{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp11_mechanism_context_external20_20260804","research_id":"eoa_inverse_innovation_exp11_external_scrutiny_20260804","cell_id":"layer_decay_and_expiration_management__systems_cybernetics","opaque_id":"layer_decay_and_expiration_management__systems_cybernetics__C","search_lanes":{"direct_problem":{"queries":["industrial control system temporary control logic modification expiration bypass override register lifecycle","\"temporary control logic\" PLC management of change","\"temporary changes\" control system become permanent","\"superseded\" PLC logic archive controller"],"source_ids":["SRC1","SRC2","SRC5"],"no_result_note":null},"closest_prior_art":{"queries":["Simplex architecture runtime assurance switching advanced controller safety controller primary paper","runtime assurance controller switching shadow mode safety monitor rollback control systems paper","industrial controller shadow mode replay testing control logic changes digital twin","control system patch management controller logic rollback validation paper"],"source_ids":["SRC2","SRC4","SRC7","SRC8"],"no_result_note":null},"historical_terminology":{"queries":["temporary modifications plant control system management of change","online software replacement analytic redundancy process control","temporary overrides bypasses control system time limit","legacy control logic modification rollback"],"source_ids":["SRC1","SRC2","SRC5","SRC8"],"no_result_note":null},"products_practices_standards":{"queries":["NIST SP 800-82 Rev 3 configuration change control rollback industrial control","FactoryTalk AssetCentre change management control program archive rollback","IEC 61511 bypass override management temporary modification expiration","industrial control system configuration management inventory backup standard"],"source_ids":["SRC1","SRC2","SRC3","SRC4","SRC5","SRC7"],"no_result_note":null},"non_english_regional":{"queries":["temporäre Änderung Leittechnik Überbrückung Ablaufdatum Sicherheitssteuerung","modification temporaire système de contrôle commande dérogation durée limite sécurité industrielle","cambio temporal sistema de control bypass fecha vencimiento gestión de cambios seguridad de procesos","alteração temporária sistema de controle prazo gestão de mudanças processo segurança"],"source_ids":["SRC6"],"no_result_note":"An official Portuguese-language Brazilian regulation was retained. German, French, and Spanish searches did not produce a closer direct source than the retained English and Portuguese material."},"composition_subproblems":{"queries":["control system inventory version archive change detection rollback temporary expiry","controller output monitored but not used switch old controller rollback","temporary control change dependency impact assessment reauthorization archive","PLC management of change shadow testing protected master recovery"],"source_ids":["SRC2","SRC3","SRC4","SRC5","SRC6","SRC7","SRC8"],"no_result_note":null}},"sources":[{"source_id":"SRC1","title":"1926.64 App C — Compliance Guidelines and Recommendations for Process Safety Management","url":"https://www.osha.gov/laws-regs/regulations/standardnumber/1926/1926.64AppC","publisher":"U.S. Occupational Safety and Health Administration","date_or_year":"1992","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Temporary changes have contributed to catastrophes.","Temporary changes require detection, monitored time limits, and management-of-change controls because otherwise they can become permanent."]},{"source_id":"SRC2","title":"CIC Management of Change","url":"https://minerva.jrc.ec.europa.eu/en/shorturl/technical_working_group_2_seveso_inspections/cic_management_of_change","publisher":"European Commission Joint Research Centre, MINERVA","date_or_year":"2023","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Management of change covers permanent and temporary instrument or control-system changes affecting safety.","Temporary changes should have fixed time limits, controlled extensions, reapproval, documentation, and a procedure to verify removal or restoration.","Change evaluation should involve affected specialties, assess wider impacts, assign responsibility, and verify the intended outcome before final approval."]},{"source_id":"SRC3","title":"NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf","publisher":"National Institute of Standards and Technology","date_or_year":"2023","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["OT guidance calls for current asset inventories with identifiers, versions, ownership roles, and updates when components are added, removed, or changed.","Configuration changes should be tested, validated, documented, periodically reviewed, and aligned with management-of-change practices.","OT changes should be tested before production use and have recovery plans; protected backups and retained previous configurations support restoration."]