4. The 9+1 Method: Connecting AI to the Workflow
4.1. How a Recommendation Becomes a Result the Organization Can Learn from
The method is easiest to understand by following one decision. Suppose an organization is considering a price, a class size, a partner, or a learner-support action. It first records the business object, the responsible role, and the rules that apply. It then creates a snapshot containing only information that was available at that time. A model may study the snapshot, but its answer is still a recommendation. Where human judgment is required, the responsible person approves, rejects, or changes it. The approved action is then carried out, the result is confirmed, and both the action and later outcome are linked back to the original decision. Examination and certification facts continue to come from the authorized body rather than from an operating model.
Four connected cycles result. The service cycle follows the learner and the cohort from program design to later service. The decision cycle moves from information to recommendation, approval, action, confirmation, and outcome. The quality cycle gives complaints, missing information, and service failures a named person and resolution path instead of merely turning a dashboard red. The learning cycle compares what was expected with what happened and asks whether a model should continue. Together they prevent AI from becoming a separate system that nobody fully owns.
A useful decision record is therefore more important than a complicated model. At minimum it records: what decision was made; which program or learner group it concerned; what was known at the time; which rules and data versions were used; what the model suggested and how uncertain it was; who approved any high-risk action; what was sent for execution; what actually happened; when the outcome would be checked; and how any correction, appeal, or return to an earlier version was handled. These fields may live in one database, several existing systems, or a controlled spreadsheet. The method describes the information that must remain connected; it does not require six new software platforms.
There are three common routes. On the normal route, the required information is available and a suitable model may make a recommendation. On the exception route, a missing document, refund, deferral, complaint, appeal, or service problem goes to the responsible role and may return to an earlier business stage. On the fallback route, a model says that it should not be used or that the evidence is too weak, so a rule or person makes the decision instead. A complete loop means that every important event has somewhere to go and every action can be traced back to a decision. It does not mean that every learner receives a credential or every decision is automated.
Figure 1 shows the idea in one view. The P nodes form the proposed service journey. Model labels inside a node mean “may support this decision,” not “must run here.” M10 observes the model set rather than controlling P8 or deciding a learner’s result. The six responsibilities below the journey remain necessary even when no model is used.
4.2. A Ten-Step Guide for Applying the Method
The framework can be applied to another credential program, training service, or similarly governed service in ten steps.
- 1.
Fix the authority boundary. List who owns product rules, learner eligibility, examination, certification, finance, data access, complaints, and model approval. Record what the operating team cannot decide. G0 records this boundary; A0 defines how externally issued results enter the training workflow. Both precede data modeling.
- 2.
Name the business objects. Define product, offering, cohort, learner, order, payment, refund, learning event, assessment event, certificate status, partner, service point, resource, campaign, and action. Give each object an identifier and version rule. Ambiguous nouns such as “traffic,” “conversion,” or “inventory” should be split before analysis begins.
- 3.
Draw the observable event path. For each P1–P9 node, write the event that opens the decision, the party responsible, the possible actions, and the event that closes it. Add correction, cancellation, refund, deferral, re-entry, complaint, appeal, and recovery paths. The result is a process map, not yet an algorithm map.
- 4.
Define results and minimum conditions separately. Choose results at the correct level and time horizon: product adoption, paid registration, learning participation, examination attendance, service quality, contribution, cash, or later response. Then write the authorization, fairness, privacy, capacity, and quality conditions that must be met regardless of profit.
- 5.
Create the event and version record. Capture when an event happened, when the organization learned about it, where it came from, what its definition was, and whether it was later corrected. A result entered later must not be treated as if it had been known at an earlier decision time.
- 6.
Check whether each model is ready to use. Ask whether the decision exists, the desired result can be observed, the required events are mature, and a real action is available. “Do not use this model yet” is a useful answer when it prevents a meaningless calculation.
- 7.
Compare only actions that are allowed and possible. Remove disallowed or undeliverable actions first. Then use the simplest method that can distinguish the remaining choices. Record uncertainty and at least one workable alternative. A score without a possible action and a responsible owner is not a completed decision.
- 8.
Approve and carry out the action. High-risk actions receive case-specific approval; lower-risk actions may follow a previously approved rule. Use the same request identifier when an action is retried so that it is not performed twice. Keep recommendation time, approval time, sending time, and confirmed result separate.
- 9.
Observe the result after a stated period. Link the later result to what was known and what was actually done. If cause and effect cannot be separated, say so directly; a later success is not automatically caused by the model recommendation.
- 10.
Review the model set. Compare decisions made by rules, people, and models. Look for changed conditions, missing execution results, complaints, and evidence that should have arrived but did not. Continue, update, simplify, pause, return to an earlier version, or ask for human review. M10 may help, but the workflow must still function without it.
This sequence does not require a large technology project. An organization can begin with three simple items: a versioned workflow table, a decision record, and a monthly review of unresolved cases. Models are introduced only where a decision repeats, the information is adequate, and there are real alternatives. This order avoids building a sophisticated model first and inventing its business purpose afterward.
4.3. Where Each Model May Help
Table 4 connects the business stages to the models that may support them. A stage may use no model, one model, or several models. A model may also help at more than one stage when it is still answering the same kind of question. Each stage needs a clear closing event; otherwise the organization can make recommendations without knowing whether anything happened.
4.4. Minimum Operating Responsibilities and Controls
The stages become usable only when a role is named for each decision.
Table 5 gives a minimum responsibility map. “Accountable” means the role that owns the final decision; “responsible” means the role that completes the work. A colon divides a stage into responsibility types; it does not create another business stage. The same person may hold several roles in a small organization, but the responsibilities should not disappear. An algorithm is never listed as accountable.
The role map does not replace ordinary operating controls. Before live use, the organization still needs approved marketing claims and channel scripts; contracts, invoices, tax and reconciliation rules; refund and chargeback settlement; instructor qualification and replacement; schedules, make-up classes and platform-failure plans; clear separation between examination coordination and certification authority; complaint deadlines, escalation and remedies; partner exit and learner transfer; privacy, retention, security and incident handling; and links among learning objectives, occupational skills, formative assessment and employer feedback. These are workflow responsibilities, not reasons to invent another algorithm. Scheduling, teacher shifts, and examination-seat allocation remain an explicit decision gap that can first be handled by rules or existing scheduling tools.
