{"actors":["Digital preservation librarian","Repository administrator","Archivist responsible for the collection","Information-security liaison for escalation","Records or curatorial authority responsible for authenticity determinations"],"affected_objective":"Preserve the integrity, authenticity, and provenance of a digital archival object implicated in an unexplained fixity anomaly without overwriting evidence or treating a checksum discrepancy as proof of corruption or misconduct.","arm":"ORDINARY_DIVERSE_P2","authority_safety":{"authorized_first_step":"The digital preservation librarian may open a read-only anomaly dossier, capture existing manifests and event logs, and recompute checksums on isolated copies without changing the preservation package or production repository.","decision_authority":"The repository administrator authorizes replica or infrastructure actions; the responsible archivist and applicable records or curatorial authority authorize preservation-package changes; the information-security liaison controls any security escalation.","excluded_actions":["Do not overwrite, delete, normalize, or promote any replica while the explanation remains unresolved.","Do not treat a checksum mismatch as proof of unauthorized alteration, corruption, or staff misconduct.","Do not expose restricted object contents or preservation logs beyond existing access permissions.","Do not repair manifests, provenance records, or preservation packages on the strength of a working explanation.","Do not collapse distinct object versions merely because their descriptive identifiers match."],"halt_rollback":"Stop if a probe would modify package contents, timestamps, manifests, replicas, or production logs; preserve the original traces, discard any derived working copy, and return the dossier to an unresolved state if new evidence contradicts the working explanation."},"baseline":"A fixity alert is often routed directly toward replica replacement, checksum regeneration, or technical incident handling, even when the observed mismatch could arise from several different content, manifest, workflow, or measurement histories and the evidence needed to distinguish them is dispersed across systems.","candidate_id":"abductive_explanation_selection__library_information_science__ORDINARY_DIVERSE_P2","causal_chain":["A scheduled or manual fixity check reports an inconsistent checksum pattern for a preserved digital object or package.","Staff bound the explanandum to the specific object versions, manifests, replicas, algorithms, timestamps, and repository events involved, recording those traces separately from claims about corruption or alteration.","They construct a candidate set including storage-level change, manifest-to-object misassociation, an incompletely recorded authorized transformation, replica synchronization lag, checksum-tool or configuration difference, and a lower-probability unauthorized alteration.","Each explanation is compared against replica topology, byte counts, algorithm identifiers, provenance events, ingest or migration timing, log continuity, related-object patterns, missing traces, and required exceptions.","A working explanation is selected only when it accounts for the mismatch materially better than its nearest rival; otherwise the dossier retains a ranked tie.","The result is labeled provisional, contested, or unresolved and is restricted to read-only investigation and preservation-safe containment.","Staff derive a discriminating probe, such as independently recomputing multiple algorithms on isolated copies or comparing contemporaneous manifests and event logs across replicas.","Probe outcomes update the ranked explanations and determine whether the case proceeds to authorized preservation repair, provenance correction, infrastructure investigation, security escalation, or continued monitoring."],"cell_id":"abductive_explanation_selection__library_information_science","consequence":"Prematurely interpreting a fixity anomaly can cause staff to replace an authentic version with the wrong replica, rewrite provenance around an unverified account, overlook a repository defect, or escalate a benign workflow discrepancy as a security event.","diversity_from_prior_proposals":"This opportunity addresses preservation-integrity anomalies in archival packages rather than failed information retrieval. Its intervention operates on fixity manifests, replicas, provenance events, and preservation authority, and its causal path runs from an integrity trace through reconstruction of competing object histories to a preservation-safe probe.","experiment_id":"eoa_inverse_innovation_exp13_second_slot_policy60_20260806","intervention":"Establish a Preservation Fixity Anomaly Dossier for checksum discrepancies that lack an immediately deterministic explanation. The dossier fixes the observation boundary, separates repository traces from interpretations, compares a required set of competing object-history explanations, records a provisional leader or unresolved tie, limits action according to confidence and preservation risk, and specifies one read-only probe that can distinguish the leading accounts before any replica or manifest is changed.","mechanism_mapping":[{"counterfactual_removal":"Without the reconstruction record, staff may compare current files while overlooking that different authorized or unauthorized event sequences could have produced them.","mechanism_slug":"forensic_scenario_reconstruction","role":"Builds rival histories connecting manifests, replicas, transformations, and repository events to the observed fixity pattern."},{"counterfactual_removal":"Without an explicit comparison matrix, one conspicuous mismatch can dominate despite conflicting timing, provenance, algorithm, or replica evidence.","mechanism_slug":"inference_to_best_explanation_matrix","role":"Compares candidate histories using evidential coverage, temporal coherence, mechanism plausibility, missing traces, ad hoc assumptions, and discriminating consequences."},{"counterfactual_removal":"Without a disconfirming plan, repeated checksum computations may merely reproduce the anomaly without distinguishing content change from manifest, configuration, or synchronization explanations.","mechanism_slug":"disconfirming_probe_plan","role":"Specifies a read-only observation whose possible results separate the working explanation from its nearest rival."},{"counterfactual_removal":"Without a durable log, later repair, migration, or replica events can obscure which evidence supported the original explanation and what was expected next.","mechanism_slug":"abduction_log","role":"Tracks the candidate ranking, defeasibility status, predictions, probe results, and revision triggers across the anomaly's lifecycle."