{"closest_prior_art":[{"name":"ALA Library Privacy Guidelines for Library Management Systems","overlap":"Calls for defined retention periods, secure destruction, purging expired or inactive accounts, coverage of backups, vendor compliance, analytics-risk review, and regular privacy audits.","remaining_difference":"It does not prescribe a boundary-stable monthly balance of starting expired stock, newly expired records, verified clearances, exception transfers, ending stock, residuals, age thresholds, and threshold-linked actions across coupled stores.","source_ids":["SRC1"]},{"name":"CARLI Alma User Purge workflow","overlap":"Identifies records whose purge dates have passed, reports their age, excludes active or cross-institution transactions, requires staff-reviewed deletion sets, and connects eligibility reports to purge jobs.","remaining_difference":"It is principally a single-platform purge workflow; it does not reconcile longitudinal expired-record stocks and flows across analytics, exports, backups, vendors, and exception stocks or use cross-store residual thresholds.","source_ids":["SRC2"]},{"name":"San José Public Library Privacy Audit","overlap":"Inventories patron-data practices, records scheduled purges, identifies vendor transaction data awaiting a deletion schedule, and finds deficiencies in policies for extracts, storage, and sharing.","remaining_difference":"The audit is a close cross-system governance practice but does not expose a recurring stock-flow ledger, predicted-versus-observed ending stock, explicit reconciliation residuals, or capacity-based operating bands.","source_ids":["SRC3"]},{"name":"Ex Libris Alma anonymization and purge controls","overlap":"Provides retention-driven jobs for letters, irreversible unlinking of fulfillment history, user-account purging, selectable retained fields, and separate treatment of anonymization and account deletion.","remaining_difference":"The product controls individual clearance mechanisms but do not themselves provide the proposed cross-store stock-flow reconciliation, hidden-reservoir tests, or decision thresholds based on accumulated expired identifiable records.","source_ids":["SRC4"]}],"contrastive_claim_falsifier":"The claim is falsified if the retrospective shows that existing audits, eligibility reports, purge and anonymization jobs, vendor evidence, and exception controls already reconstruct the same bounded stock with tolerable residuals and prompt the same safe actions, or if ledger warnings would not have changed any documented decision after expected processing lags.","contrastive_claim_remaining":"For a stable multi-store boundary, monthly reconciliation of expired identifiable record stock—together with level, oldest-age, and unexplained-residual thresholds—provides materially earlier or different authorized retention actions than retention schedules, privacy inventories, eligibility reports, and purge-job results alone.","experiment_id":"eoa_inverse_innovation_exp13_second_slot_policy60_20260806","gates":{"adequate_source_search":{"rationale":"The bounded search covered the proposal directly, historical and synonymous terms such as lapsed or stale patron records, ALA/NISO guidance, Alma/Polaris/Sierra practices, and combinations involving inventories, backups, analytics, vendors, deletion, anonymization, and audit. Four opened sources from four publishers were retained, including official guidance and first-party product documentation. Phrase misses were not treated as novelty evidence.","source_ids":["SRC1","SRC2","SRC3","SRC4"],"status":"PASS"},"bounded_next_test":{"rationale":"Six read-only month-end reconstructions from existing timestamps, inventories, job logs, exception registers, and vendor reports are finite and measurable. Predeclared eligibility, counting, lag, and residual tolerances allow comparison with documented baseline decisions before any deletion or anonymization is authorized.","source_ids":["SRC1","SRC2","SRC3","SRC4"],"status":"PASS"},"distinct_testable_claim":{"rationale":"Existing guidance and tools address inventories, retention periods, eligible-record reports, purge sets, anonymization, and audits. The remaining contrast is whether a recurring cross-store stock-flow balance with level, age, and residual thresholds changes authorized decisions; that difference is observable and falsifiable.","source_ids":["SRC1","SRC2","SRC3","SRC4"],"status":"PASS"},"no_obvious_safety_or_authority_stop":{"rationale":"The first step is read-only and preserves system-owner, records, legal-hold, research, security, and contractual authority. Existing guidance supports audits and careful eligibility review. The proposed halts address classification errors, unexplained residuals, vendor discrepancies, and displacement; the reconciliation extract must itself remain access-controlled and governed.","source_ids":["SRC1","SRC2","SRC3"],"status":"PASS"},"supported_problem":{"rationale":"Operational evidence shows that eligible Alma records require manual purge jobs, letters can remain indefinitely