The next section keeps three layers separate. The classical method is the established idea on which a model builds. The target model is the fuller method proposed for future development. The current prototype is the smaller algorithm that was actually executed in the synthetic study. A formula may describe the target model even when the prototype implements only part of it; each subsection states this difference explicitly.
4.5. The Ten Decision Models at a Glance
M stands for
decision model. The number identifies a type of decision; it does not tell the organization when the model must run.
Table 6 gives each executable prototype a stable name. These names refer to the smaller prototypes evaluated in this study, not to the more ambitious target models discussed later. The claimed improvements are also separated carefully: some models improve the definition of the problem, some enlarge or narrow the possible actions, and some guarantee a structural property. The paper does not claim that every numerical solver is new.
Table 7 shows the information that a real workflow hand-off needs. It is a design requirement; some of these fields remain to be added before the prototypes can enter live use. Every hand-off should include a version, time period, unit, and uncertainty statement even when these columns are omitted from the compact display.
The current prototypes return less information than
Table 7 requires. M1 returns the selected and blocked attributes plus role-disagreement diagnostics. M2 returns a price only when one of the tested prices is feasible. M3 returns coefficients and then a forecast path. M4 returns either a transition-probability table or a separate
REVIEW_REQUIRED signal, and M5 the partner subset. M6 returns the site subset, total cost, and temporary share, but not a complete regional-capacity object. M7 returns three plan values; shortage, overflow, and aging measures are calculated separately in the synthetic mechanism checks. M8 returns the chosen action and two profit summaries but not an explanation for every excluded action. M9 returns recommended contexts plus a reason for every context without a recommendation. M10 returns a model-set review proposal and diagnostics, not a record of the model version actually in use. The richer hand-offs in
Table 7 are therefore work still required before live integration.
The propositions below state checkable design properties of the implemented prototypes. Most follow from filtering, ordering, bounded updates, or finite enumeration. They show that the algorithms respect the rules they claim to implement; they are not presented as new foundational theorems or as proofs of real-world benefit.
4.5.1. M1 — Choosing Product Attributes with RMGS
When to use it.
The first model, the Rule-filtered Multi-role Greedy Selector (RMGS), helps when a program team must choose among optional product attributes under a budget. It should not run when there is no real design choice, when attributes have no stable meaning, or when the relevant roles cannot be identified.
Prototype theory and mechanism.
Kano analysis classifies attributes from responses to their presence and absence and can support prioritization [
8]; it does not by itself solve a budgeted choice involving several roles and disallowed attributes. RMGS is a downstream selection layer. It removes attributes that are not permitted or deliverable, combines the overall view with the least favorable role, displays disagreement, and then applies a value-per-cost greedy rule. Earlier work on quantifying qualitative design judgments and on sign orientation illustrates why inputs must be measurable and point in a common direction [
37,
38]; it does not validate the RMGS weights or its use in vocational training.
Input, calculation, and output.
For attribute
i and role
r, let
be a finite score on a common scale oriented so that larger is always better,
the role weight,
the cost,
an indicator that the attribute is allowed, and
B the budget. RMGS computes
Here says how strongly disagreement is penalized, and is the unweighted population standard deviation across roles; the role weights enter only the first term. The synthetic example uses and role weights . The coefficients 0.45 and 0.55 deliberately give slightly more weight to the least satisfied role than to the weighted mean. They are example design choices for sensitivity testing, not universal vocational-training constants. RMGS then places positive-value zero-cost attributes first, sorts the remaining allowed attributes by , and adds an attribute only when it still fits the budget. The output lists the selected attributes, the attributes removed by current rules, and the role disagreement. A responsible role must approve the selection before it becomes the product version used by the price and demand models.
Procedure.
(1) Fix the product version and attribute meanings. (2) confirm the roles and their weights. (3) mark attributes that the organization is allowed and able to deliver. (4) calculate the weighted, least-role, and disagreement terms in Equation (
4). (5) rank the remaining attributes by value per unit of cost. (6) add them while budget remains. (7) show which role or rule caused an exclusion. (8) record the approved product version for later decisions.
Innovation and boundary.
Kano classifies needs; RMGS turns those assessments into a constrained choice. The innovation is the combination of rule filtering, least-role protection, disagreement reporting, and budgeted selection—not a new Kano theory. The current prototype does not estimate Kano probabilities, model complementarity or substitution among attributes, or guarantee global optimality over all subsets.
Proposition 1 (rule and budget consistency).
Suppose the attribute set is finite, , costs are finite and non-negative, scores are finite and on the common scale just defined, and role weights are non-negative and sum to one. RMGS treats a positive-value zero-cost attribute as having first priority; positive-cost attributes are ordered by . Every returned attribute has , and total selected cost is at most B. Proof. The algorithm scans a finite sorted list. It skips every item with and adds an item only after checking that the new total does not exceed B. Both statements are invariants of every addition and therefore hold when the scan ends. This proves feasibility, not global optimality.
Evidence boundary.
In the synthetic study, regret fell in nine of ten seeds. The comparator did not use the same rule check or least-role term, so the result shows how this selection rule behaves; it does not prove that RMGS estimates real satisfaction more accurately.
4.5.2. M2 — Choosing a Workable Price with PSPS
When to use it.
The second model, the PSM-bounded Scenario Price Selector (PSPS), is used only when the organization has genuine pricing discretion, a product version has been fixed, and it can state plausible demand, refund, cost, and capacity scenarios. If the price is externally fixed or the perceived price range is missing, the model should not present an “optimal” price.
Prototype theory and mechanism.
The Van Westendorp price sensitivity meter (PSM) derives perceived price points or intervals from four price judgments; it is not a causal demand curve and does not identify the most profitable price [
9]. PSPS therefore follows “bound, screen, rank”: PSM bounds the candidate grid, price-indexed demand and refund scenarios screen it for capacity and group-difference limits, and only the surviving prices are ranked by average and poor-case profit.
