{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp11_mechanism_context_external20_20260804","research_id":"eoa_inverse_innovation_exp11_external_scrutiny_20260804","cell_id":"layer_decay_and_expiration_management__systems_cybernetics","opaque_id":"layer_decay_and_expiration_management__systems_cybernetics__C","search_lanes":{"direct_problem":{"queries":["industrial control temporary override management expiration review controller patch actuator authority","control system override bypass register periodic review expiry safety lifecycle","stale controller patches exception rules overlays control systems lifecycle management","process control software patch accumulation legacy logic technical debt"],"source_ids":["S1","S2","S6","S8"],"no_result_note":null},"closest_prior_art":{"queries":["controller decommissioning shadow mode replay stability analysis temporary control logic removal","\"temporary modifications\" \"process software\" periodic review control system","industrial control management of change temporary software modification periodic review obsolete logic removal","shadow mode controller deployment actuator contribution rollback industrial control"],"source_ids":["S1","S3","S4"],"no_result_note":null},"historical_terminology":{"queries":["site:nrc.gov temporary modification control system expiration configuration control software bypass","site:iaea.org temporary modifications control systems review removal safety plant configuration","plant modifications process software lifetime configuration recovery parallel operation","closed-loop eigenvalue sensitivity controller robustness 1987"],"source_ids":["S1","S7"],"no_result_note":null},"products_practices_standards":{"queries":["alarm management lifecycle stale suppression shelving timeout ISA 18.2 official","industrial control patch management recommended practice control systems","Rockwell safety application test edit original logic retained impact validation","control system override management authorisation recording monitoring review"],"source_ids":["S1","S2","S4","S5","S8"],"no_result_note":null},"non_english_regional":{"queries":["alt Steuerungssoftware temporäre Änderungen SPS Ablaufdatum Überprüfung Rückbau","gestión cambios temporales sistema control caducidad lógica PLC revisión","gestión de parches sistemas de control ciclo de vida validación","mantenimiento programas PLC gestión cambios incrementales lógica obsoleta"],"source_ids":["S6"],"no_result_note":"German- and Spanish-language searches found regional PLC revision, patch, and change-management terminology but no retained source closer than the international nuclear-modification guidance. S6 supplies German industrial evidence but is published in English."},"composition_subproblems":{"queries":["control loop interaction eigenvalue sensitivity controller contribution stability analysis industrial process","modal analysis controller interaction remove controller eigenvalue sensitivity shadow replay","multiple control overlays interaction instability process control patches override systems","temporary process software modification dependency configuration recovery simulation parallel operation"],"source_ids":["S1","S2","S4","S7"],"no_result_note":null}},"sources":[{"source_id":"S1","title":"Modifications to Nuclear Power Plants: Safety Guide No. NS-G-2.3","url":"https://www-pub.iaea.org/MTCD/Publications/PDF/Pub1111_scr.pdf","publisher":"International Atomic Energy Agency","date_or_year":"2001","source_type":"OFFICIAL_STANDARD","language":"English","claims_supported":["Temporary modifications expressly include process software and should be minimized, time-limited, distinctly logged, periodically reviewed, and removed or converted to permanent modifications.","Existing modifications, their sequencing, dependencies, cumulative effects, and interactions should be considered.","Named personnel must be authorized to initiate, approve, perform, and remove modifications, with independent safety review and regulatory approval where required.","Removal should include configuration-recovery checks; process-software changes can be validated in simulation or controlled tests and, where possible, run in parallel without connection to field devices."]},{"source_id":"S2","title":"Control systems","url":"https://www.hse.gov.uk/comah/sragtech/techmeascontsyst.htm","publisher":"UK Health and Safety Executive","date_or_year":"Undated; accessed 2026-08-04","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Safety-related control-system procedures should cover authorization, security, recording, monitoring, review, and reset of overrides.","Suppressed or shelved alarms require controls that restore them when they again become relevant to plant operation.","Dependencies, independence, common-mode failures, reinstatement verification, and actuator reliability are material safety considerations."]