{"actors":["Digital preservation manager","Repository and storage administrators","Digital archivists and collection curators","Records-management and legal-retention owners","Information-security and preservation-governance reviewers"],"affected_objective":"Long-term integrity and recoverability of preserved digital objects across storage locations, ingest cohorts, file-format families, and successive fixity-audit windows.","arm":"ORDINARY_DIVERSE_P2","authority_safety":{"authorized_first_step":"Perform a read-only retrospective analysis of approved repository manifests, fixity-audit events, replica-state histories, and repair logs using object identifiers and operational cohort labels; produce no storage or object changes.","decision_authority":"The digital preservation manager may authorize analysis and recommend review. Repository administrators control replica operations, collection curators approve preservation treatments affecting intellectual objects, records or legal owners approve actions governed by retention obligations, and designated preservation governance approves production changes.","excluded_actions":["No deletion, replacement, migration, quarantine, or relocation of preserved objects or replicas during the first evidence step.","No alteration of checksums, manifests, audit histories, provenance records, or retention metadata.","No automatic preservation treatment based solely on a cohort alert or aggregate risk score.","No relaxation of replica, fixity, authenticity, or retention requirements to improve the headline indicator.","No inference that a file-format family or collection is defective solely because it contains a flagged object trajectory."],"halt_rollback":"Halt if object identities cannot be joined consistently across audit and repair systems, audit regimes changed without traceable versioning, access would expose restricted content rather than operational metadata, or a proposed interpretation conflicts with retention or authenticity requirements. The read-only step is rolled back by deleting derived analytic tables under the approved retention procedure and issuing no treatment recommendation."},"baseline":"Repository oversight emphasizes a rolling proportion of eligible digital objects whose required replica sets pass scheduled fixity checks. Operators repair failures as tickets arise, while the stable repository-wide pass rate is reviewed without routinely distinguishing objects that remain healthy from objects repeatedly cycling through failure, reduced redundancy, and repair.","candidate_id":"ensemble_and_population_level_equilibrium_versus_individual_level_heterogeneity__library_information_science__ORDINARY_DIVERSE_P2","causal_chain":["Preserved objects occupy different file-format families, ingest cohorts, storage tiers, replica topologies, and hardware locations, giving them different sequences of fixity and redundancy states.","In each audit window, the repository aggregates object-level pass states into one proportion of eligible objects meeting the required replica condition.","Repairs can return some objects to compliance while other objects fail, leaving the aggregate proportion stable even when particular objects or operational cohorts repeatedly enter degraded states.","The aggregate calculation discards transition histories, duration under reduced redundancy, recurrence, and shared failure locations.","When the stable proportion is treated as sufficient evidence about every preserved object, repeated or clustered degradation is managed as isolated tickets rather than as an object- or cohort-level preservation condition.","A trajectory-based relevance test separates transient independent failures from sustained recurrence, prolonged exposure, or correlated replica degradation.","Authorized owners can then consider treatment at the implicated object, cohort, storage, or workflow level while continuing to monitor repository-wide equilibrium and object-level outcomes."],"cell_id":"ensemble_and_population_level_equilibrium_versus_individual_level_heterogeneity__library_information_science","consequence":"Objects that repeatedly lose valid replicas, remain under-redundant, or share a failure-prone storage dependency can approach a recoverability or authenticity threshold without being distinguished by a stable repository-wide fixity pass rate.","diversity_from_prior_proposals":"This opportunity concerns preservation-object state transitions and replica recoverability rather than patron discovery outcomes. Its intervention is a trajectory-triggered preservation treatment gate operating across object cohorts and storage dependencies, and its causal path runs from failure-repair turnover through stable fixity equilibrium to hidden recurrent degradation.","experiment_id":"eoa_inverse_innovation_exp13_second_slot_policy60_20260806","intervention":"Institute a preservation trajectory gate alongside the repository-wide fixity indicator. For each eligible object, derive an auditable sequence of compliant, reduced-redundancy, failed, repaired, and unaudited states; summarize recurrence, duration, and correlated replica exposure by predeclared operational cohorts; and route only sustained or threshold-crossing patterns to human preservation review. Reviewers may recommend replica relocation, storage remediation, renewed format validation, or a separately approved preservation treatment, while the macro indicator and unaffected heterogeneity remain intact.","mechanism_mapping":[{"counterfactual_removal":"Without the joint display, a stable repository-wide pass rate cannot reveal whether the same objects repeatedly account for degraded states.","mechanism_slug":"distributional_dashboard","role":"Presents the macro fixity indicator beside object-state durations, transition counts, recurrence distributions, and supported cohort cuts for the same audit windows."