{"actors":["Library privacy and records-governance staff","Integrated library system and discovery-platform administrators","Circulation, authentication, and analytics system owners","Vendor-management staff responsible for hosted library services","Patrons whose identifiable service-use records are retained"],"affected_objective":"Keep patron-linked service records that have exceeded their approved retention period within a governed clearance band while preserving legal holds, active-account needs, audit integrity, accessibility obligations, and authorized research uses.","arm":"ORDINARY_DIVERSE_P2","authority_safety":{"authorized_first_step":"The library privacy officer may conduct a read-only, six-month retrospective reconciliation using existing system inventories, retention rules, record timestamps, deletion logs, anonymization logs, export registers, and vendor reports; this step authorizes no deletion, anonymization, account change, or vendor instruction.","decision_authority":"The library privacy officer owns measurement and may recommend thresholds. The records officer and each affected system owner must jointly approve clearance rules; counsel, institutional review, security, or contract authorities must approve exceptions within their respective jurisdictions.","excluded_actions":["Deleting, anonymizing, or altering records during the retrospective evidence step","Clearing records subject to a legal hold, active investigation, approved research protocol, or mandatory retention duty","Disabling patron accounts or changing service eligibility to lower the measured stock","Treating an undocumented vendor record as cleared","Moving expired identifiable records into unmonitored exports, backups, spreadsheets, or analytics stores","Using aggregate stock thresholds to bypass record-level eligibility verification","Changing approved retention schedules without the designated records authority"],"halt_rollback":"Suspend any later clearance process if eligibility errors, unexplained residuals, legal-hold conflicts, vendor discrepancies, or displacement into another store exceed predeclared tolerances. Disable the clearance job, preserve its manifests and audit logs, restore prior configurations, and restore erroneously cleared records only from an authorized recoverable source when legally permitted; otherwise initiate the applicable incident process before reconsideration."},"baseline":"Compare the proposed frame with existing practice for the same systems: maintaining written retention periods, monitoring current account or transaction activity, and running occasional deletion or anonymization jobs without reconciling the accumulated level of expired identifiable records across production databases, exports, analytics stores, and vendor custody.","candidate_id":"stock_flow_accumulation_control__library_information_science__ORDINARY_DIVERSE_P2","causal_chain":["Circulation, authentication, discovery, messaging, and analytics services create patron-linked records for operational purposes.","When a record reaches its approved retention deadline, it converts from an in-period record into the stock of expired-but-identifiable records unless an authorized exception applies.","Deletion, anonymization, exception review, vendor processing, and backup expiration occur on different schedules and may clear that stock only after delays.","If conversion into expired status exceeds verified clearance, the stock persists across review periods even when current patron activity or new-record creation declines.","A monthly reconciliation separates the accumulated expired-record level from creation, expiration, deletion, anonymization, exception-transfer, restoration, and vendor-clearance flows.","Target and age thresholds can trigger authorized clearance batches, exception review, vendor escalation, or correction of export and backup handling.","Subsequent reconciliation tests whether eligible records leave the bounded stock without being displaced into unmanaged copies or improperly removed from protected exception stocks."],"cell_id":"stock_flow_accumulation_control__library_information_science","consequence":"Expired patron-linked records can remain identifiable across operational and vendor systems, complicate faithful execution of retention policy, enlarge the material implicated by an access incident or records request, and prompt rushed clearance decisions that overlook holds or legitimate exceptions.","diversity_from_prior_proposals":"This opportunity governs the accumulated stock of patron-linked records that have crossed retention deadlines and uses retention conversion, anonymization, deletion, exception transfer, and vendor clearance as its causal paths. It is independent of the sealed P1's preservation-staging capacity problem, collection-content stock, accession flows, and preservation-readiness intervention.","experiment_id":"eoa_inverse_innovation_exp13_second_slot_policy60_20260806","intervention":"For a bounded set of circulation, authentication, discovery, messaging, analytics, export, backup, and hosted-vendor stores, establish a monthly ledger of patron-linked record rows that have passed their approved retention deadline and remain identifiable. Reconcile starting stock plus newly expired records and authorized restorations against verified deletion, irreversible anonymization, and documented transfer into separately governed exception or legal-hold stocks. Investigate residuals by store and custodian. Set an operating band based on the approved clearance cadence and verified processing capacity, with separate maximum-age and residual warnings. After the read-only study and required approvals, use threshold-specific actions such as eligibility-reviewed clearance batches, exception adjudication, vendor escalation, export cleanup, or clearance-capacity adjustment. Retune or retire controls only after the level and turnover remain within the intended band and coupled stores show no displacement.","mechanism_mapping":[{"counterfactual_removal":"Without reconciliation, completed deletion jobs could be reported while the inherited expired-record stock, newly expired records, or undocumented copies remain unaccounted for.","mechanism_slug":"stock_flow_balance_reconciliation","role":"Relates monthly change in expired identifiable record rows to expiration, restoration, deletion, anonymization, exception-transfer, and vendor-clearance flows within a stable boundary."