{"actors":["Cataloging and metadata librarians who create and revise authority records","Archivists and special-collections staff who describe creators, correspondents, organizations, and collections","Discovery-system and repository administrators who publish identity clusters, labels, and work attributions","External authority-file and metadata providers that issue identifiers, merges, splits, and replacement records","Researchers, collection users, and represented people or communities affected by attribution and naming decisions","Metadata-governance, privacy, and cultural-protocol officers who control evidence and display rules"],"affected_objective":"Reproduce and explain why a catalog or archival system associated a specified work, record, or collection with a particular person or organization identity and displayed a particular name at a specified past decision time.","arm":"ORDINARY_DIVERSE_P2","authority_safety":{"authorized_first_step":"A designated metadata librarian may construct a read-only shadow ledger from a bounded sample of closed authority-control cases and generate experimental identity and attribution projections; production authority records, discovery indexes, repository descriptions, and external registries remain unchanged.","decision_authority":"The head of metadata services decides whether the shadow reconstruction is operationally interpretable; the responsible collection curator governs archival evidence, the privacy or cultural-protocol officer governs restricted identity information and display labels, and production changes remain subject to the library's existing authority-control process.","excluded_actions":["Do not merge, split, rename, suppress, or redirect any production authority record during the experiment.","Do not infer a person's identity from behavioral, circulation, authentication, or patron data.","Do not convert an unverified correspondence or cataloger inference into an adjudicated identity claim.","Do not expose restricted biographical evidence, former names, pseudonym links, community knowledge, or staff notes beyond their existing access boundaries.","Do not treat identifier continuity as proof that two authority references denote the same entity.","Do not use event order alone to infer intent, responsibility, kinship, or authorship."],"halt_rollback":"Stop if the reconstruction requires newly linking sensitive identities, overriding a cultural naming restriction, or resolving an ambiguous match with consequential guessing. Delete the shadow projections and copied restricted assertions under the pilot retention rule; source descriptions and production authority records remain unchanged."},"baseline":"Catalog and archival systems maintain current authority records, identifier crosswalks, preferred labels, variant names, and links from works or collections. Catalogers may consult change notes and external histories, but successive merges, splits, redirects, imports, and local overrides can leave the earlier identity cluster or displayed attribution difficult to regenerate as it existed at a prior decision time.","candidate_id":"event_log_centered_modeling__library_information_science__ORDINARY_DIVERSE_P2","causal_chain":["New documentary evidence, an external authority update, a local cataloging judgment, or a community request prompts a bounded identity or naming decision.","A person or organization reference is created, linked, merged, split, redirected, relabeled, disputed, or suppressed in one or more mutable authority and description systems.","Current identity clusters and preferred labels propagate to bibliographic, archival, repository, and discovery records, potentially changing attribution and retrieval across many linked descriptions.","Later reviewers can see the resulting records but may be unable to reconstruct which evidence-status-aware decisions produced a past cluster, which links were uncertain, or which downstream descriptions were affected at that time.","The intervention records each identity assertion and authority decision as a canonical event with stable identity, participant roles, dual time, transformation delta, provenance, uncertainty, and correction lineage.","Pinned projectors replay eligible events to derive current and decision-time identity clusters, preferred-label views, attribution memberships, redirect maps, and affected-description lists under declared evidence and access rules.","Late evidence or a correction appends a supersession, retraction, merge, split, or adjudication event and triggers scoped rebuilds without erasing the earlier knowledge state.","Rebuild-and-diff checks expose projection drift, unintended attribution changes, unresolved identity conflicts, and descriptions that cannot be explained from the accepted event history."],"cell_id":"event_log_centered_modeling__library_information_science","consequence":"A library may be unable to explain why works or archival materials were grouped under an identity, determine which descriptions inherited an erroneous merge, reproduce a former catalog display, or distinguish an evidence-backed identity revision from a mechanically propagated external update.","diversity_from_prior_proposals":"This opportunity concerns the evolution and reversibility of creator and organizational identity attributions in authority control. Its problem, intervention, and causal path concern identity assertions, merge-and-split decisions, naming policies, and propagated description memberships rather than electronic-resource entitlement, discovery availability, authentication, or outage reconstruction in P1.","experiment_id":"eoa_inverse_innovation_exp13_second_slot_policy60_20260806","intervention":"Create a governed authority-decision event ledger in which creation of an authority reference, evidence assertion, identifier linkage, preferred-label selection, pseudonym linkage, organizational succession, merge, split, redirect, disputed attribution, suppression, community-requested change, and correction are canonical events. Each event carries a stable event key; persistent but uncertainty-aware references to authority records, works, collections, sources, people, and organizations; explicit roles such as subject, asserted identity, evidence source, cataloger, requester, and adjudicator; effective time and record time; cataloging context; the links or labels added and removed; provenance; validity status; uncertainty; and access restrictions. Idempotent validation quarantines duplicates and malformed events. Corrections are linked retractions, supersessions, merges, splits, or adjudications rather than silent replacement. Versioned projectors derive identity clusters, preferred and historical label views, work and collection attributions, redirect maps, affected-description lists, and decision-time discovery representations while exposing frontiers, excluded evidence, conflicts, and completeness limits.","mechanism_mapping":[{"counterfactual_removal":"Without an append-only event history, a merge, split, relabeling, or suppression can replace the earlier identity configuration and obscure which decision changed linked descriptions.","mechanism_slug":"append_only_event_store","role":"Preserves accepted identity assertions, authority decisions, and linked corrections as the bounded source for experimental projections."