{"id":"6620eeb4-371c-4a47-a6eb-ae84fb21a859","arxiv_id":"2607.04511","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"Same-mean remediation processes can consume 1–17% of local capacity depending on release cadence; a governance audit reports that calendar discount so MTTR is not treated as a fielding model.","lead":"This paper shows that the same mean remediation lag can hide very different security fielding risk depending on release calendars, and defines a cadence audit that measures the capacity lost to batching. Enterprise teams can use the calendar discount to decide when MTTR/SLA alone is unsafe as fielding evidence.","discovery_kind":"new_method","skeptic_critique":{"model":"grok-4.5","headline":"The governance claim rests on capacity boundaries from an unvalidated four-state channel; if real adaptation is not captured by that model, the numerical discounts are not the right objects for the MTTR warning.","rationale":"The reader correctly isolates the four-state channel and capacity semantics as the weakest assumption. The paper is careful about scope (not a breach predictor; notional ledger; declare rate scenario), and the internal math for that model is explicit and numerically checked (Tables 5, 11–14; Appendices B–D). That is enough for CONDITIONAL: the audit interface and the qualitative warning that matched means can hide calendar effects are usable once local L and rates replace the demonstration values. It is not enough for ACCEPT, because the headline percentages and the inside/outside verdict language are model-dependent objects, not model-free timing facts. No stronger internal inconsistency appears; the concern is external validity of the capacity interpretation, not a calculation error inside the chosen backend. Agreement with the reader is therefore full on the load-bearing point; the verdict stays CONDITIONAL.","tokens_in":24325,"tokens_out":679,"duration_ms":6369,"concrete_test":"Independently recompute the continuous and calendar-aware boundaries for the monthly and bimonthly same-mean packets using at least one structurally different local model (e.g., pure delay-differential fielding without the four-state √L coupling, or a two-state defender-only lag model with the same m, T, α, τ_Σ). If the calendar discount for T/m=2 falls below ~8% or the monthly discount leaves the 3–8% band under the same normalized rates, the numerical illustrations no longer support the governance claim as stated.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The strongest claim is that material calendar discount (e.g., ~17.4% for T/m=2, ~5.2% monthly under the normalized scenario) means MTTR/SLA should not be used alone as fielding evidence. That claim is only as strong as the semantics of L^cont_crit and L^cal_crit. Those boundaries are defined by zero real-part principal root of the continuous characteristic equation (A.3–A.4) or unit spectral radius of the one-cycle map M_L(T)=J_α exp(A_L T) (A.9–A.11), for the four-state system of Appendix A in which residual pressure L enters only through the √L coupling terms. The paper treats this as the local adaptive channel whose inside/outside capacity is the governance object (§2, §4, Table 2). Nothing in the manuscript shows that enterprise residual pressure after controls, or attacker technique share, evolves according to that structure; the residual-pressure ledger is notional (Table 4), rates are a screening convention (κ band in Table 12), and the backend is imported from prior work [1]. If the true fielding–adaptation dynamics have different order, different coupling, or multi-channel structure, the reported discounts can still be nonzero while no longer corresponding to a capacity loss that justifies the MTTR warning. The release-geometry checks (rings, staggering) inherit the same model.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The paper argues that MTTR, SLA compliance, and related mean remediation metrics are useful governance indicators but are not fielding models: two processes can share the same reported mean lag while exposing the estate to different release geometry (windows, partial backlog clearing, rings, emergency bypass). It defines a remediation-cadence audit packet (routine mean lag m, period T, release fraction α, cohort geometry, emergency/routine split, hard-delay budget τ_Σ, residual-pressure interval I_L, rate scenario), compares a continuous same-mean shortcut with a calendar-aware release process, and reports a local capacity verdict plus a calendar discount Δ_cal = (L_cont_crit − L_cal_crit)/L_cont_crit. Worked notional packets with fixed m = 30 days and τ_Σ/m = 0.5 give discounts of about 17.4% (T/m = 2), 5.2% (monthly), and 1.3% (two-week) under a normalized screening scenario; a κ band keeps the qualitative reading; rings at fixed per-asset cadence do not recover the continuous boundary; cohort staggering can help or hurt near