},{"counterfactual_removal":"Without the translation rule, reviewers cannot tell how object and replica states produce the headline proportion or which trajectory information aggregation removes.","mechanism_slug":"micro_macro_crosswalk","role":"Defines eligibility, the object-level pass rule, replica requirements, audit timing, exclusions, and the pooling operation used to calculate repository-wide compliance."},{"counterfactual_removal":"Without decomposition, clustered storage or ingest-cohort effects can be confused with independent transient object failures.","mechanism_slug":"variance_decomposition_table","role":"Separates variation associated with objects, ingest cohorts, format families, storage locations, replica topology, and audit windows, with uncertainty and missing-audit states retained."},{"counterfactual_removal":"Without a predeclared excursion rule, isolated failures may prompt unnecessary treatments while recurrent degradation remains indistinguishable from routine repair traffic.","mechanism_slug":"subgroup_excursion_alert","role":"Routes sufficiently observed recurrence, prolonged reduced redundancy, or correlated replica degradation to an authorized human reviewer."},{"counterfactual_removal":"Without controlled perturbation analysis, the repository cannot examine whether stable aggregate compliance depends on a fragile repair rate, storage location, or cohort composition.","mechanism_slug":"equilibrium_stress_test","role":"Uses offline scenarios to vary repair delay, replica loss, audit coverage, and cohort composition and observes both aggregate compliance and object-level threshold crossings."}],"nearest_rivals":["Equilibrium restoration: it would address a repository-wide fixity indicator that has left its operating band; this opportunity applies while that aggregate state remains stable.","Aggregation bias detection and correction: it would challenge object eligibility, weighting, or pass-state construction; here the declared aggregate can be valid while remaining insufficient for claims about object trajectories.","Variability characterization: it would catalog differences in audit or repair histories without making their relationship to stable repository-wide compliance the organizing decision problem.","Routine incident management: it resolves individual audit failures but need not identify how recurring microstate transitions coexist with or sustain the macro equilibrium.","Digital-format risk assessment: it evaluates format characteristics, whereas this opportunity begins with heterogeneous object and replica trajectories beneath an aggregate operational state."],"negative_tests":{"intervention_falsifier":"The trajectory gate is falsified as a useful intervention if, under consistent instrumentation and predeclared thresholds, recurrent or cohort-clustered histories do not yield reproducible treatment distinctions beyond ordinary incident handling, or reviewers cannot assign flagged conditions to an authorized and technically relevant owner.","problem_falsifier":"The problem is falsified if the repository-wide indicator is not stable in the declared audit regime, if the indicator is invalid because eligibility or audit coverage is systematically wrong, or if object histories show no consequential recurrence, prolonged reduced redundancy, or correlated degradation beneath it.","risks":["Incomplete or changing audit coverage may make unaudited objects appear healthy or create artificial trajectories.","Identifier changes and repair-ticket joins may incorrectly merge or split object histories.","Small cohorts can create unstable alerts or reveal restricted collection structure.","Format, collection, or ingest-cohort labels may be treated as deterministic risk labels despite heterogeneous members.","Extra audits or preservation treatments can consume storage and staff capacity without addressing the causal condition.","Replica independence may be overstated when locations share hardware, software, administrative, or geographic dependencies.","A local treatment could alter provenance or authenticity if executed outside approved preservation procedures."],"strongest_counterevidence":"The strongest counterevidence would be that repeated degradation patterns disappear after audit schedules, identifier mappings, and repair-event timestamps are harmonized, showing that the apparent microstate heterogeneity was produced by instrumentation rather than object or storage conditions."