},{"source_id":"SRC4","title":"Control systems — Technical Measures Document","url":"https://www.hse.gov.uk/comah/sragtech/techmeascontsyst.htm","publisher":"UK Health and Safety Executive","date_or_year":"2025","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Control-system modifications require management controls, competent implementation, and verification that safety functions and integrity remain intact.","Passive monitoring, active control, and software-change modes have materially different hazards.","Change control and software backups are relevant safeguards, and remote software or parameter modification can create unexpected operations or affect safety functions."]},{"source_id":"SRC5","title":"Management of change at a major hazard facility","url":"https://content-v2.api.worksafe.vic.gov.au/sites/default/files/2020-12/ISBN-Management-of-change-at-major-hazard-facility-2020-12.pdf","publisher":"WorkSafe Victoria","date_or_year":"2020","source_type":"OFFICIAL_GUIDANCE","language":"English","claims_supported":["Temporary changes include bypassed alarms and changes to control, alarm, or trip-system software or calibration.","Temporary changes require duration limits and checks preventing unreviewed permanence.","Change records should include authorization, commissioning, reversal, and before-and-after documentation; superseded versions should be withdrawn from use or marked uncontrolled.","Post-implementation review should test whether the intended effect occurred and consider reversing a change that increases risk."]},{"source_id":"SRC6","title":"Regulamento Técnico do Sistema de Gerenciamento da Segurança Operacional — Prática de Gestão nº 16: Gerenciamento de Mudanças","url":"https://www.gov.br/anp/pt-br/assuntos/exploracao-e-producao-de-oleo-e-gas/orientacoes-aos-concessionarios-e-contratados/arquivos/regulamento_sgso.pdf/%40%40download/file","publisher":"Agência Nacional do Petróleo, Gás Natural e Biocombustíveis, Brazil","date_or_year":"2007","source_type":"OFFICIAL_STANDARD","language":"Portuguese","claims_supported":["Operators must manage permanent and temporary changes so operational-safety risks remain acceptable.","The regulation requires pre-implementation hazard and impact assessment, documentation updates, communication, and authorization at an appropriate management level.","Extending a temporary change requires review and renewed authorization, and change records must be archived for specified retention periods."]},{"source_id":"SRC7","title":"Welcome to FactoryTalk AssetCentre Web Client","url":"https://www.rockwellautomation.com/en-id/docs/factorytalk-assetcentre/16-00-00/assetcentrewebhelp-ditamap/welcome-to--ftasc--web-client.html","publisher":"Rockwell Automation","date_or_year":"2026","source_type":"FIRST_PARTY_PRODUCT","language":"English","claims_supported":["A commercial automation-asset product implements program-file version control, document archiving, management-of-change workflows, event and user audit logs, and controller change detection.","Scheduled disaster-recovery checks compare device programs and configurations with protected master files to support recovery.","The product exposes lifecycle information, archive history, device monitoring, and archive-cleanup controls, but the documentation does not show automatic withdrawal of an overlay's execution authority."]},{"source_id":"SRC8","title":"An Architectural Description of the Simplex Architecture","url":"https://www.sei.cmu.edu/documents/1146/1996_005_001_16463.pdf","publisher":"Carnegie Mellon University Software Engineering Institute","date_or_year":"1996","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Simplex was designed for safe online evolution of process-control software using monitored fallback and explicit control-authority switching.","During replacement, a new unit computes while its output is monitored but unused; after synchronization, the old output is disabled and the new output enabled.","If switching fails, the system can return authority to the old unit and abort the replacement; the architecture also permits adding, deleting, merging, or splitting replacement units."