},{"counterfactual_removal":"Without event-primary typed relationships, evidence sources, identity candidates, works, collections, catalogers, and adjudicators collapse into undifferentiated record links.","mechanism_slug":"event_knowledge_graph","role":"Represents authority decisions as primary nodes connected to participants, evidence, affected descriptions, and explicit roles."},{"counterfactual_removal":"Without dual time, the reconstruction cannot distinguish when an identity or name was considered applicable from when evidence was received, recorded, propagated, or corrected.","mechanism_slug":"bitemporal_event_register","role":"Supports historical applicability views and reproduction of what the cataloging system knew at a selected record-time frontier."},{"counterfactual_removal":"Without stable identity and idempotent acceptance, repeated authority feeds or replay can apply the same merge, redirect, or attribution change more than once.","mechanism_slug":"event_replay_deduplication","role":"Prevents source repetition and retry from multiplying identity transformations."},{"counterfactual_removal":"Without event-sourced projections, the ledger cannot regenerate governed identity clusters, labels, attributions, redirects, or decision-time displays.","mechanism_slug":"event_sourced_projection","role":"Builds replaceable authority and description views from declared event types, ordering rules, evidence statuses, and access policies."},{"counterfactual_removal":"Without linked compensating corrections, reversing an erroneous identity decision would require silently editing history or leaving the incorrect projection in force.","mechanism_slug":"compensating_event_correction","role":"Appends retraction, supersession, merge, split, or adjudication lineage and preserves the state visible before correction."},{"counterfactual_removal":"Without rebuild and comparison, manually patched or asynchronously propagated identity views can diverge from the accepted decisions without detection.","mechanism_slug":"projection_rebuild_and_diff","role":"Recomputes sampled authority and attribution views with a pinned projector and compares them with preserved system snapshots."},{"counterfactual_removal":"Without provenance-aware reconciliation, external identifiers, cataloger judgments, archival evidence, and community statements may be collapsed into one unsupported identity conclusion.","mechanism_slug":"provenance_weighted_event_reconciliation","role":"Keeps competing identity assertions distinct and projects them according to an explicit evidence and adjudication policy."}],"nearest_rivals":["A current authority record containing preferred and variant names plus textual change notes","A versioned authority table that stores record revisions but not propagated attribution decisions as canonical events","External authority-file change histories and identifier redirects","A provenance graph linking descriptions to sources without replayable merge, split, and decision-time projection semantics"],"negative_tests":{"intervention_falsifier":"Reject the intervention for the sample if independent replay of the same accepted events, ordering rules, reference data, access policy, and projector version yields different identity clusters or attributions; or if a projected cluster cannot explain every included and excluded work reference without consulting undeclared mutable state.","problem_falsifier":"The problem is not supported if existing authorized records can reproduce every sampled authority cluster, preferred label, work or collection attribution, redirect, evidence status, and downstream propagation state at the selected decision times, including reversible merge-and-split lineage, without undocumented inference.","risks":["The ledger could preserve sensitive former names, pseudonym relationships, disputed identities, or biographical evidence beyond their permitted purpose.","Identity resolution could falsely merge distinct people or fragment one continuing person or organization.","A dominant external authority source or cataloging convention could be encoded as neutral adjudication.","Replayed historical labels could expose language or information that current policy restricts.","Incomplete propagation records could make the affected-description projection appear exhaustive when it is not.","Fine-grained staff decision events could become an inappropriate employee-monitoring record.","Projector rules could hide contestable cultural, linguistic, or archival interpretations behind deterministic output.","Late corrections could alter large attribution clusters unless scope and materiality remain visible."],"strongest_counterevidence":"Existing authority systems may already preserve complete reversible revision histories, evidence notes, merge-and-split lineage, and time-stamped propagation logs sufficient to regenerate sampled identity and attribution states; if so, making authority decisions canonical events would add governance and replay complexity without improving the stated reconstruction objective."