Input, calculation, and output.
The prototype receives a price grid, interval
, demand
and refund share
for group
g, scenario
, and price
, group market size
, unit cost
c, capacity
C, and two permitted-difference limits. It defines
where
is the arithmetic mean of the lowest
scenario profits. The prototype keeps each group market size
fixed across scenarios;
also keeps the illustrative rate defined if a supplied size is zero. Here
controls how much poor-case profit matters beside mean profit; the synthetic illustration uses
. A candidate is retained only when
,
, and
. These are researcher-chosen illustration values.
is only a group-difference signal, not a complete definition of fairness or access. PSPS returns the retained price with the largest
, together with its poor-case profit and number of feasible prices. If the candidate list is empty, it returns no price. A returned price goes to approval and then to demand, resource, and cohort-planning models with an expiry date.
Procedure.
(1) Confirm that the organization may set the price. (2) establish the perceived interval and its sampling limits. (3) define candidate prices. (4) calculate net registrations after refunds in each scenario. (5) remove prices outside the interval or beyond capacity and group-difference limits. (6) calculate Equation (
5). (7) compare sensitivity to demand, refunds, capacity, and
. (8) return the price or explain that no tested price is feasible.
Innovation and boundary.
Traditional PSM ends with a perceived range; PSPS converts that range into a conditional operating choice without pretending it is a demand curve. Capacity and group differences define the feasible set before profit is compared, and an empty set produces no price rather than a forced answer. The current prototype receives a precomputed PSM interval, chooses one common price, and uses the same 160 scenarios for selection and scoring. It does not estimate the four PSM curves, identify price elasticity, model multi-period cash, or guarantee fair access.
Proposition 2 (finite-grid feasibility).
Whenever PSPS returns
RUN, its price lies in
and satisfies the two implemented limits; among tested prices that satisfy those checks, it maximizes Equation (
5).
Proof. Only prices passing all three checks are appended to the finite candidate list. The algorithm returns the list element with maximum
. This proves optimality only on the stated grid and scenarios, not for every possible price or future demand.
Evidence boundary.
In the synthetic scenarios, capacity violations disappeared and the group gap fell, while mean synthetic profit fell sharply. This is an explicit trade-off inside the same scenarios, not out-of-sample evidence that the selected price will work in practice.
4.5.3. M3 — Forecasting a Named Demand path with SBRF
When to use it.
The third model, the Shock-augmented Bass Ridge Forecaster (SBRF), is for a new or growing offer when a clearly named cumulative event must be forecast. “Interest,” “paid registration,” “learning start,” “examination attendance,” and “certification” are different events. The model should not run on an unnamed “user growth” series or on a mature offer with no meaningful diffusion process.
Prototype theory and mechanism.
The Bass model describes adoption through an innovation term
p and an imitation term
q [
10,
11]. SBRF adds one recorded shock
, such as a campaign launch, and estimates the coefficients by ridge regression. Imitation can accelerate adoption, while the remaining market
creates saturation. The shock separates a known intervention from endogenous diffusion, ridge regularization limits unstable coefficients, and clipping prevents negative growth or growth beyond the stated ceiling. With
,
, and cumulative count
, the period-
t update is
For fitting, the prototype sets
and
. The denominator floor of one avoids division by zero after the path reaches
m. Before fitting, cumulative observations must be finite, non-decreasing, measured from the same process origin, and no greater than the stated ceiling. Before clipping
p and
q to be non-negative, the ridge estimate is
Here I is the identity matrix and is the ridge penalty; the synthetic example uses . The fuller target model may allow , , and to change over time, but that extension was not executed here.
Input and output.
Inputs are the named event, a versioned cumulative training series, the market ceiling, observed shock values, a ridge parameter, and a later evaluation period. The current prototype accepts only interest and paid; learning start, examination attendance, and certification are examples for later endpoint-specific models, not currently supported endpoints. It returns p, q, and , followed by a bounded cumulative forecast path. The path can become a demand scenario for resource and economic planning; it is not itself a staffing order.
Procedure.
(1) Name the event and time unit. (2) reconcile corrections and learner groups. (3) check that diffusion is a sensible description. (4) hold later periods back from fitting. (5) compute the unconstrained ridge estimate with the recorded shock. (6) clip negative estimates of
p and
q to zero. (7) generate the path with Equation (
8). (8) compare it with the held-back period and pass scenarios forward.
Innovation and boundary.
The contribution is not a new Bass theory. It is the disciplined combination of a named vocational-training event, a recorded shock, regularized estimation, and a market-bounded path. This prevents different events from being mixed, known activity from being hidden inside unexplained growth, and an unbounded forecast from becoming a staffing instruction. The shock coefficient is a conditional association, not a causal campaign or policy effect. The current prototype fixes , uses constant p and q, and fits 18 periods before a 10-period holdout.
Proposition 3 (bounded path and unique ridge estimate).
If
and
, every SBRF forecast satisfies
and
. If
, the unconstrained ridge estimate is unique.
Proof. Equation (
8) clips each increment between zero and
, so induction gives monotonicity and the upper bound. For any nonzero vector
a,
; the matrix is positive definite and invertible. Clipping
p and
q afterward is deterministic, but it is not the solution of a non-negatively constrained ridge problem.
Evidence boundary.
Path error improved in only five of ten synthetic seeds. SBRF is therefore a clearer planning structure, not a demonstrated forecasting winner.
4.5.4. M4 — Describing the Learner Journey with EJTT
When to use it.
The fourth model, the Eligibility-conditioned Journey Transition Table (EJTT), is used when the organization needs to estimate movement among clearly defined states such as registered, paid, learning, inactive, examined, withdrawn, or refunded. Eligibility remains a separate condition rather than a credential decision made by the state model. EJTT requires dated events and stable, mutually exclusive state definitions. It does not decide whether a learner passed or received a credential; those facts are issued by the authorized body and enter the operating workflow through A0.
Prototype theory and mechanism.