},"next_evidence_step":"Pre-register one repository's ensemble boundary, object-level pass rule, required replica states, audit window, operational cohorts, missing-audit treatment, and recurrence or duration thresholds. Then conduct a read-only analysis of twelve completed audit windows, reconstruct object-state trajectories, compare them with the stable aggregate series, and manually validate a bounded sample of flagged and unflagged histories against manifests and repair tickets. Produce a governance memo on whether any treatment pilot is warranted, without modifying preserved content or infrastructure.","observable_state":"Across successive scheduled audit windows, the proportion of eligible objects whose required replica sets pass fixity remains within the repository's declared operating band. Beneath that stable series, object histories may differ: some remain continuously compliant, some experience isolated failures, and others repeatedly enter reduced-redundancy or repair states, potentially clustering by ingest cohort, storage dependency, replica topology, or format family.","prior_art_status":"UNSEARCHED","problem":"A digital repository can maintain a valid, stable object-level fixity compliance rate while particular preserved objects or operational cohorts repeatedly cycle through failure, reduced redundancy, and repair. Extending the stable population claim to every object hides trajectory-specific recoverability conditions and prevents preservation action from being matched to their causal level.","proposal_index":2,"remaining_contrastive_claim":"This proposal is warranted specifically when valid, stable repository-wide fixity compliance coexists with consequential heterogeneity in object or replica trajectories. If the aggregate is invalid, repository-wide integrity is deteriorating, or trajectory differences have no preservation consequence, a neighboring approach is more appropriate.","revision_record":{"claim_changes":[],"conceptual_changes":[],"evidence_changes":[],"operational_changes":[],"parent_version":null,"progress_targets_addressed":["Constructed one independent library-and-information-science opportunity centered on digital preservation rather than discovery.","Preserved the macro-equilibrium, microstate-profile, aggregation-translation, level-boundary, relevance-test, and multi-level-feedback structure.","Specified bounded authority, authenticity and retention safeguards, falsifiers, operational risks, and a read-only evidence step."]},"schema_version":1,"structural_mapping":[{"archetype_element":"Ensemble Frame","domain_realization":"All eligible preserved digital objects governed by one declared replica policy and observed across successive scheduled audit windows; each object-window is a realization, with exclusions and missing audits represented explicitly."},{"archetype_element":"Macro Equilibrium Indicator","domain_realization":"The proportion of eligible objects whose required replica sets satisfy the declared fixity condition in each audit window, considered stable only within an established operating band and unchanged audit regime."},{"archetype_element":"Microstate Variability Profile","domain_realization":"Per-object sequences of compliant, failed, repaired, reduced-redundancy, and unaudited states, including recurrence counts, state durations, repair intervals, and correlated replica events."},{"archetype_element":"Aggregation Translation Rule","domain_realization":"Each eligible object contributes one pass or non-pass state per audit window to the repository-wide proportion; pooling removes transition order, recurrence, degraded-state duration, replica dependency, and cohort locality."},{"archetype_element":"Level-of-Analysis Boundary","domain_realization":"The headline indicator supports a claim about the eligible repository population during a window, not a claim that each object is continuously healthy, equally recoverable, or exposed to independent replica risks."},{"archetype_element":"Heterogeneity Relevance Test","domain_realization":"Variation becomes reviewable when consistent data show sustained recurrence, excessive time below required redundancy, correlated replica degradation, or proximity to a preapproved recoverability or authenticity threshold; isolated self-contained failures can remain routine variation."},{"archetype_element":"Subgroup and Locality Map","domain_realization":"Supported patterns are localized by ingest cohort, storage location, replica topology, preservation workflow, format family, and collection responsibility without treating a cohort label as a deterministic object judgment."},{"archetype_element":"Multi-Level Feedback Design","domain_realization":"Repository-wide compliance remains monitored while supported excursions are routed to object, collection, workflow, or infrastructure owners, and any approved treatment is checked for effects on both the flagged trajectories and aggregate integrity."},{"archetype_element":"Representative Case Guardrail","domain_realization":"Neither a single corrupted object nor a continuously healthy exemplar represents the repository; review samples multiple histories across trajectory classes and validates them against manifests and repair records."}],"title":"Trajectory-Gated Preservation Review Beneath Stable Fixity Compliance","version":0}