}],"nearest_rivals":["Automated fixity monitoring, which detects checksum agreement or disagreement but does not reconstruct and compare the histories that could explain an anomaly.","Automatic replica repair, which restores a selected copy only after assuming which replica is authoritative and which one is defective.","A provenance audit, which checks documentation completeness but need not rank competing explanations for a particular mismatch.","A cybersecurity incident workflow, which investigates possible unauthorized activity but can privilege that explanation over preservation-workflow, manifest, or measurement rivals.","Routine format-validation or characterization, which assesses file conformance and properties without explaining why fixity traces diverged."],"negative_tests":{"intervention_falsifier":"Given the same bounded set of anomaly traces, reviewers using the dossier do not produce more discriminating read-only probes, clearer authority limits, or more consistent revision decisions than reviewers following the existing anomaly workflow.","problem_falsifier":"Existing fixity cases already preserve the original traces, distinguish observations from interpretations, compare credible object-history rivals, record why one explanation outranks another, limit action by confidence, and define disconfirming probes and revision triggers.","risks":["The dossier may delay an urgent containment action when ongoing storage failure is independently evident.","Qualitative fit comparisons may create an appearance of precision unsupported by the available traces.","Staff may silently presume that the oldest or most available replica is authoritative.","Security concerns may receive too little attention because benign preservation-workflow explanations are more familiar.","Restricted content or sensitive repository logs may be exposed during cross-system comparison.","A working explanation may harden into the provenance record before authorized validation.","Read-only recomputation may still strain fragile storage or compromised media if isolation procedures are inadequate."],"strongest_counterevidence":"If a documented repository rule, using verified algorithm and version identifiers, deterministically identifies the authoritative bytes and maps the observed mismatch to a known state with no credible rival history, the case is rule-based validation rather than abductive explanation selection."},"next_evidence_step":"Choose eight closed, non-sensitive historical fixity anomalies representing manifest mismatch, authorized transformation, replica lag, tool configuration, storage change, and unresolved cases. Provide reviewers only the immutable traces available before resolution and have them complete read-only dossiers; compare their ranked explanations, proposed discriminating probes, and revision triggers with the subsequently documented event histories. No repository or package changes are authorized.","observable_state":"An immutable dossier records object and package identifiers, replica locations, byte counts, stored and recomputed checksums, algorithm and tool versions, manifest versions, timestamps, ingest or migration events, preservation actions, synchronization status, access-control events, and gaps in the logs. Statements such as “bit corruption,” “authorized migration,” or “unauthorized alteration” are stored only as candidate explanations.","prior_art_status":"UNSEARCHED","problem":"When a preserved digital object produces inconsistent fixity results across manifests, replicas, or verification runs, the mismatch does not by itself reveal what happened. Storage-level change, an authorized transformation with incomplete provenance, replica lag, manifest misassociation, tool configuration differences, and unauthorized alteration can leave overlapping traces. Acting on the first explanation can destroy evidential context or promote the wrong copy as authoritative.","proposal_index":2,"remaining_contrastive_claim":"The proposal adds case-level selection among competing histories of a preservation-integrity anomaly, coupled to defeasibility, preservation-safe action limits, and discriminating read-only probes; it is not merely checksum monitoring, replica repair, provenance documentation, format validation, or security triage.","revision_record":{"claim_changes":["Initial version; no claims revised."],"conceptual_changes":["Initial version instantiates abductive explanation selection around unexplained digital-preservation fixity anomalies."],"evidence_changes":["No external evidence consulted; prior art remains unsearched."],"operational_changes":["Initial version limits the first evidence step to retrospective review of eight closed, non-sensitive cases and authorizes no repository changes."],"parent_version":null,"progress_targets_addressed":["Material independence from the sealed retrieval-focused opportunity","Explicit preservation-integrity explanandum and trace boundary","Competing object-history explanations and auditable fit comparison","Provisional selection or preserved tie","Read-only discriminating probe and revision triggers","Preservation-specific authority and rollback limits","Problem and intervention falsifiers"]},"schema_version":1,"structural_mapping":[{"archetype_element":"Surprising Observation Record and Explanandum Boundary","domain_realization":"A defined object or package shows a particular disagreement among stored and recomputed checksums, manifests, replicas, or verification runs; the target is that bounded discrepancy rather than the repository's general reliability."},{"archetype_element":"Observation–Interpretation Separation","domain_realization":"Bytes, checksums, algorithms, manifests, timestamps, replica states, and event logs are recorded as observations; corruption, authorized transformation, configuration error, and unauthorized alteration remain interpretations."},{"archetype_element":"Candidate Explanation Set","domain_realization":"The dossier includes a leading account, common storage, synchronization, manifest, and tool explanations, an authorized-workflow explanation, and a lower-probability unauthorized-alteration rival that would change escalation."},{"archetype_element":"Explanatory Fit Criteria","domain_realization":"Candidate histories are assessed for coverage of replica and manifest evidence, temporal coherence, provenance continuity, mechanism plausibility, related-object patterns, missing expected traces, and dependence on unrecorded exceptions."},{"archetype_element":"Rival Comparison and Best-So-Far Selection","domain_realization":"The record identifies why a working object history outranks its nearest rival or preserves a ranked plurality when available traces remain observationally equivalent."},{"archetype_element":"Defeasibility Status and Action–Confidence Boundary","domain_realization":"A provisional explanation may authorize isolated recomputation, log inspection, or containment that preserves all versions, but not overwriting replicas, changing manifests, alleging misconduct, or declaring authenticity."},{"archetype_element":"Discriminating Evidence Plan","domain_realization":"The next probe is chosen for its ability to distinguish candidates, such as cross-algorithm recomputation on isolated copies, contemporaneous-manifest comparison, event-sequence reconstruction, or replica-state comparison."},{"archetype_element":"Revision Trigger and Explanation Owner","domain_realization":"The digital preservation librarian owns the dossier and must reopen the ranking when a predicted checksum relation fails, an unrecorded transformation appears, a log gap closes, a replica changes state, or a rival explains the traces with fewer unsupported events."}],"title":"Preservation Fixity Anomaly Dossiers","version":0}