A funnel compares totals at several points. A multi-state model instead asks which move happened, when it happened, and which other moves were possible [
12]. Process-mining research adds the idea that an event should retain its origin and should follow a stated process [
13]. The fuller target model uses a continuous-time transition generator
. Prohibited moves have
, and
. With arrivals
, expected state totals follow
The row vector contains the expected number of learners in each named state at time t. The matrix contains transition rates: is the rate from state g to state , and the diagonal term balances each row. The vector records new arrivals from outside the current state system. These quantities belong to the future target model; the current prototype estimates one-step probabilities rather than continuous-time rates.
Current prototype, input, and output.
Let
count records with current state
g, synthetic age band
a, eligibility
e, and next state
h; let
contain permitted next states. With
, EJTT estimates
The permitted set is supplied as an input before any count is smoothed. Every permitted state receives the same pseudocount, including a state not observed in that particular group, while a prohibited state receives none. The three synthetic age bands only demonstrate conditioning; they do not establish that age is necessary or appropriate in real learner decisions. For an unseen band, the prototype borrows only from the same state and eligibility. If none exists, an ordinary state is held. A conflict involving PAID, EXAM, or an externally issued CERTIFIED result returns REVIEW_REQUIRED; the training-operations model does not cancel or rewrite the authoritative fact. The output is a probability table or a review signal, not an examination or certification decision.
Procedure.
(1) Agree the state names and final states. (2) preserve both event time and the later time at which the organization learned the event. (3) identify duplicates and impossible orders. (4) group the training transitions by state, age band, and eligibility. (5) define the permitted next states for every state–eligibility pair. (6) add the same pseudocount to every permitted state, but not to a prohibited state. (7) divide by the permitted total and test the table on later records. (8) pass workload and case information forward with its state version.
Innovation and boundary.
EJTT does not merely add vocational-training stages to a funnel. It replaces the one-way funnel with an eligibility-conditioned multi-state journey: a learner may enter, remain, withdraw, receive a refund, or return, while the permitted state set is established before probabilities are formed. Authoritative results still come from the authorized body and enter the training workflow through A0. The current prototype receives this rule table as an input; it does not yet read a versioned rule from G0 or estimate hazards, censoring, competing risks, complete return paths, or full process conformance.
Proposition 4 (valid allowed-state probabilities).
For every EJTT group that enters the ordinary probability calculation with a non-empty permitted set, the returned probabilities are non-negative, sum to one, and give no probability to a prohibited forward state.
Proof. Each permitted state receives a non-negative count plus the positive pseudocount
, so the denominator in Equation (
11) is positive. Division preserves non-negativity and makes the permitted probabilities sum to one; states outside the set are zero by definition. An average of same-eligibility probability vectors also sums to one. With no matching evidence, an ordinary state may remain unchanged. A conflict involving
PAID,
EXAM, or
CERTIFIED instead returns the separate
REVIEW_REQUIRED signal, which is outside the probability distribution. This proves probability consistency for the ordinary table, not calibration or the validity of any authoritative result.
Evidence boundary.
On held-back synthetic records, EJTT removed all prohibited transition probability. On the shared set of records for which EJTT returned an ordinary probability distribution, state accuracy rose from 0.4975 to 0.5644, while negative log-likelihood changed from 1.1171 to 1.1375 and paid-state count error from 8.01 to 11.85. EJTT sent another 6.54% of records to the separate review path; those records were excluded from both methods’ three conditional measures. The exercise therefore shows the intended rule and review behavior, not better probability calibration or real-world predictive superiority.
4.5.5. M5 — Choosing a Partner Combination with QPPE
When to use it.
The fifth model, the Qualified Partner Portfolio Enumerator (QPPE), is for a genuine choice among optional venue, technology, content, delivery, or support partners. A body required by regulation or contract is not a candidate to be ranked. The model should also stop when qualification documents are missing or expired.
Prototype theory and mechanism.
The original operating brief began with the Analytic Hierarchy Process (AHP). AHP can structure criteria and weights [
14,
15], but its weighted ranking is compensatory: a high commercial score can hide failed qualification. QPPE changes the order of the decision. It defines who may be compared, removes combinations that cannot deliver the required capacity, and then stress-tests portfolios rather than ranking one partner at a time. With eligibility
, selection
, criterion weights
, and scenario score
, the fuller target form is
Here says whether candidate v is selected, says whether that candidate may be considered, is its score on criterion l in scenario , and is the criterion weight. The quantities and B are partner cost and total budget. Budget and concentration appear only in this future target form, not in the executable prototype.
Current prototype, input, and output.
QPPE receives candidate identity, a current qualification flag, a fixed-actor flag, capacity, cost, a maximum of three partners, minimum required capacity, and 100 synthetic utility scenarios. It considers only candidates satisfying
qualified AND not fixed. The binary flag cannot distinguish confirmed failure from missing or expired evidence, so an upstream check must resolve that uncertainty before this prototype runs. For a subset
S, its implemented score is
In the prototype, is the synthetic utility of partner v in scenario , is its cost score, and is an illustrative cost weight. It returns the highest-scoring capacity-feasible subset, or explains that capacity cannot be met. A responsible owner must then approve the partner set and complete any agreement before confirmed capability is passed to location, resource, and cohort-planning decisions.
Procedure.
(1) Separate required bodies, internal units, and genuine candidates. (2) verify current qualification. (3) exclude fixed and unqualified actors before scoring. (4) build synthetic or estimated utility scenarios. (5) enumerate subsets from one partner to the stated size limit. (6) remove subsets below required capacity. (7) calculate Equation (
13) and choose the maximum. (8) send the result to human approval, contracting, and later quality review.
Innovation and boundary.
QPPE makes three structural changes to AHP-style ranking: qualification precedes preference, a portfolio replaces one winner, and capacity plus worst-scenario utility replace average score alone. Qualification filtering defines the permitted action set; finite enumeration then examines every capacity-feasible combination within the size limit. The prototype does not perform AHP pairwise comparisons or adaptive weighting. Budget, concentration, and explicit backup constraints remain target-model features.
