{"actors":["Electronic-resources librarians who record licenses, coverage, activation, and platform changes","Catalog and discovery-system staff who publish patron-facing holdings and links","Authentication and proxy administrators who implement access rules","Publishers, aggregators, and knowledge-base providers that report entitlement and title changes","Patrons and reference staff who encounter or investigate access failures","Library data-governance and licensing officers who control sensitive records"],"affected_objective":"Produce an explainable, reproducible answer to whether a defined patron population should have been able to discover and access a specified electronic resource at a specified time.","arm":"COMMON_P1","authority_safety":{"authorized_first_step":"A designated electronic-resources librarian may create a read-only shadow ledger from a bounded set of closed access cases and generate experimental projections; no production catalog, proxy, license, or vendor record may be changed.","decision_authority":"The electronic-resources service owner decides whether a shadow result is operationally credible; the licensing officer governs contract-derived fields, the authentication administrator governs access-rule interpretations, and the library data-governance officer approves retention and role-based disclosure.","excluded_actions":["Do not infer patron identity or behavior from access-control events.","Do not expose license terms, vendor credentials, patron reports, or staff notes outside their existing access groups.","Do not treat an outage report as a confirmed outage or a vendor assertion as an adjudicated entitlement.","Do not mutate production discovery, ERM, proxy, link-resolver, or vendor systems during the first evidence step.","Do not use temporal sequence alone to assign fault or causation.","Do not retain raw request logs when a minimized case reference is sufficient."],"halt_rollback":"Stop the shadow exercise if reconstructing an event requires prohibited personal or contractual data, if identity links cannot be bounded without consequential guessing, or if the ledger exposes broader access than its source systems. Delete the shadow projections and restricted event copies under the pilot retention rule; production systems remain unchanged."},"baseline":"Current-state records in the electronic-resource management system, knowledge base, discovery index, proxy configuration, vendor portal, and support tickets are consulted separately. Staff reconcile them manually, while overwritten coverage dates, title transfers, corrections, and differing update times can prevent reproduction of the access state presented at an earlier moment.","candidate_id":"event_log_centered_modeling__library_information_science__COMMON_P1","causal_chain":["A license, title, coverage interval, platform, authentication rule, discovery setting, or outage changes through a bounded institutional or vendor-reported event.","Separate systems replace or asynchronously refresh their current-state fields, retaining different fragments of the change history.","When a patron reports missing or failed access, the visible records do not constitute one reproducible account of the entitlement, discoverability, and technical-access state at that decision time.","Staff must reconstruct the case from snapshots, tickets, messages, and vendor claims whose occurrence time, record time, evidentiary status, and corrections are not consistently distinguished.","The intervention accepts evidence-linked access events into a governed log using stable event and resource references, explicit participant roles, dual time, transformation deltas, and assertion status.","Versioned projectors replay eligible events under declared ordering and evidence rules to derive entitlement, discoverability, authentication, and case-timeline views with visible frontiers and conflicts.","Linked correction or late-arriving events trigger scoped rebuilds while preserving the state that staff and patrons could have observed at an earlier record-time frontier.","Rebuild-and-diff checks reveal whether live or experimental views can be reproduced from the accepted history and where source coverage is insufficient."],"cell_id":"event_log_centered_modeling__library_information_science","consequence":"The library may be unable to distinguish no entitlement from a suppressed record, stale coverage, platform migration, authentication defect, vendor outage, or unadjudicated report. Staff may also be unable to explain what access state was presented when a prior support or licensing decision was made.","diversity_from_prior_proposals":"Runtime isolation precludes comparison with prior proposals. This candidate is specifically organized around replaying licensed electronic-resource access states across entitlement, discovery, authentication, and outage events rather than around general collection provenance or patron-activity tracking.","experiment_id":"eoa_inverse_innovation_exp13_second_slot_policy60_20260806","intervention":"Create a governed electronic-resource access event ledger in which license execution or amendment, coverage grant or withdrawal, title merge or split, platform transfer, activation, discovery publication or suppression, proxy-rule change, outage report or confirmation, restoration, and correction are canonical event assertions. Each accepted assertion carries a stable event identity; persistent but uncertainty-aware resource, platform, institution, and patron-population references; participant roles; effective-time interval; record time; affected service context; before/after delta; provenance; and reported, corroborated, disputed, retracted, or adjudicated status. Idempotent ingestion quarantines duplicates and malformed assertions. Corrections append linked supersession or retraction records. Pinned projectors derive entitlement, discovery, authentication, patron-facing availability, case-timeline, and decision-time views, exposing their source coverage, processing frontier, unresolved conflicts, and completeness limits. Late evidence causes a scoped rebuild and materiality review rather than silent insertion into an existing view.","mechanism_mapping":[{"counterfactual_removal":"Without append-only storage, corrections and vendor updates can replace the evidence needed to reproduce an earlier access determination.","mechanism_slug":"append_only_event_store","role":"Preserves accepted access assertions and linked corrections as the bounded historical authority for the shadow model."