},{"source_id":"S3","title":"Common Inspection Criteria: Management of Change","url":"https://minerva.jrc.ec.europa.eu/en/shorturl/technical_working_group_2_seveso_inspections/cic_management_of_change","publisher":"European Commission Joint Research Centre, MINERVA","date_or_year":"2023","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Management of change applies to temporary changes, supporting IT programs, and control-room configurations, including removals and decommissioning.","Temporary changes should have a maximum duration and, after expiry, be removed or treated as permanent.","Risk analysis, alternatives, pre-start-up testing, assigned responsibility, documentation, audit, and final authorization are expected parts of change control."]},{"source_id":"S4","title":"Edit a Safety Application","url":"https://www.rockwellautomation.com/en-us/docs/technical/logix5000/_online/1756-rm012/guardlogix-5580-and-compact-guardlogix-5580-safety/safety-applications/edit-a-safety-application.html","publisher":"Rockwell Automation","date_or_year":"Undated; accessed 2026-08-04","source_type":"FIRST_PARTY_PRODUCT","language":"English","claims_supported":["GuardLogix test edits can execute edited logic while retaining the original, unexecuted logic in controller memory, demonstrating a reversible execution-state mechanism.","Safety-program changes require authorization, impact analysis, affected-element revalidation, functional tests, documentation, and alternate safety protection during online edits.","Incorrect online edits can stop the application, confirming that authority switching is safety-relevant rather than merely administrative."]},{"source_id":"S5","title":"ISA-TR18.2.6-2012: Alarm Systems for Batch and Discrete Processes (preview)","url":"https://www.isa.org/getmedia/c8d7850a-6a68-4b42-a62f-bd8b5a7f9b8e/TR_18-2-6_Preview.pdf","publisher":"International Society of Automation","date_or_year":"2012","source_type":"OFFICIAL_STANDARD","language":"English","claims_supported":["ISA-18.2 applies an explicit lifecycle to programmable-controller and HMI-based alarm systems.","Lifecycle management of executable or condition-dependent control-system logic is established in the adjacent alarm-management domain.","The preview does not establish actuator-authority withdrawal or modal testing."]},{"source_id":"S6","title":"Maintainability and evolvability of control software in machine and plant manufacturing—An industrial survey","url":"https://mediatum.ub.tum.de/doc/1525020/1525020.pdf","publisher":"Control Engineering Practice / Elsevier; hosted by Technical University of Munich","date_or_year":"2018","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Automated production systems can remain in service for 30–50 years while undergoing repeated software change.","A survey of 68 machine and plant manufacturers found maintainability and evolvability criteria generally below expectations.","Companies lacked sufficient knowledge of deployed software variants and versions because installed software status was uncertain, supporting the inventory and provenance problem while not directly proving stale actuator overlays."]},{"source_id":"S7","title":"Sensitivity of closed-loop eigenvalues and robustness","url":"https://ntrs.nasa.gov/citations/19880035387","publisher":"NASA Technical Reports Server; journal reprint from Journal of Guidance, Control, and Dynamics","date_or_year":"1987","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Closed-loop eigenvalue sensitivity to controller, estimator, and uncertain plant parameters is established control-analysis prior art.","Eigenvalue proximity can produce large sensitivity, supporting the proposal's caution about modal separation and robustness.","The source does not describe lifecycle management, shadowing, or expiry of controller overlays."]},{"source_id":"S8","title":"Recommended Practice for Patch Management of Control Systems","url":"https://www.osti.gov/biblio/944885","publisher":"Idaho National Laboratory and U.S. Department of Energy Office of Scientific and Technical Information","date_or_year":"2008","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Patch management for industrial control-system software was reported as inconsistent or nonexistent in critical-infrastructure environments.","Industrial control systems cannot tolerate abrupt interruption, supporting cautious validation and rollback rather than indiscriminate removal.","The report concerns software patch governance and does not establish regime-gated withdrawal of actuator-path overlays."