capacity. The contribution is framed as a reproducible governance diagnostic, not a breach predictor or CVE prioritizer.","tokens_in":24796,"tokens_out":1796,"duration_ms":28504,"significance":"If the capacity semantics are accepted, the paper makes a useful and well-scoped contribution to security-operations measurement and remediation governance. The calendar-discount concept, the audit-record/status table, and the evidence-resolution reading (when Δ_cal is material relative to I_L width or claimed headroom, do not use MTTR alone) are practical and clearer than mean-only dashboards. Strengths that should be credited: careful non-overclaiming (notional ledger, screening rates, limitations section); independent numerical checks of finite boundaries, hard-delay placement invariance, ring limits, and staggering (Tables 11–14, Appendix D); a rate-scenario band; the model-independent same-mean non-equivalence argument in Appendix C; and a stated reproducibility package. The qualitative point that matching mean lag does not match fielding dynamics is independently valuable even if specific L_crit numbers move under alternative backends.","major_comments":[{"comment":"The central governance claim—that a material calendar discount means MTTR/SLA should not be used alone as fielding evidence—depends on the operational meaning of L_cont_crit and L_cal_crit. Those boundaries are defined as zero real-part principal root / unit spectral radius for the four-state local channel of Appendix A (Eqs. A.1–A.11), with residual pressure L entering only through the √L couplings. The manuscript does not show that enterprise residual pressure after controls, or attacker technique share, evolves under that structure; rates are a screening convention and the residual ledger is notional. Without structural sensitivity (different order, coupling, multi-channel) or a clearer claim hierarchy that separates model-independent non-equivalence (Appendix C) from model-dependent percentages, the reported 17.4%/5.2%/1.3% discounts risk being treated as capacity loss when they are","section":"§2, §4, Appendix A (A.1–A.11)"},{"comment":"Table 10’s practical discount bands (“below ~3%”, “3–8%”, “8–15%”, “above ~15%”) and the headline “resolved cadence warning” for the bimonthly packet (Tables 5–6) treat materiality relative to residual-pressure resolution as if those cutoffs were operationally grounded. They are audit language under one normalized delayed scenario (L_cont_crit ≈ 2.767, τ_Σ/m = 0.5). The paper should either derive materiality thresholds from stated headroom/uncertainty rules that do not depend on the particular L scale of the backend, or mark the bands and the worked I_L placement as illustrative under the declared screening convention so readers do not import 5% or 17% as portable policy numbers.","section":"§5 Table 10; §3 Tables 5–6"},{"comment":"The residual-pressure construction (Eq. 2, Table 4) is a minimal two-by-two substitution ledger mapped to a scalar L = s². That is acceptable for a method paper, but the governance statuses in Table 2 (especially “resolved cadence warning” vs “calendar-discount finding”) inherit the scale and contrast definition of that ledger. Production guidance should require a stated mapping from BAS/control-validation evidence to the same L that enters the characteristic equation, or the audit should report discount and geometry findings without forcing an inside/outside verdict on an uncalibrated L. As written, the bridge from local evidence to L_crit comparison is underspecified relative to the strength of the management reading in §3.","section":"§3 Eq. (2), Table 4; Table 2"}],"minor_comments":[{"comment":"Figure 1 and Table 1 are clear; consider adding a one-line mapping from each audit field to the backend symbol (m, T, α, τ_Σ, L) so operations readers can connect the packet to Appendices A–D without hunting.","section":"§2 Figure 1, Table 1"},{"comment":"The relationship to the companion implementation-filter paper [1] should be stated more sharply in the introduction: what is reused unchanged versus what is new in the audit interface, so novelty is not ambiguous for readers who only see this manuscript.","section":"§1"},{"comment":"Table 12: note explicitly that the bimonthly discount is non-monotone in κ (already mentioned in text) in the table caption so the band is not misread as monotone capacity loss.","section":"§6 Table 12"},{"comment":"Minor consistency: abstract says monthly train “5.2%” and later “about 5%”; keep one reported precision when the same screening case is restated in §1 and §9.","section":"Abstract, §1, §9"},{"comment":"Appendix C’s transfer-function counterexample is one of the clearest model-light arguments in the paper; consider a short forward pointer from §5 so readers who skip appendices still see that same-mean non-equivalence does not require the full capacity machinery.","section":"§5; Appendix C"}],"recommendation":"major_revision","confidential_remarks":"Fit for a security-operations / measurement venue is good; the dynamical-systems backend will be dense for some practitioners, so the revision should keep the audit interface readable if the model justification is expanded. The skeptic concern about the four-state channel is real and load-bearing; I would not reject on that alone because the paper is carefully scoped and Appendix C is independently useful, but I would not accept without a clearer separation of model-independent claims from backend-specific percentages. No integrity or citation-pattern concerns beyond the usual need to demarcate reuse of [1]."