},{"counterfactual_removal":"Without dual effective and record time, the model cannot separate when coverage or access applied from when the library learned or recorded it.","mechanism_slug":"bitemporal_event_register","role":"Supports both effective-date access projections and decision-time reconstructions of what was known."},{"counterfactual_removal":"Without idempotent identity checks, repeated vendor feeds, retries, or replay can multiply grants, withdrawals, and outage transitions.","mechanism_slug":"event_replay_deduplication","role":"Uses stable source-scoped event identities and acceptance records to prevent duplicate effects."},{"counterfactual_removal":"Without versioned projections, the ledger becomes an archive that cannot produce governed patron-facing or investigative views.","mechanism_slug":"event_sourced_projection","role":"Derives entitlement, discoverability, authentication, and composite access states from declared event types and evidence policies."},{"counterfactual_removal":"Without linked compensation or supersession, an incorrect coverage or title-transfer assertion must either persist as accepted or be silently overwritten.","mechanism_slug":"compensating_event_correction","role":"Preserves the earlier knowledge state while allowing a governed correction, retraction, or adjudication to change later projections."},{"counterfactual_removal":"Without deterministic rebuild and comparison, a projection can drift or depend on undocumented manual edits without detection.","mechanism_slug":"projection_rebuild_and_diff","role":"Recomputes a view with a pinned projector and compares it with the stored shadow result and selected source snapshots."},{"counterfactual_removal":"Without provenance-weighted reconciliation, vendor reports, contracts, staff observations, and patron reports are liable to be collapsed into one unsupported fact.","mechanism_slug":"provenance_weighted_event_reconciliation","role":"Retains competing assertions and applies an explicit evidence rule while leaving unresolved conflicts visible."}],"nearest_rivals":["A synchronized current-state electronic-resource management record with last-updated timestamps","System-specific audit logs attached to the ERM, discovery index, proxy, or link resolver","A bitemporal holdings table that versions coverage fields but does not make cross-system happenings canonical","Support-ticket workflow histories used to narrate individual access failures"],"negative_tests":{"intervention_falsifier":"For the bounded cases, reject the intervention if two independent replays using the same accepted events, ordering rules, reference data, and projector version produce different access states; or if the projected state cannot distinguish entitlement, discoverability, authentication, and evidentiary uncertainty at the selected decision times without consulting undeclared mutable state.","problem_falsifier":"The inferred problem is not supported if existing authorized records can reproduce, for every sampled case, the effective-time and record-time entitlement, discovery, authentication, and outage state; identify the evidence and correction lineage; and explain discrepancies without manual inference from unrecorded communications.","risks":["Event granularity may expand into unnecessary tracking of staff or patron activity.","Contractual terms and authentication details may leak through projections or provenance links.","Resource identity resolution across title transfers, packages, ISSNs, and platform migrations may merge distinct resources or fragment one continuing resource.","A vendor or staff assertion may be laundered into a confirmed access fact.","Incomplete event capture may make the ledger appear more comprehensive than the evidence warrants.","Late events may revise historical projections in ways that confuse users unless decision-time views are preserved.","Pinned projectors and schema upcasters may encode contestable interpretations as technical defaults.","Replay and retention requirements may preserve sensitive support evidence longer than its declared purpose permits."],"strongest_counterevidence":"A resource's access state may be adequately represented by authoritative current entitlement and configuration measurements plus ordinary audit trails; if those sources already preserve dual-time changes and reconstruct sampled cases, making events canonical adds modeling and governance burden without decision value."