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The broader problem is externally supported: control software persists for decades amid repeated updates, deployed-version knowledge is often weak, industrial-control patch management has been inconsistent, and high-hazard guidance explicitly manages the lifetime, interactions, cumulative effects, review, and removal of temporary process-software modifications. However, none of the eight retained sources directly measures the narrower causal hypothesis that expired actuator-authority overlays produce conflicting feedback or opaque incident residuals. That mechanism remains plausible but unconfirmed.","source_ids":["S1","S3","S6","S8"],"uncertainty":"Most direct lifecycle evidence is normative and nuclear/process-safety specific. It does not quantify prevalence, effect size, or causal attribution for non-safety controller overlays."},"adopter_evidence":{"status":"SUPPORTED","finding":"An identifiable adopter and authorization chain exists: the accountable operating organization or control-system owner, plant management, trained control engineers, independent safety reviewers, and—where safety significance requires it—the regulator. Official guidance assigns initiation, approval, implementation, removal, testing, and final authorization responsibilities.","source_ids":["S1","S2","S3","S4"],"uncertainty":"The exact approving body and regulatory obligations vary by jurisdiction, plant class, and whether the overlay affects a credited safety function."},"implementation_evidence":{"status":"PARTLY_SUPPORTED","finding":"Most implementation primitives are established: modification registers and time limits, periodic review, interaction and dependency assessment, retained configurations, recovery checks, simulation, offline or parallel execution disconnected from field devices, explicit test criteria, and reversible test-edit states retaining the prior logic. Closed-loop eigenvalue sensitivity analysis is also established. The specific integration—identified overlay contribution, matched three-arm replay, spectral-gap invalidation, and lifecycle-gated authority withdrawal—was not found as a deployed package.","source_ids":["S1","S3","S4","S7"],"uncertainty":"Feasibility depends on obtaining a sufficiently accurate local model or matched replay, separating the overlay contribution from coupling and plant drift, and demonstrating restoration fidelity."},"prior_art":{"disposition":"ESTABLISHED_PRACTICE","closest_analogues":[{"name":"IAEA temporary process-software modification lifecycle","source_ids":["S1"],"same_problem":true,"same_causal_lever":true,"overlap":"Covers process-software modifications; cumulative and interaction review; minimization and time limits; periodic review; named authorization; independent safety review; logging and identification; configuration recovery after removal; simulation; parallel execution disconnected from field devices; and acceptance before operation.","remaining_difference":"It does not prescribe validation-confidence decay, explicit active/shadow/archive states, overlay-contribution identification, modal residual and spectral-gap gates, or comparison against an age-only expiry arm."},{"name":"European Commission management of temporary control-related change","source_ids":["S3"],"same_problem":true,"same_causal_lever":true,"overlap":"Applies risk-reviewed lifecycle control to temporary changes and control-room or IT configurations, establishes maximum duration, and requires removal or permanent disposition after expiry with authorization, audit, testing, and responsibility assignment.","remaining_difference":"It is a general safety-management process rather than a controller-specific response-attribution protocol and supplies no modal or matched-replay decision rule."},{"name":"Rockwell GuardLogix reversible test-edit workflow","source_ids":["S4"],"same_problem":false,"same_causal_lever":true,"overlap":"Separates execution authority from retention: edited logic can execute while the original remains in memory, with authorization, impact analysis, testing, documentation, and revalidation.","remaining_difference":"It manages editing and deployment rather than accumulated stale overlays, and it does not choose withdrawal using regime validity, matched disturbances, or modal diagnostics."},{"name":"ISA alarm-management lifecycle and HSE shelving controls","source_ids":["S2","S5"],"same_problem":false,"same_causal_lever":false,"overlap":"Provides a neighboring lifecycle precedent for condition-dependent control-system logic, including suppression or shelving and restoration when relevant.","remaining_difference":"Alarm presentation does not normally contribute to the actuator command, so this analogue does not solve overlay attribution, closed-loop stability, or safe actuator-authority withdrawal."