strong, but reproducible stale-status adjudication, controller-regime detection, dependency completeness, replay compatibility, and the proposed effect threshold remain untested."},"prior_art":{"disposition":"ADJACENT_PRIOR_ART","closest_analogues":[{"name":"MLflow Model Registry lifecycle, aliases, and archival","source_ids":["SRC5"],"same_problem":true,"same_causal_lever":true,"overlap":"Versions are registered, labeled by lifecycle status, selected through mutable aliases, moved out of production, archived, and governed through access-controlled environments.","remaining_difference":"It does not require controller-regime adjudication, supersession evidence, dependency and sole-fallback checks, incident-replay preservation, or identical-event shadow comparison before removing eligibility."},{"name":"IBM Rational Asset Manager governed retirement lifecycle","source_ids":["SRC6"],"same_problem":true,"same_causal_lever":true,"overlap":"Assets move through policy-tested and reviewer-approved states; retirement restricts access, notifies related parties, and remains reversible through restoration.","remaining_difference":"It governs generic repository assets rather than executable control choices and does not test regime fit, selection opportunities, sole validated fallback, or replay capability."},{"name":"ServiceNow dependency-aware configuration-item retirement and archival","source_ids":["SRC7"],"same_problem":true,"same_causal_lever":true,"overlap":"Lifecycle changes trigger dependency inspection, orphan detection, exclusions, approval tasks, and controlled retire, archive, or delete operations intended to prevent stale accumulation.","remaining_difference":"Its dependency rules manage CMDB records and may cascade retirement to dependents; they do not protect controller fallback or incident replay, evaluate plant regimes, or compare baseline and shadow selector outcomes."},{"name":"IEC 61508-oriented software configuration management","source_ids":["SRC4"],"same_problem":false,"same_causal_lever":false,"overlap":"It establishes identification, authorization, impact analysis, traceability, earlier-baseline reconstruction, complete runtime replacement, and operational-lifetime preservation of released software.","remaining_difference":"It is a safety-lifecycle configuration-management framework, not a lifecycle eligibility gate for multiple simultaneously registered supervisory policies or models."}],"contrastive_claim_remaining":"For one nominated non-safety-critical supervisory-controller family, an owner-adjudicated lifecycle gate that blocks retirement when sole-fallback or replay capability would be lost will reduce stale-eligible recorded opportunities by at least 50% relative to the same opportunities under frozen baseline eligibility, with zero dependency loss and no unresolved reviewer disagreement.","contrastive_claim_falsifier":"The incremental claim is falsified if a complete retained source shows that this same controller-specific, dependency- and replay-protected shadow-gating package is already routine, or if the prespecified replay finds baseline stale eligibility is zero, reduction is below 50%, any sole-fallback or replay capability is lost, or reviewers cannot resolve classifications.","confidence":"MODERATE","search_limitations":"The bounded search retained exactly eight directly opened sources across research, standards, guidance, products, historical terminology, and Chinese-language documentation. Public descriptions may omit proprietary controller-management practices; some standards text is paywalled, and no patent, procurement, incident, or organization-specific registry corpus was exhaustively searched."},"researchability_gates":{"externally_supported_problem":{"status":"PASS","rationale":"Independent research and official or first-party sources support the broader existence of stale deployed models, legacy IACS artifacts, and accumulating stale configuration records. The family-specific prevalence remains deliberately falsifiable rather than assumed.","source_ids":["SRC1","SRC2","SRC7"]},"identifiable_adopter_or_authorizer":{"status":"PASS","rationale":"The IACS asset owner or operator is an externally recognized responsible role, and lifecycle products identify managers, reviewers, administrators, and approval groups capable of authorizing transitions.","source_ids":["SRC2","SRC6","SRC7"]},"distinct_testable_incremental_claim":{"status":"PASS","rationale":"Adjacent systems implement lifecycle states, selection aliases, approvals, dependency checks, and restoration, but the retained sources do not combine them into the controller-specific fallback- and replay-protected shadow gate. The 50% reduction and zero-loss thresholds distinguish a falsifiable increment.","source_ids":["SRC4","SRC5","SRC6","SRC7","SRC8"]},"bounded_next_evidence_step":{"status":"PASS","rationale":"The proposed 30-day frozen trace, complete version enrollment, two-reviewer adjudication, and offline replay of identical selection opportunities constitute a bounded test with explicit denominators, thresholds, and halt conditions.","source_ids":["SRC4","SRC5","SRC6","SRC7"]},"no_unresolved_safety_or_authority_stop":{"status":"PASS","rationale":"The authorized step makes no live eligibility changes or deletions, names an accountable owner, requires safety and compliance approval for protected artifacts, and halts on fallback, replay, dependency, preservation, or reviewer conflict. Standards and guidance support owner responsibility, change authorization, impact analysis, and preservation of rebuildable earlier versions.","source_ids":["SRC2","SRC4"]},"adequate_search_evidence":{"status":"PASS","rationale":"All six required lanes were searched adversarially using direct, historical, standards/product, German and Chinese, and component-combination terminology. Eight retained sources include four independent publisher families plus primary research, two standards, official guidance, and multiple first-party products.","source_ids":["SRC1","SRC2","SRC3","SRC4","SRC5","SRC6","SRC7","SRC8"]}},"strict_success":true,"screen_survival":true,"remaining_research_value":"MODERATE","recommended_next_step":"Enroll every version in one owner-nominated non-safety-critical controller family, freeze the prespecified 30-day trace, have two reviewers independently classify supersession, regime fit, dependencies, fallback and replay roles, and preservation holds, then run the identical-event shadow replay without changing live eligibility. Report baseline stale-eligibility rate, inter-reviewer agreement, relative reduction, dependency-loss rate, and missed-regime limitations.","world_novelty_boundary":"This bounded public search establishes only that the proposal has adjacent prior art and a remaining controller-specific empirical claim. It cannot establish world novelty, patentability, freedom to operate, market size, routine adoption outside public documentation, or realized operational impact."}