},"next_evidence_step":"Select 20 closed electronic-resource access cases from one library, limited to two platforms and a six-month window. Using only records already authorized for the participating staff, encode the minimum events needed for each case, freeze an event-schema version and evidence policy, and independently replay the cases into entitlement, discovery, authentication, and composite access projections at the original report time. Compare the projections with preserved screenshots or source snapshots and the documented case resolution. Record missing event classes, unresolved identity links, duplicate handling, replay determinism, source-access violations, and whether each explanation required undeclared mutable state. Do not connect the prototype to production or evaluate patron outcomes.","observable_state":"For a specified resource, patron population, and historical date, the ERM may show one coverage interval, the discovery layer another link or suppression state, the proxy a later authentication rule, the vendor portal a platform-specific entitlement, and a ticket an outage or transfer narrative. Staff can observe the current values and scattered timestamps but cannot necessarily identify one ordered, evidence-status-aware set of accepted changes that regenerates the patron-facing access state at the ticket's decision time.","prior_art_status":"UNSEARCHED","problem":"When licensed electronic-resource access changes across contracts, packages, title transfers, platforms, discovery records, proxy rules, and vendor incidents, libraries can retain several mutable current-state descriptions of the same resource. In an access dispute or retrospective license review, those descriptions may not show which bounded changes produced the patron-facing state, when each change was effective versus recorded, whether a statement was reported or adjudicated, or how a later correction altered the view. The concrete problem is reconstructing and explaining why a defined patron population could or could not discover and access a specified resource at a specified past time without treating any one mutable subsystem or support narrative as complete history.","proposal_index":1,"remaining_contrastive_claim":"Unlike synchronized current-state records, system-specific audit logs, temporal holdings tables, or ticket histories, the proposed model makes cross-system access-changing events the governed source and requires entitlement, discovery, authentication, composite availability, and decision-time records to be disposable, versioned projections with explicit frontiers and correction lineage. This is a structural distinction to test, not a claim of novelty or superior effect.","revision_record":{"claim_changes":["Initial version; claims are limited to a testable structural fit and do not assert novelty, prevalence, demand, or effect size."],"conceptual_changes":["Initial version centers the event model on historical electronic-resource access determinations spanning entitlement, discovery, authentication, and incident evidence."],"evidence_changes":["No external or prior-art evidence was consulted; the first evidence step is a bounded retrospective shadow reconstruction."],"operational_changes":["Initial version restricts authority to read-only encoding and replay of closed cases, with no production-system mutation."],"parent_version":null,"progress_targets_addressed":["Concrete domain problem and affected objective","Actors and observable state","Event-centered intervention and causal chain","Structural and mechanism mappings with removal counterfactuals","Baseline, nearest rivals, and contrastive claim","Scoped authority, safeguards, halt conditions, and excluded actions","Problem and intervention falsifiers, counterevidence, and risks","Bounded first evidence step"]},"schema_version":1,"structural_mapping":[{"archetype_element":"Bounded event assertion","domain_realization":"A license amendment, coverage change, title transfer, activation, discovery suppression, proxy-rule change, outage assertion, restoration, or correction with a declared transformation and evidentiary status."},{"archetype_element":"Stable event identity and participant-role binding","domain_realization":"A source-scoped event key links the resource, institution, platform, package, vendor, patron population, reporter, and adjudicator in explicit roles while preserving unresolved title or platform identity."},{"archetype_element":"Event time and record time","domain_realization":"Effective coverage or incident time is stored separately from receipt, cataloging, confirmation, correction, and adjudication time."},{"archetype_element":"Canonical governed event log","domain_realization":"The shadow access ledger is authoritative only for experimental projections within the sampled scope; append permission belongs to named electronic-resources staff and validated imports."},{"archetype_element":"Ordering and concurrency semantics","domain_realization":"Contractual effective order, source-local update order, record-time order, and computational tie-break order are declared separately; simultaneous or uncertain changes remain partially ordered."},{"archetype_element":"Correction and supersession lineage","domain_realization":"A mistaken coverage interval, resource match, outage claim, or platform mapping is retracted or superseded through a linked event rather than silently edited."},{"archetype_element":"Versioned projection definitions","domain_realization":"Separate pinned projectors derive entitlement, discovery visibility, authentication applicability, composite access state, case timelines, and what-was-known-at-the-time views."},{"archetype_element":"Projection frontier and completeness statement","domain_realization":"Each view displays the latest processed source record, covered platforms and date range, unresolved assertions, missing sources, and excluded informal communications."},{"archetype_element":"Late-event and replay policy","domain_realization":"A late contract amendment or vendor notice triggers a bounded rebuild of affected resources and preserves the prior decision-time projection."},{"archetype_element":"Reconciliation and retention controls","domain_realization":"Rebuild-and-diff checks compare projections with sampled source snapshots, while field minimization, role-based access, redaction propagation, and pilot deletion rules apply to both events and views."}],"title":"Replayable Electronic-Resource Access Ledger","version":0}