},"next_evidence_step":"Select 15 closed authority-control cases from one cataloging unit, including bounded examples of a merge, split, preferred-label change, external redirect, disputed attribution, and organizational succession. Using only evidence already authorized for the participating staff, encode the minimum authority-decision events, freeze the schema, identity policy, evidence policy, access rules, and projector version, and independently replay identity clusters, labels, attributions, redirects, and affected-description lists at the original decision-time frontiers. Compare them with preserved authority and discovery snapshots. Record unexplained memberships, missing propagation events, ambiguous identities, duplicate handling, replay differences, restricted-data exposure, and reliance on undeclared mutable state. Do not update production records or contact represented people during this test.","observable_state":"For a selected creator or organization, the current authority file may show one preferred label and identifier cluster while bibliographic, archival, repository, and external records retain different identifiers, attributions, redirects, or former labels. Staff can observe the present links and scattered notes but may not have one evidence-status-aware sequence that regenerates the cluster and every propagated description membership at a prior cataloging decision time.","prior_art_status":"UNSEARCHED","problem":"When libraries revise person and organization identities through authority-record creation, identifier linkage, preferred-name changes, pseudonym decisions, organizational succession, merges, splits, redirects, and corrected attributions, mutable authority and description records primarily expose the latest conclusion. A later cataloger may not be able to reproduce which evidence and decisions formed an earlier identity cluster, determine what was believed when a work was attributed, or identify every description changed by an erroneous merge. The concrete problem is reconstructing and safely revising the decision history behind creator or organizational identity attribution without treating a current authority record, external identifier, or catalog note as complete historical truth.","proposal_index":2,"remaining_contrastive_claim":"Unlike current authority records, record-level version histories, external redirect logs, or static provenance graphs, the proposed model makes bounded identity assertions and authority decisions the governed historical substrate and treats identity clusters, labels, attributions, redirects, affected-record lists, and decision-time displays as disposable versioned projections with explicit evidence rules, frontiers, conflicts, and correction lineage. This is a testable structural distinction, not a novelty or effect claim.","revision_record":{"claim_changes":["Initial version; claims are limited to structural fit and falsifiable reconstruction behavior, with no assertion of novelty, prevalence, demand, or effect size."],"conceptual_changes":["Initial version centers the event model on authority-control identity assertions, merge-and-split decisions, naming changes, and propagated work or collection attributions."],"evidence_changes":["No external or prior-art evidence was consulted; the proposed evidence step is a bounded retrospective shadow replay."],"operational_changes":["Initial version authorizes read-only encoding and projection of closed cases only, with no production authority, description, discovery, or registry mutations."],"parent_version":null,"progress_targets_addressed":["Independent domain problem and affected objective","Actors, observable state, and consequence","Canonical event intervention and distinct causal chain","Structural and mechanism mappings with removal counterfactuals","Baseline, nearest rivals, and remaining contrastive claim","Bounded authority, exclusions, halt conditions, privacy, and cultural safeguards","Problem and intervention falsifiers, strongest counterevidence, and risks","Read-only first evidence step"]},"schema_version":1,"structural_mapping":[{"archetype_element":"Event Boundary and Type Contract","domain_realization":"One event is a bounded identity assertion or authority decision—such as a linkage, label selection, merge, split, redirect, suppression, attribution, dispute, or correction—not merely a saved record snapshot."},{"archetype_element":"Canonical Event Record","domain_realization":"Each authority-decision event records its identity, type, participants and roles, dual time, cataloging context, link or label delta, provenance, status, uncertainty, and access restriction."},{"archetype_element":"Stable event identity and participant-role binding","domain_realization":"Source-scoped event keys connect authority references, identity candidates, works, collections, evidence sources, catalogers, requesters, and adjudicators without assuming that record identifiers prove entity sameness."},{"archetype_element":"Entity identity resolution rule","domain_realization":"The model retains confirmed, candidate, disputed, predecessor, successor, pseudonym, collective, merged, and split relationships with confidence and reversible lineage."},{"archetype_element":"Canonical governed event log","domain_realization":"The shadow ledger is authoritative only for experimental identity and attribution projections within the sampled cases; append authority and validation belong to named metadata staff."},{"archetype_element":"Ordering and concurrency semantics","domain_realization":"Evidence date, asserted applicability time, local decision order, external source sequence, propagation order, and computational tie-breaks are represented separately, with unresolved concurrency preserved."},{"archetype_element":"Correction and supersession lineage","domain_realization":"An erroneous merge, attribution, label, or identifier link is retracted, split, or superseded through a linked event rather than overwritten."},{"archetype_element":"Versioned projection definitions","domain_realization":"Pinned projectors derive identity clusters, preferred and historical labels, work and collection attributions, redirects, affected-description lists, and record-time catalog displays."},{"archetype_element":"Projection frontier and completeness statement","domain_realization":"Each view declares processed sources and dates, propagation coverage, unresolved matches, inaccessible evidence, excluded identity classes, and whether affected descriptions are exhaustively or partially enumerated."},{"archetype_element":"Replay, reconciliation, retention, and access","domain_realization":"Independent replay regenerates sampled views and rebuild-and-diff checks compare them with snapshots, while purpose limits, differential access, redaction propagation, and deletion rules govern both events and projections."}],"title":"Replayable Authority-Identity Decision Ledger","version":0}