Proposition 5 (qualified finite-set optimum).
Every partner returned by QPPE is qualified and not a fixed actor. Among all enumerated subsets within the size limit that meet capacity, the returned subset maximizes Equation (
13).
Proof. The enumeration indices are constructed only from qualified, non-fixed candidates. Every subset below capacity is skipped, and every remaining subset is evaluated once before the largest score is returned. The result is optimal only for this finite search and implemented score.
Evidence boundary.
The synthetic candidate removed all unqualified selections and improved worst-scenario utility. Because the two compared methods used different action sets and the same scenarios for choice and scoring, the experiment supports the qualification-first structure, not general superiority.
4.5.6. M6 — Planning Service Coverage with ZHCE
When to use it.
The sixth model, the Zero-site Hybrid Coverage Enumerator (ZHCE), is used when regional demand can be served by some combination of online support, permanent service points, and temporary capacity. It is not needed for a fully digital offer with no location decision, and a location plan cannot be inferred from web traffic or IP addresses alone.
Prototype theory and mechanism.
The original brief used a centre-of-gravity idea. That method can suggest where one point belongs from demand and distance weights, but it cannot naturally represent no permanent point, several capacity-limited candidates, online substitution, and temporary service. ZHCE therefore reformulates the decision as a small hybrid coverage and facility-location problem [
16]. Prior layout work supports only the general need to encode spatial functions and constraints, not the vocational-service claims made here [
39]. A simplified target objective is
subject to coverage, permanent-point capacity, travel distance, required on-site work, and the condition that a closed point receives no assignment. Online and temporary service also need quality and availability limits. Here
is one when permanent point
h is opened,
is demand from region
r assigned to point
h in scenario
, and
is temporary service. The terms
,
, and
are fixed, assignment, and temporary-service costs, while
is the scenario weight. The current prototype is deterministic, so it has no
or
and uses a fixed greedy assignment order.
Current prototype, input, and output.
ZHCE receives regional demand, the share that must be served in person, distances, permanent-point capacity and fixed cost, travel cost, temporary unit cost, a soft reference gap
for regional temporary-service rates, and a non-negative penalty coefficient
. Demand must be finite and non-negative with a positive total; each in-person share must lie in
; distances, capacities, costs,
, and
must be finite and non-negative. Invalid input returns
UNIDENTIFIABLE. The prototype fixes the online share, enumerates zero, one, or two permanent points, and assigns required in-person demand to the nearest open point with remaining capacity. Anything left is sent to temporary service. For each subset, it calculates
where
; zero-demand regions do not enter the rate difference. The prototype minimizes
J. Because
is a soft reference rather than a hard limit, a sufficiently cheaper plan may exceed it. The output is the permanent-point set, raw total cost, temporary-service share, and regional gap; the penalized objective can be reconstructed from the disclosed inputs.
Procedure.
(1) Define the service task and unit. (2) estimate regional demand from defensible location information. (3) state what must occur in person. (4) verify candidate points, distance, capacity, and costs. (5) enumerate zero-, one-, and two-point choices. (6) allocate demand by distance and remaining capacity. (7) send the remainder to temporary service under the stated assumption. (8) For every subset, calculate raw cost, temporary-service share, regional gap G, and full objective J; return the smallest J and report any excess over .
Innovation and boundary.
ZHCE changes “where should one point be” into “whether to open, where to open, and how to cover.” It includes the empty set, separates online from mandatory in-person work, uses temporary service as recourse, and exposes unequal regional dependence on that recourse. The gap is an access signal, not a fairness guarantee. The current prototype still assumes unlimited temporary capacity at unit cost 52 and omits temporary quality, maximum travel, and unmet-demand cost.
Proposition 6 (complete comparison within the prototype’s search).
Suppose demand is finite and non-negative with positive total, in-person shares lie in , and distances, capacities, costs, , and are finite and non-negative. Then is non-empty. ZHCE returns the lowest implemented penalized objective among every permanent-point subset up to its stated limit, including the empty set, when each subset is evaluated by the fixed demand-ordering rule. Under unlimited temporary service, all demand is assigned. Proof. Positive total demand makes at least one region enter . The algorithm enumerates every permitted subset and evaluates raw cost, the regional gap, and the penalty once. Permanent points serve demand in the fixed order; the non-negative remainder goes to temporary service. A different assignment order may change the value, so this is not joint location–allocation optimality.
Evidence boundary.
In the synthetic instance, ZHCE opened no permanent point and lowered raw cost, but the mean regional temporary-service gap worsened from 0.1276 to 0.2300 and exceeded the soft reference value 0.18. This negative access trade-off is as important as the cost reduction. The result shows why the zero-point option and the gap should both be tested; it does not show that a real organization should close or avoid permanent service points.
4.5.7. M7 — Planning Three Different Resource Types with TQRP
When to use it.
The seventh model, the Three-class Quantile Resource Planner (TQRP), is used when a program must plan physical items, service hours, and digital content. These resources behave differently: printed materials can be stored, teacher or support hours disappear when a period ends, and digital content can be copied cheaply but becomes outdated.
Prototype theory and mechanism.
Economic order quantity (EOQ) and safety-stock reasoning concern storable physical items [
17]; yield management concerns time-limited service capacity [
19]. Neither applies unchanged to digital content. TQRP therefore separates three mechanisms:
Costs may be combined only after each quantity keeps its own unit. A printed copy, an instructor-hour, and a content version are never added as raw quantities.
For physical requirements and service load, the quantile rule follows the classic newsvendor critical-fractile logic under asymmetric loss [
40]. If
,
, and these denote under-capacity and unused-capacity costs, then
A larger shortage cost therefore implies a higher planning quantile. For digital content, the prototype uses only as a response heuristic: a larger aging-exposure score gives a shorter interval. The score is not assumed to be a calibrated failure probability, and the interval is not cost-optimal.
Current prototype, input, and output.