},{"counterfactual_removal":"Without lever adjustment, the ledger would expose accumulation without connecting it to actions capable of changing conversion, clearance, or exception-review rates.","mechanism_slug":"net_flow_lever_adjustment","role":"Links threshold states to approved clearance batches, exception review, vendor escalation, export handling, or processing-capacity changes."},{"counterfactual_removal":"Without level, age, and residual warnings, staff could rely on the existence of a retention schedule or recent purge while older eligible records remain accumulated.","mechanism_slug":"accumulation_threshold_alert","role":"Flags when the expired-record level, oldest eligible record, or unexplained balance exceeds a predeclared operating boundary."},{"counterfactual_removal":"Without probing coupled stores, records copied to analytics exports, vendor environments, backups, or staff files could falsely appear cleared from the governed stock.","mechanism_slug":"hidden_accumulation_probe","role":"Uses residuals and store-level custody checks to detect displacement beyond the primary operational databases."},{"counterfactual_removal":"Without lag-aware control, scheduled vendor deletion, backup expiration, or asynchronous anonymization could be mistaken for failure or success before completion is verifiable.","mechanism_slug":"delay_compensated_control","role":"Registers expected execution and verification delays before thresholds or clearance settings are retuned."}],"nearest_rivals":["A written retention schedule that states deadlines but does not measure or reconcile the stock remaining past them","A periodic purge script that reports rows processed without balancing starting stock, newly expired records, exceptions, failures, and ending stock","A privacy data map that identifies systems and custodians but does not control accumulated expired records over time","Access-control or encryption improvements that protect retained records without determining whether retention-eligible stock is clearing","Database compression or storage cleanup that reduces bytes without verifying deletion or irreversible anonymization of patron identifiers"],"negative_tests":{"intervention_falsifier":"After approved actions and their scheduled verification lags, the intervention is falsified if executed threshold responses do not change the predicted net-flow or stock direction, or if the baseline process produces the same safe decisions without decision-relevant information from the reconciliation.","problem_falsifier":"The proposed problem is absent if no patron-linked records persist beyond their authorized retention or exception periods, or if existing controls already reconcile all bounded stores to expiration and clearance flows with tolerable residuals and use the resulting stock level in authorized decisions.","risks":["Record-row counts may hide differences in sensitivity, duplication, linkage potential, or storage representation.","Incorrect retention metadata may classify active or protected records as eligible for clearance.","Anonymization may be treated as irreversible when remaining attributes or linked datasets permit re-identification.","Vendor reports may omit replicas, exports, subprocessors, or delayed deletion paths.","Aggressive thresholds may compromise legal holds, active services, audit evidence, accessibility, or approved research.","Creating a new inventory or reconciliation extract may itself create another patron-linked copy.","Focusing on easily cleared systems may leave older records concentrated in less observable stores."],"strongest_counterevidence":"Complete cross-system evidence that existing retention operations already identify every expired eligible record, preserve every authorized exception, verify deletion or irreversible anonymization across vendors and coupled stores, and select the same actions without a stock-flow ledger would undermine the claim that this intervention adds decision value."