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The broader problem is well supported: official guidance reports catastrophic consequences from uncontrolled temporary changes, specifically includes bypassed alarms and control-system software, and warns that temporary changes become permanent without time limits and review. The retained evidence does not quantify the prevalence of expired controller patches or model overlays, nor directly establish that accumulated overlays commonly cause conflicting feedback rather than other control or plant faults.","source_ids":["SRC1","SRC2","SRC4","SRC5","SRC6"],"uncertainty":"The exact phenotype—multiple superseded overlays simultaneously retaining actuator-path authority and producing attributable modal or residual effects—remains an empirical hypothesis requiring a bounded inventory and replay study."},"adopter_evidence":{"status":"SUPPORTED","finding":"An identifiable adopter and authorizer exist: the accountable facility or control-system owner and operational management, supported by control engineers and subject to competent safety review. Multiple official sources assign change approval, documentation, and review duties to operators or senior management.","source_ids":["SRC2","SRC4","SRC5","SRC6"],"uncertainty":"The precise organizational title and whether independent compliance approval is legally required vary by jurisdiction, system criticality, and facility governance."},"implementation_evidence":{"status":"PARTLY_SUPPORTED","finding":"Most implementation elements exist separately in established practice: inventories, identifiers, change logs, time limits, reauthorization, impact review, reversal records, version archives, protected baselines, recovery, passive monitoring, and authority switching with rollback. No retained source integrates regime-validity decay, dependency and hold gates, matched three-arm replay, actuator-contribution shadowing, and preregistered modal diagnostics into one overlay-expiration workflow.","source_ids":["SRC2","SRC3","SRC4","SRC5","SRC6","SRC7","SRC8"],"uncertainty":"Commercial documentation establishes available configuration-management capabilities, not that plants routinely represent each control overlay as an independently withdrawable actuator contribution or can identify its local dynamic effect."},"prior_art":{"disposition":"ADJACENT_PRIOR_ART","closest_analogues":[{"name":"Temporary-change management of change for control, alarm, and trip systems","source_ids":["SRC1","SRC2","SRC5","SRC6"],"same_problem":true,"same_causal_lever":true,"overlap":"This practice identifies temporary changes, assigns owners and approvers, evaluates cross-system risk, imposes time limits, requires reauthorization, preserves records, and removes, reverses, or formalizes a change when its authorized period ends.","remaining_difference":"It generally treats a change as a governed plant configuration rather than an independently attributable overlay contribution and does not prescribe matched active-versus-shadow replay or modal diagnostics."},{"name":"Simplex online controller replacement and runtime assurance","source_ids":["SRC8"],"same_problem":false,"same_causal_lever":true,"overlap":"A candidate controller computes while its output is monitored but not used; explicit switching transfers plant authority, and failed switching can restore the prior controller. This closely anticipates shadow execution, reversible authority withdrawal, and safety gating.","remaining_difference":"Simplex addresses safe upgrades and runtime controller failures, not discovery and lifecycle expiration of accumulated superseded overlays, regulatory holds, archival retention, or comparison against an age-only expiry rule."},{"name":"FactoryTalk AssetCentre automation configuration management","source_ids":["SRC7"],"same_problem":true,"same_causal_lever":false,"overlap":"The product supplies controller-oriented asset records, versions, protected masters, management-of-change workflow, audits, change detection, archives, and recovery support.","remaining_difference":"The documented product manages files and configurations but does not directly shadow or revoke one overlay's actuator-path authority based on regime validity or measured dynamic contribution."},{"name":"NIST OT inventory, change-control, testing, and recovery guidance","source_ids":["SRC3"],"same_problem":true,"same_causal_lever":false,"overlap":"The guidance covers accurate inventories, ownership, configuration review, testing, validation, retained configurations, backups, and recovery plans for operational technology.","remaining_difference":"It does not define overlay-level lifecycle states, confidence decay, supersession-triggered authority withdrawal, or the proposed causal test."