TQRP receives synthetic observations for physical demand
, service load
, and a non-negative digital-aging exposure score
h. Its one-period plan is
Here is the mean exposure score in the synthetic planning records. The floor only prevents division by zero; the range of one to twelve periods and the 0.90 and 0.95 quantiles are illustrative policies. In the mechanism check, is reported as accumulated aging exposure, not as the probability that content becomes outdated. is not an EOQ or a live order quantity: it is a one-period physical-requirement target that would later be adjusted for stock on hand, outstanding orders, and lead time. The outputs keep that target, service capacity, and digital update interval separate.
Procedure.
(1) Translate demand into named units and periods. (2) classify each resource. (3) separate mixed bundles. (4) calculate the physical 90th percentile. (5) calculate the service 95th percentile. (6) calculate the digital update interval from average aging exposure. (7) report shortage, overflow, and accumulated aging exposure separately. (8) pass the three results forward without merging their units.
Innovation and boundary.
TQRP replaces one misleading “inventory” formula with three resource-specific mechanisms: physical items can carry over, service time expires, and versioned digital content ages without being consumed. It is a one-period quantile planner, not the multi-period optimization in Equation (
16); it does not jointly optimize orders, shifts, outsourcing, lead times, refresh cost, or corrective action.
Proposition 7 (separation and monotone response).
If active inputs are non-empty, finite, and non-negative, all plan values are non-negative and unlike units are never added. If a demand distribution shifts right in first-order stochastic dominance, its fixed quantile cannot fall; away from the clipping breakpoints, increasing cannot lengthen . Proof. Quantiles preserve first-order stochastic order. The map is decreasing, ceiling and clipping preserve the weak direction, and all three calculations use separate fields. This proves a directionally coherent response, not minimum total cost.
Evidence boundary.
In the later synthetic records, total cost, service overflow, and accumulated aging exposure fell, but physical shortage rose from zero to 0.697. The model reveals a trade-off; total cost alone cannot decide whether that trade-off is acceptable.
4.5.8. M8 — Choosing a Cohort Plan with FTPS
When to use it.
The eighth model, the Feasibility-first Tail-profit Selector (FTPS), compares a small set of cohort-level plans, such as class size, campaign intensity, staffing package, or service arrangement. It requires a defined learner group, a fixed planning period, candidate actions, profit scenarios, and observable minimum conditions. If refund timing, settlement rules, or major cost drivers cannot be described, the fuller economic model cannot be identified.
Prototype theory and mechanism.
Activity-based costing separates the activities that create operating cost [
18]; conditional value-at-risk (CVaR) summarizes the poor tail [
21]; robust optimization makes protection against uncertainty visible [
20]. FTPS uses a lexicographic mechanism: encoded authorization, capacity, access, and quality conditions define the feasible set; poor-tail profit ranks that set first; mean profit only breaks a tie. Cash is a target-model condition, not one of the three implemented binary checks.
Current prototype, input, and output.
The prototype receives six actions, 180 already-computed profit scenarios
, three binary minimum-condition indicators, and a quality scenario for each action. In a live model, profit would separate revenue, refunds, teaching, support, content, authorization, compliance, and platform costs; the current prototype does not validate that accounting model. It forms
In the synthetic example, the three indicators stand for authorization, capacity, and access; is quality. For loss , the mean of the lowest 20% of profit is the return-side empirical tail measure . The 0.72 threshold and tail fraction are example values, not standards. Strict lexicographic order means even a small tail-profit advantage outranks any mean-profit difference; this is a strong management preference for protecting the poor case.
Procedure.
(1) Fix the cohort and time period. (2) list the candidate actions. (3) create joint profit, quality, and minimum-condition scenarios. (4) remove every action that fails any encoded condition. (5) calculate the mean of the lowest 20% profits. (6) compare those values, then means. (7) in a live implementation, explain which condition removed each action and how much average profit was given up; the current prototype does not yet return that full explanation. (8) send the chosen cohort plan for approval and later compare it with realized cash and quality.
Innovation and boundary.
A cost–sales fit asks which plan is profitable; FTPS asks first which plans are admissible and survivable. Its innovation is the non-compensatory order of minimum conditions, tail profit, and mean profit: high profit cannot buy its way past a failed condition. The current prototype does not generate activity costs, model refund timing, or calculate liquidity, and it uses the same scenarios for choice and scoring.
Proposition 8 (non-compensatory feasibility).
An action outside can never be returned, regardless of profit. If is non-empty, the returned action has tail profit no lower than any other feasible action and, among equal-tail actions, the highest mean profit. Proof. Filtering occurs before any profit ordering. The finite feasible set is then ordered lexicographically by . If it is empty, no automated action is returned.
Evidence boundary.
The synthetic study removed all encoded violations and improved poor-case profit, but average profit fell. The prespecified primary result strictly improved in only two seeds and was no worse in all ten; these are not ten strict wins.
4.5.9. M9 — Choosing the Next Permitted Action with SEAS
When to use it.
The ninth model, the Stable Eligible Action Selector (SEAS), is used when the organization has a real choice among learner- or cohort-facing actions after an observed event. The decision time, outcome window, allowed actions, consent, purpose, contact history, and delivery capacity must be stated. If there is no intervention choice or no evidence for alternatives, the model makes no recommendation.
Prototype theory and mechanism.
SEAS is not an improved RFM formula. Association rules describe co-occurrence [
22], RFM summarizes past activity [
25], and dynamic RFM with discrete-interval hazards can turn that history into a time-indexed repurchase-probability estimate [
26]. Work on employee-turnover warning in finance and taxation education likewise uses prediction to support attention to talent retention [
41]. Its target is employees rather than learners, and neither a turnover warning nor a repurchase probability identifies the effect of a next action. SEAS therefore reframes the problem as a decision with an explicit action set and outcome window. Its mechanism is “allowed, supported, stable, valuable”: filter by permission, sample support, and a rough early–late drift check, then compare historical net value. Causal policy evaluation would require action propensities or another defensible design [
23].
Current prototype, input, and output.