},"next_evidence_step":"Using existing metadata and logs only, reconstruct six consecutive month-end snapshots for a preselected set of systems: starting and ending expired identifiable record rows; records newly crossing retention deadlines; authorized restorations; verified deletions and irreversible anonymizations; transfers into and releases from separately governed exception stocks; oldest eligible-record age; and location or custodian. Predeclare counting, eligibility, and residual tolerances, inspect only the largest residuals, and compare whether stock-level warnings would have changed documented decisions. Conclude with a go/no-go review before any operational clearance is authorized.","observable_state":"A monthly auditable table shows expired identifiable record rows by system and custodian, oldest eligible-record age, target band, newly expired and restored rows, verified deletions, irreversible anonymizations, exception-stock transfers, predicted and observed ending stock, reconciliation residual, vendor and backup verification status, threshold state, authorized response, expected lag, and subsequent trajectory.","prior_art_status":"UNSEARCHED","problem":"A library may maintain patron-record retention schedules and report deletion-job activity without governing the persistent stock of patron-linked records that have already exceeded their approved retention period. Because expiration, anonymization, deletion, exception transfer, restoration, vendor processing, exports, and backup expiration are not reconciled against the accumulated level, expired identifiable records can remain across systems even when current data creation or a recent purge appears manageable.","proposal_index":2,"remaining_contrastive_claim":"The claim left for testing is that a boundary-stable reconciliation of expired identifiable record stock, combined with level, age, and residual thresholds, identifies materially different or earlier authorized retention actions than a written schedule, purge-job reporting, a static data map, or storage management alone.","revision_record":{"claim_changes":["Initial version; the contrastive claim is testable and makes no assertion of novelty, prevalence, demand, or effect size."],"conceptual_changes":["Initial version; defines expired-but-identifiable patron records as a persistent stock distinct from current record creation and deletion activity.","Initial version; models retention-deadline crossing as conversion into the stock and legal holds or approved exceptions as transfers into separately governed coupled stocks."],"evidence_changes":["Initial version; prior art remains unsearched and the first evidence step is a read-only retrospective reconciliation across a bounded system set."],"operational_changes":["Initial version; no deletion, anonymization, account change, or vendor instruction is authorized before reconciliation and multi-owner review."],"parent_version":null,"progress_targets_addressed":["Concrete stock, unit, boundary, owner, sources, and monthly cadence","Explicit expiration, restoration, deletion, anonymization, exception-transfer, vendor, backup, and displacement paths","Target-band, age, capacity, and residual thresholds","Authority limits, protected exceptions, risks, falsifiers, halt conditions, and rollback provisions","Bounded read-only evidence step"]},"schema_version":1,"structural_mapping":[{"archetype_element":"Accumulated stock","domain_realization":"Patron-linked record rows within the selected systems that have passed their approved retention deadline, are not covered by a current authorized exception, and remain identifiable."},{"archetype_element":"Stock boundary, owner, unit, source, and cadence","domain_realization":"The library privacy officer owns a monthly row-count ledger covering designated production databases, analytics stores, exports, backups, and hosted vendors, derived from timestamps, retention rules, inventories, job logs, exception registers, and vendor reports."},{"archetype_element":"Inflow and conversion","domain_realization":"Records enter the stock when they cross their approved retention deadline while still identifiable; authorized restorations or rediscovered copies are recorded as additional inflows."},{"archetype_element":"Outflow and clearance","domain_realization":"Records leave through verified deletion or irreversible anonymization after record-level eligibility checks."},{"archetype_element":"Transfer and exception paths","domain_realization":"Records subject to legal holds, investigations, approved research, or mandatory duties transfer into separately governed exception stocks; releases from those stocks may later convert into the eligible expired-record stock."},{"archetype_element":"Leakage and hidden reservoirs","domain_realization":"Unregistered exports, staff files, replicas, subprocessors, vendor stores, and backups can preserve identifiable records outside the primary system and appear as residuals or coupled hidden stocks."},{"archetype_element":"Net-flow balance","domain_realization":"Ending expired identifiable rows equal starting rows plus newly expired and restored rows minus verified deletions, irreversible anonymizations, and documented exception transfers, plus releases from exception stocks and an explicit residual."},{"archetype_element":"Target band and thresholds","domain_realization":"The operating band permits only the stock consistent with the approved clearance cadence and verified processing capacity, with separate warnings for maximum eligible-record age and unexplained reconciliation residuals."},{"archetype_element":"Control levers","domain_realization":"Authorized levers include eligibility-reviewed clearance batches, exception adjudication, vendor escalation, export cleanup, synchronization of retention metadata, and adjustment of verified clearance capacity or cadence."},{"archetype_element":"Delays and feedback","domain_realization":"Vendor execution, backup expiration, batch scheduling, exception review, and deletion verification delays are recorded before control settings are changed."},{"archetype_element":"Displacement check","domain_realization":"A reported reduction is accepted only when system inventories, export registers, vendor evidence, backup status, and residual analysis show that eligible identifiable records were cleared rather than moved elsewhere."}],"title":"Expired Patron-Record Stock Control Across Library Systems","version":0}