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"Punchline: this is a usable governance diagnostic for a real ops failure mode—MTTR/SLA can stay flat while fielding gets coarser—and the paper mostly refuses to oversell it.\n\nWhat is new is not delay systems or patch process models. It is the audit packet, the calendar-discount number as an evidence-resolution object, the same-mean vs calendar-aware comparison for matched mean lag, and the release-geometry results: equal-phase rings approach a phase-averaged calendar, not continuous fielding, and staggering can help or hurt near capacity. That packaging is the contribution. The dynamical backend is imported from the author’s prior work; the security-ops interface on top of it is the paper.\n\nIt does the method-paper work well. Scope is tight and repeated: not a breach predictor, not a CVE prioritizer, notional residual-pressure ledger, declare the rate scenario. Finite boundaries are stabilized (Table 11), hard-delay placement is checked, a 16-fold κ band is reported, and Appendix C’s same-mean transfer-function counterexample is almost model-independent. Citations are appropriate—NIST 800-40, vendor cycles, KEV, EPSS, ATT&CK, sampled-data control—without padding. The status table (mean-only adequate / resolved warning / input-resolution limited) is more useful than another binary threshold.\n\nSoft spots, in proportion. The residual-pressure cells are chosen so L sits between continuous and calendar boundaries; that is exposition, not measurement. The load-bearing semantics of L_cont_crit and L_cal_crit live in the four-state channel of Appendix A. If real adaptation has different order, coupling, or multi-channel structure, the absolute discounts move even if batching still differs from continuous catch-up. The paper admits the screening convention and the need for local L; it does not hide the free parameters. That limits how far the 17.4% / 5.2% / 1.3% figures travel as enterprise facts. It does not make the qualitative audit idea empty.\n\nWho it is for: people who own VM metrics, change windows, rings, and control-validation evidence and already distrust mean-only dashboards. Not for prioritization research.\n\nI would send it to peer review. A referee should pressure the capacity semantics and demand clearer separation between geometry-driven timing loss and the specific dynamical object. Worth engaging if you work on remediation measurement or security governance metrics.","headline":"Careful method paper: calendar discount and audit packet are the real product; the 17%/5% numbers only mean capacity inside an unvalidated four-state channel, but the paper is honest about that and still deserves referees.","tokens_in":25412,"tokens_out":628,"would_cite":true,"duration_ms":20846,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"Mean remediation lag is not a fielding model: the same average lag can hide release calendars that consume a large fraction of local security capacity.","keywords":["Cybersecurity operations","vulnerability management","patch management","remediation metrics","MTTR","release cadence","security governance","control validation"],"falsifier":"On a real estate with sharp BAS or red-team residual-pressure intervals, recompute continuous and calendar-aware boundaries from measured release telemetry; if the calendar-aware process never flips the growth-rate sign and the discount stays negligible relative to measured headroom across a realistic rate band, the claim fails for that channel class.","tokens_in":25136,"feed_emoji":"⏱️","tokens_out":892,"duration_ms":17266,"temperature":0.7,"pith_summary":"Enterprise security teams often treat mean time to remediate and SLA compliance as proof that defensive fixes are being fielded safely. This paper argues that is unsafe: two programs can report the same mean lag while one fields continuously and another waits for monthly or bimonthly windows, clears only part of the backlog, or routes work through rings and emergency bypass. The author introduces a remediation-cadence audit that records release period, release fraction, cohort geometry, hard delay, residual-pressure evidence, and rate scenario, then compares a continuous same-mean