For context
x and allowed action
a, let
be eligible historical records,
their mean synthetic outcome,
the value of one outcome in the same utility unit as cost
, and
Let be the value of taking no action in context x. An action is considered only when , , both periods are observed, , and . In the synthetic prototype , , and is a success-equivalent utility deduction, not money. The thresholds are illustrative, and the early–late difference is only a crude drift screen; it cannot remove confounding or action-selection bias. Examination-facing actions mean reminders or support within the operator’s authority, never eligibility rulings, examination administration, or certification decisions.
Procedure.
(1) Name the decision, context, and outcome window. (2) construct the allowed action list before looking at outcomes. (3) retain only eligible records known at the decision time. (4) require at least 35 records. (5) require observations in both early and late periods. (6) calculate instability and remove actions above 0.11. (7) compare outcome value minus cost in one unit and remove any action that does not beat no action. (8) select the remaining action with the largest value, or record no recommendation.
Innovation and boundary.
Association rules and RFM answer whom to notice; SEAS asks what may be done next. Its innovation is the combination of an allowed set, support, temporal stability, comparable net value, and explicit abstention. The prototype receives rather than deriving it from authority, consent, eligibility, contact-frequency, and capacity rules. It does not estimate causal uplift or perform off-policy evaluation.
Proposition 9 (context-level permission and abstention).
For each context, every returned action belongs to , meets the support, period-coverage, and stability conditions, and has estimated net value above . If no action passes, that context remains without a recommendation even when another context makes the overall run status positive. Proof. Candidates are built separately by context from allowed actions that pass every stated check, including ; selection occurs only inside that list. An empty list has no returned action. This proves filtering behavior, not causal benefit.
Evidence boundary.
The revised comparison gives SEAS and the comparator the same context-level permission rules and the same person-level eligibility check. Both therefore have a zero disallowed-action rate. The comparator chooses the permitted action with the highest eligible historical mean in each context; it does not use the support, stability, or cost checks. SEAS acts less often (0.7021 versus 0.8007) and has lower mean synthetic gain (0.2122 versus 0.2463). This is a cost of abstaining under the stated thresholds, not evidence that SEAS improves outcomes. RFM, a fixed-contact policy, and a causal policy method remain useful future comparisons.
4.5.10. M10 — Reviewing whether the model set should continue
When to use it.
The tenth model looks at the other models rather than at an individual learner or program action. It is called the Evidence- and Reversibility-aware Model Review (ERMR), or simply the model-set review model. It asks whether the current combination of models, rules, information passed between decisions, and alternative methods should continue. “Missing evidence” means results, action confirmations, or reviews that should already exist but do not. M10 is optional, and the business workflow must remain usable without it.
Underlying idea.
The model may propose
KEEP,
RECALIBRATE,
DEGRADE,
FREEZE,
ROLLBACK, or
HUMAN_REVIEW. These mean, respectively: continue; update parameters; use a simpler method or narrower action range; pause new automated actions; return to a named stable version; or ask a responsible person to review the situation. M10 can only propose a response; it cannot change the model set by itself. Classical change detection and model predictive control remain important comparison points [
42,
43]. Published work on enterprise financial-risk warnings is an example of an object-level warning intended to focus managerial attention [
44]. It is a contrast, not a theoretical source or validation for ERMR, and it does not answer M10’s different question of whether an entire model set should continue.
Input and output.
Inputs include the model-set version, current rules, model-level risk, changed data, service loss, human changes, a synthetic signal representing missing confirmations, the share of results mature enough to judge, unresolved cases, the previous response, a waiting period between changes, and a compatible stable version. In each synthetic period, 24 rows contain five scores between zero and one: risk, data change, performance loss, human-change frequency, and confirmation gap. Outputs include one of the six responses, the affected models, a missing-evidence score, predicted worst risk, service loss, and a status showing whether a human decision is still required. A separate list records actual human approval and execution confirmation. A proposal without the required confirmation does not become the effective review action, and its missing confirmation increases the evidence-debt input in the next period. M10 never makes an examination, certification, or learner-level next-action decision.
Calculation.
Let
contain the responses allowed by the current rules, waiting period, result maturity, and availability of a stable version. For each response
a, the prototype calculates an unsafe indicator
, a combined burden
containing service loss, changed-data exposure, switching, severity jump, and reversibility, and predicted worst risk
. It chooses by priority rather than by turning safety into money:
The function lexargmin means “compare the first value; use the second only to break a tie; then use the third.” The first value
is one when the predicted worst risk exceeds the synthetic-example limit 0.45; it is also one for
KEEP when the missing-evidence score exceeds 1.20. The third value
is the largest predicted post-response risk among the 24 synthetic rows. The middle value is
where
is predicted service loss,
is mean data-change signal,
is the response’s risk multiplier,
records a change from the previous response,
measures an abrupt severity increase,
is a waiting-period cost, and
is the encoded reversibility score. Every coefficient and threshold in this equation is a researcher-chosen simulation setting, not a validated operating standard. The ordered comparison means that a lower service cost cannot compensate for a response predicted to be unsafe.
Procedure.
(1) Confirm that a named model-set version exists. (2) use only results mature at the review time. (3) update the missing-evidence score from missing outcomes, the synthetic confirmation-gap signal, uncertain rules, unresolved human changes, and any missing approval or execution confirmation from the preceding period. (4) distinguish a serious failure from ordinary variation. (5) build the allowed response set; for example, a return to an earlier version requires a named compatible version. (6) calculate Equations (
23) and (
24). (7) issue a proposal and explanation, not a state change. (8) update the simulator’s recorded review action only after the required human decision and action confirmation. A live system would additionally need a separate record of the model version actually in use.
What was improved.
The model-set review prototype brings four issues into one decision: missing evidence, the ability to reverse a change, explicit assumptions about what a corrective response will do, and the difference between proposing and successfully applying a change. It uses fixed effect parameters, not an uncertainty distribution or a robust uncertainty set. Its synthetic model signals cover M2, M4, M7, M8, and M9 only. Hidden response effects are generated separately from the model’s assumptions, so the illustration can show failure when those assumptions are wrong; it does not estimate causal effects from operating data.
Proposition 10 (no unconfirmed review action, with delayed evidence debt).