}],"contrastive_claim_remaining":"For one non-safety-critical superseded overlay whose actuator contribution is separately identifiable, lifecycle-gated shadowing based on regime validity, dependency, hold, restoration, residual, coupling, and spectral-gap checks will remain noninferior to the current-active stack on preregistered safety, stability, settling, and recovery measures while improving at least one preregistered response or interpretability metric beyond measurement error relative to both the current-active baseline and fixed age-only expiry.","contrastive_claim_falsifier":"The claim is falsified if no eligible overlay exists or its contribution cannot be identified within tolerance; or, on held-out matched disturbances, gated shadowing creates any new constraint violation or restoration failure, exceeds the baseline test-retest noninferiority bound, or fails to improve a preregistered response or interpretability metric beyond measurement error relative to both comparators.","confidence":"HIGH","search_limitations":"The bounded search used exactly eight retained sources across six adversarial lanes and included U.S., European, UK, Australian, Brazilian, commercial, and historical research terminology. It did not inspect paywalled full standards, patents, proprietary plant configurations, incident databases exhaustively, or unpublished product features. The search cannot establish world novelty, patentability, freedom to operate, prevalence, market size, or realized impact."},"researchability_gates":{"externally_supported_problem":{"status":"PASS","rationale":"Official sources establish that uncontrolled temporary changes can persist, cause severe harm, and specifically include bypassed alarms and control-system software. That is sufficient external support for testing the narrower overlay-accumulation hypothesis despite uncertainty about its prevalence.","source_ids":["SRC1","SRC2","SRC4","SRC5","SRC6"]},"identifiable_adopter_or_authorizer":{"status":"PASS","rationale":"Facility and control-system owners, operational management, competent engineers, and safety reviewers are identifiable, and official sources assign approval and review responsibilities to operator management.","source_ids":["SRC2","SRC4","SRC5","SRC6"]},"distinct_testable_incremental_claim":{"status":"PASS","rationale":"Prior art covers lifecycle governance, archiving, shadow computation, switching, and rollback, but no retained source combines regime- and dependency-gated expiration with matched three-arm replay and preregistered attribution and modal diagnostics. The remaining comparative claim is measurable and falsifiable.","source_ids":["SRC2","SRC3","SRC5","SRC7","SRC8"]},"bounded_next_evidence_step":{"status":"PASS","rationale":"A single-subsystem, offline replay with one non-safety-critical superseded overlay, fixed operating window, matched disturbances, three predefined arms, signed restoration image, and explicit halt criteria is a bounded evidence step consistent with established testing, monitoring, review, and rollback practices.","source_ids":["SRC3","SRC4","SRC5","SRC8"]},"no_unresolved_safety_or_authority_stop":{"status":"PASS","rationale":"The authorized first step is offline and reversible, excludes safety-critical withdrawal and deletion, preserves holds and evidence, and requires accountable owner plus safety/compliance approval. These restrictions align with official requirements for competent authorization, safety verification, impact assessment, records, and reversal.","source_ids":["SRC2","SRC4","SRC5","SRC6"]},"adequate_search_evidence":{"status":"PASS","rationale":"All six required lanes were searched adversarially. Eight direct retained sources were opened, span seven independent publishers, and include official guidance, an official regulation, first-party product documentation, and primary historical research.","source_ids":["SRC1","SRC2","SRC3","SRC4","SRC5","SRC6","SRC7","SRC8"]}},"strict_success":true,"screen_survival":true,"remaining_research_value":"MODERATE","recommended_next_step":"Pre-register and execute the proposed offline replay pilot on one subsystem and one non-safety-critical superseded overlay. First complete the authority, dependency, hold, and signed-restoration checks; then run current-active, lifecycle-gated shadow, and age-only shadow arms on matched disturbances. Estimate active and shadow operators from the same identification method, preregister residual, coupling, spectral-gap, constraint, noninferiority, settling, interpretability, and restoration thresholds, and retain the full configuration and disposition record. Do not proceed to live authority withdrawal unless the owner and independent safety/compliance reviewer accept the replay evidence.","world_novelty_boundary":"This result identifies adjacent public prior art and a bounded contrastive research claim only. It does not establish world novelty, patentability, freedom to operate, market size, routine deployability, or realized safety and performance impact."}