}],"contrastive_claim_remaining":"For a non-safety-critical, superseded overlay with identifiable contribution, regime-, dependency-, restoration-, and response-gated shadowing may improve at least one preregistered response or interpretability metric relative to both the current-active baseline and age-only expiry while remaining within baseline test-retest noninferiority bounds and causing no constraint or restoration failure. A secondary incremental claim is that residual- and spectral-gap-qualified modal diagnostics predict safe shadowing decisions better than conventional administrative review alone.","contrastive_claim_falsifier":"The incremental claim is falsified if no eligible overlay can be identified; contribution estimates fail preregistered residual, coupling, or operating-window criteria; gated shadowing creates any new constraint violation or restoration mismatch; it exceeds the baseline noninferiority bound; or it fails to improve any preregistered response or interpretability metric beyond measurement error relative to both baseline and age-only expiry.","confidence":"MODERATE","search_limitations":"The search retained exactly eight direct sources. ISA material was limited to an official preview, one central IAEA guide has been superseded, and the evidence is concentrated in nuclear and process-industry control. Normative guidance and product documentation establish a mature practice package but do not prove uniform adoption. Non-English searches found no closer retained source. The search did not cover proprietary plant procedures, paywalled full standards, patents, or every sector and therefore cannot establish world novelty or ubiquity."},"researchability_gates":{"externally_supported_problem":{"status":"PASS","rationale":"Multiple independent sources support long-lived and repeatedly modified control software, weak deployed-version knowledge, inconsistent ICS patch governance, and the recognized need to limit and review interacting temporary process-software modifications. The narrow conflicting-feedback mechanism remains a testable hypothesis rather than an established fact.","source_ids":["S1","S3","S6","S8"]},"identifiable_adopter_or_authorizer":{"status":"PASS","rationale":"The operating organization or accountable control-system owner is identifiable, with plant management, qualified engineers, independent safety review, and regulatory approval where applicable.","source_ids":["S1","S2","S3","S4"]},"distinct_testable_incremental_claim":{"status":"PASS","rationale":"Although lifecycle management and reversible non-actuating execution are established, the matched comparison of response-gated shadowing against both current-active and age-only arms, using qualified modal attribution, remains distinct and falsifiable.","source_ids":["S1","S4","S7"]},"bounded_next_evidence_step":{"status":"PASS","rationale":"A single-subsystem historical replay using one non-safety-critical superseded overlay, fixed disturbance windows, three preregistered arms, explicit diagnostics, and a restoration drill is bounded and can be completed without changing live actuator commands.","source_ids":["S1","S3","S4"]},"no_unresolved_safety_or_authority_stop":{"status":"PASS","rationale":"The authorized first step is replay-only and excludes safety-critical withdrawal, irreversible deletion, hold overrides, and live actuation changes. Existing guidance supplies an authorization and independent-review path. Any later live action would require site-specific approval and is outside this gate.","source_ids":["S1","S2","S3","S4"]},"adequate_search_evidence":{"status":"PASS","rationale":"All six required lanes were searched adversarially using direct, historical, standards/product, regional-language, and component-combination terminology. Exactly eight retained direct sources were opened, spanning seven publisher organizations and including official standards, official guidance, first-party documentation, and primary research.","source_ids":["S1","S2","S3","S4","S5","S6","S7","S8"]}},"strict_success":false,"screen_survival":false,"remaining_research_value":"MODERATE","recommended_next_step":"Run the preregistered replay-only pilot on one inventoried, non-safety-critical, superseded overlay. Record the conventional lifecycle-review decision before revealing modal results; then compare current-active, lifecycle-gated shadow, and age-only arms on held-out matched disturbances. Include signed restoration verification and stop before any live authority withdrawal.","world_novelty_boundary":"This bounded public-source search found that the substantial lifecycle, authorization, reversible-retention, testing, and recovery package is established practice in high-assurance control governance. It did not find the exact modal-qualified three-arm replay composition as routine practice. That contrast is not a claim of world novelty, patentability, freedom to operate, market size, adoption prevalence, or realized impact."}