In the implemented simulation, a non-KEEP proposal that lacks its required human approval or action confirmation does not replace the previously recorded review action, and the missing confirmation raises the next period’s evidence-debt input. Proof. ERMR first returns the proposal with a pending-human status. The simulation updates last_action only when both later checks succeed; otherwise it copies the previous value and sets prior_confirmation_missing for the next observation. The next debt update adds a positive term for that flag. The prototype does not store or lock the model version actually in use, so the proposition must not be read as a real-world version guarantee. It also says nothing about an external refund or message whose confirmation was lost.
Evidence boundary.
The model-set review prototype should begin as a read-only aid. It performs worse than a threshold rule when hidden response effects are reversed, and it cannot recover when no real return path exists. If it cannot add value over a simpler review under matched conditions, it should be reduced to a checklist or removed.
4.6. How the Model Outputs Fit Together: A Worked Example
In the target workflow, models exchange business objects rather than unexplained scores, but a model output does not become an approved object by itself. M1 proposes attributes; after responsible approval, D0 records a product version for M2 and M3. M2 proposes a price; M3 supplies paid-registration scenarios; only an approved price–intake plan moves to M7 and M8. M4 supplies learner-state probabilities and workload estimates to M7 and sends suitable cases to Q0 or M9. M5 proposes a partner set; after qualification, approval, and any required agreement, confirmed capability can inform M6–M8. M6 currently proposes a site set, cost, and temporary share; a live implementation must turn these into a versioned regional-capacity object before M7 uses them. M7 reports plan quantities, and a later evaluation step supplies feasibility measures to M2 and M8. M8 proposes a cohort plan; approval turns it into an operating range, never a profit label for an individual. M9 proposes an action for any required approval and execution. M10 reads evidence about the model set but cannot bypass the responsible person or action-confirmation process. The current M1–M3 prototypes are evaluated with separate synthetic inputs: M1 passes an approved product version rather than its score, and the current SBRF has no price predictor. Their business hand-offs are defined, but price-conditioned numerical coupling remains future work.
The feedback between price and resources is handled in rounds. M2 reads a capacity version that has been frozen for the current calculation. If M7 finds the price–intake plan infeasible, a new P3 plan version is created and the calculation is repeated. The loop ends when a feasible plan is approved, a stated iteration limit is reached, or the models make no recommendation. This avoids two models endlessly recalculating from one another’s unfinished output.
Consider a new synthetic credential offering. At the rule stage, the organization records current authorization, learner eligibility, examination, privacy, refund, complaint, and quality rules. At P1, it approves a needs brief; product selection or demand forecasting may help, but either model may decline to recommend. At P2, RMGS compares optional features across learner, employer, instructor, and delivery roles, removes a prohibited claim, and helps create product version V1. QPPE, ZHCE, and TQRP can then test whether partners, service modes, and resources can deliver that version. At P3, PSPS uses price perception only to bound candidate prices, SBRF creates four-week paid-registration scenarios, and TQRP and FTPS test resource and economic feasibility. The responsible role approves the final planning range.
At P4, outreach and registration events are recorded; SEAS is used only when there is a permitted action to choose. At P5, documents, eligibility, order, and payment follow stated rules rather than a generic score. At P6, EJTT represents learner states, while ZHCE and TQRP support scheduling, materials, teacher hours, and digital updates without mixing units. FTPS has already removed the highest-mean plan because it falls below minimum quality, so service follows a smaller approved plan. At P7, the operator checks application completeness and its own course prerequisites, coordinates logistics, and records any eligibility decision owned by the authorized examination body; models may estimate workload but cannot determine examination eligibility or certification.
At P8, only the authorized examination or certification body issues the authoritative result; A0 verifies its source, records its receipt, and passes it to the training operator’s communication process. A later appeal enters P9, is routed to the authorized body, and closes only when that body returns a disposition through A0 and D0 links it to the original result. Operational complaints separately create Q0 cases and may trigger H0 review. A refund follows its own full path: request and rule check, approved refund request, E0 execution, payment-provider confirmation or failure, and D0 registration of a new REFUND_SETTLED or REFUND_FAILED event linked to the original payment. The original payment is corrected only if that record was itself wrong. The appended event changes the M4 state and M8 cash path; neither event is deleted for convenience.
Human approval can be specific to one high-risk case or can take the form of a limited standing rule for low-risk actions. Routine recording and authoritative certification updates need not wait for a person to sign each time. The execution record stores both the request and the later confirmation. If confirmation of an external payment, refund, or notice is missing, the case becomes PENDING/UNKNOWN. The system asks for status using the same request identifier and reconciles the result; it does not blindly repeat the action. A model-set change is simpler: the new version is not recorded as effective until the required decision and confirmation are present.
Once enough later results are available, the model-set review model may see missing confirmations and out-of-date validation, propose DEGRADE, and wait. In the current simulator, rejection or missing confirmation preserves the previously recorded review action. In a real workflow, D0 should continue to show the already adopted model version until an approved change is confirmed; that version record is not implemented here. This example is a conceptual tutorial, not a claim that one executable program has passed the same records through all ten models. The current evidence consists of separately tested prototypes, one price–capacity exercise, and one model-review exercise.
4.7. A Gradual Way to Introduce the Method
Implementation can progress through four levels. At Level 0, the organization uses clear rules, records, execution confirmations, case handling, external certification results, and responsible human decisions, but no model. At Level 1, selected prototypes study past cases without affecting service. At Level 2, they run beside the existing process so that recommendations, human decisions, actions, confirmations, and outcomes can be compared. At Level 3, one narrowly scoped model may help with an approved range of decisions, with observation and a tested alternative. ERMR, if used, begins as a read-only review aid even when another model has reached assisted use.
Movement between levels depends on evidence, not on how many months have passed. A model needs stable event meanings, a useful comparison method, known failure reasons, a workable alternative, and a named owner. A high score on past data is not enough. The organization can always return to a lower level when rules change, data quality falls, complaints rise, or actions cannot be carried out reliably. A clear manual process is better than a sophisticated model that nobody can explain or use safely.