by default, purging a user can leave patron-linked fulfillment identifiers, and a library audit found vendor-transaction deletion and extract-governance work unfinished. This makes persistence beyond intended need visible, although no retained source measures the proposal's exact cross-system stock.","source_ids":["SRC2","SRC3","SRC4"],"status":"PASS"}},"prior_art_disposition":"ADJACENT_PRIOR_ART","problem_evidence":{"finding":"The component problem is directly visible: retention deadlines do not guarantee clearance. Eligible records may await manually initiated jobs; separate artifacts and links require distinct anonymization or purge controls; and vendor transactions or extracts may lack completed deletion procedures. The sources do not document one library performing the proposed full cross-store monthly balance, so support is partial rather than conclusive for the exact formulation.","source_ids":["SRC1","SRC2","SRC3","SRC4"],"status":"PARTLY_SUPPORTED"},"research_id":"eoa_inverse_innovation_exp13_light_screen_20260806","schema_version":1,"screen_id":"E13P166","screen_survival":true,"search_lanes":{"component_combination":{"no_result_note":null,"queries":["library systems data inventory retention deletion backups analytics vendor audit","ALA NISO standard library user data retention deletion audit vendor backups","library circulation records retention schedule anonymization deletion logs"],"source_ids":["SRC1","SRC2","SRC3","SRC4"]},"direct_problem_and_intervention":{"no_result_note":null,"queries":["library patron records retention expired records deletion reconciliation audit","library privacy audit patron data retained longer than retention period vendor deletion","expired patron accounts not purged library ILS audit"],"source_ids":["SRC2","SRC3","SRC4"]},"products_practices_and_standards":{"no_result_note":null,"queries":["Alma Polaris Sierra patron purge anonymization retention vendor documentation","library patron data lifecycle audit purge logs anonymization vendor","library patron data retention purge backups vendors privacy guidelines"],"source_ids":["SRC1","SRC2","SRC4"]},"synonyms_and_historical_terms":{"no_result_note":null,"queries":["\"lapsed library card holders\" purge patron database privacy audit","\"stale patron records\" library purge circulation","NISO library patron privacy data lifecycle retention disposal"],"source_ids":["SRC1","SRC3"]}},"sources":[{"claims_supported":["Libraries should define retention periods, securely destroy no-longer-needed data, purge expired or inactive accounts, cover archival copies and backups, bind vendors to library retention policies, and conduct regular privacy audits.","Analytics exports and vendor-hosted analytics create additional patron-data storage and privacy risks."],"publisher":"American Library Association","source_id":"SRC1","source_type":"OFFICIAL_GUIDANCE","title":"Library Privacy Guidelines for Library Management Systems","url":"https://www.ala.org/advocacy/privacy/guidelines/library-management-systems"},{"claims_supported":["Alma does not automatically delete user records; staff must run purge jobs for records whose purge dates have passed.","CARLI supplies reports of past-due purge records and recommends reviewed sets that exclude active or cross-institution obligations before deletion."],"publisher":"Consortium of Academic and Research Libraries in Illinois","source_id":"SRC2","source_type":"TRADE_PROFESSIONAL","title":"Alma User Purge","url":"https://www.carli.illinois.edu/products-services/i-share/user-management/user-purge"},{"claims_supported":["A first-party library privacy audit documented annual patron-record purges and separate retention practices across systems.","The audit identified unfinished vendor-transaction deletion scheduling and missing formal procedures for extracted patron data, showing gaps between policy and operational clearance."],"publisher":"San José Public Library","source_id":"SRC3","source_type":"OFFICIAL_GUIDANCE","title":"Privacy Audit","url":"https://www.sjpl.org/privacy-audit/"},{"claims_supported":["Alma requires distinct procedures for fulfillment anonymization, notification-letter retention, and user-account purging.","Patron letters are retained indefinitely by default, and purging a user without fulfillment anonymization can leave a loan linked to a patron identifier."],"publisher":"Ex Libris","source_id":"SRC4","source_type":"FIRST_PARTY_PRODUCT","title":"How to Set Up Anonymization","url":"https://knowledge.exlibrisgroup.com/Alma/Best_Practices_and_How-Tos/Fulfillment/How_Tos/How_to_Set_Up_Anonymization"}],"world_novelty_boundary":"This bounded public-web screen found adjacent guidance, audit practice, and product workflows but no retained source specifying the complete proposed cross-store stock-flow ledger and threshold policy. That result cannot establish world novelty, patentability, market size, expert acceptance, or realized value; unsearched patents, nonpublic implementations, other jurisdictions, and differently indexed terminology may contain closer art."}