shortcut with the actual calendar. The audit returns a local capacity verdict plus a calendar discount—the share of mean-only capacity consumed by batching. Worked packets with a fixed 30-day mean show a two-month train consuming about 17 percent of capacity, a monthly train about 5 percent, and a two-week screen about 1 percent; rings do not restore the continuous benchmark, and staggering can help or hurt near capacity. When that discount is material relative to residual-pressure uncertainty or claimed headroom, MTTR alone should not be used as fielding evidence.","feed_headline":"Same mean lag can hide 17% capacity loss from calendars","feed_subtitle":"MTTR alone is not fielding evidence when batch windows eat material headroom","key_machinery":"Calendar discount: the fraction of mean-only local capacity consumed by the recorded release calendar, obtained by comparing continuous same-mean capacity boundaries with calendar-aware release-window boundaries under a declared local-channel rate scenario.","core_discovery":"MTTR, SLA compliance, and related mean-lag metrics are useful governance indicators but are not fielding models. Release windows, partial backlog clearing, rings, hard delays, and emergency splits can change the local capacity verdict even when the reported mean lag is held fixed. The remediation-cadence audit therefore reports both an inside/outside capacity verdict and a calendar discount that turns cadence assessment into an evidence-resolution question rather than a fragile point comparison.","pith_inferences":["Patch and change-management tooling may need to expose the same telemetry fields the audit requires so governance claims can be recomputed rather than asserted from ticket means.","Organizations that improve reported MTTR while lengthening release trains may be silently increasing calendar discount even as dashboards look healthier.","The same continuous-versus-batch diagnostic could apply to other security processes such as detection-rule deployment or identity-policy rollout.","Public CVE scoring remains prioritization context only; local residual-pressure ledgers stay necessary for capacity claims."],"forward_implications":["Security teams must record release period, release fraction, rings, hard delay, residual-pressure evidence, and rate scenario before treating MTTR as fielding proof.","Deployment rings at fixed per-asset cadence do not recover continuous fielding and cannot be used as verbal assurance.","Cohort staggering can help or hurt near capacity and must be checked as evidence, not assumed.","Coarser trains (for example bimonthly) produce larger, more easily resolved discounts than monthly ones with the same mean lag.","When residual-pressure evidence is coarse relative to the discount, the correct output is an input-resolution finding rather than a forced pass or warning."],"fun_headline_variants":["Same 30-day mean lag hides up to 17% calendar capacity loss","MTTR is not fielding: release trains consume mean-only capacity","Cadence audit shows batch windows eat headroom MTTR misses","Two-month release train takes 17% of continuous mean capacity","Release calendars, not MTTR, decide local remediation capacity"],"cache_read_input_tokens":16512,"weakest_assumption_plain":"Local adaptive risk on a channel is adequately described by a simple four-state dynamical system whose capacity boundary is where small disturbances stop decaying, so continuous-versus-calendar boundary comparison is the right object for fielding claims.","fun_headline_variants_meta":{"raw":{"variants":["Same 30-day mean lag hides up to 17% calendar capacity loss","MTTR is not fielding: release trains consume mean-only capacity","Cadence audit shows batch windows eat headroom MTTR misses","Two-month release train takes 17% of continuous mean capacity","Release calendars, not MTTR, decide local remediation capacity"]},"model":"grok-4.5","effort":"low","cost_usd":0.00435,"raw_usage":{"total_tokens":1345,"prompt_tokens":882,"num_sources_used":0,"completion_tokens":76,"cost_in_usd_ticks":43500000,"prompt_tokens_details":{"text_tokens":882,"audio_tokens":0,"image_tokens":0,"cached_tokens":128},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":387,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":882,"tokens_out":76,"duration_ms":4387,"temperature":1.0,"reasoning_tokens":387,"cache_read_input_tokens":128,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-11T18:19:00.046302+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"On a real estate with sharp BAS or red-team residual-pressure intervals, recompute continuous and calendar-aware boundaries from measured release telemetry; if the calendar-aware process never flips the growth-rate sign and the discount stays negligible relative to measured headroom across a realistic rate band, the claim fails for that channel class.","supporting_citations":[],"review_version":1}