# LOCKED PRE-REGISTRATION — Net Expected-Lives Ledger for the FAR 121 1,500-Hour Rule (White-Paper Question 4)

**Document status:** LOCKED prior to running the Monte Carlo. No parameter, distribution, hypothesis, estimand, or decision rule below may be changed after the first simulation draw is generated. Any post-lock change is logged as an amendment with a timestamp and rationale and is reported as a deviation in the final write-up.

**Date locked:** 2026-06-12
**Analyst role separation:** This pre-registration is authored by the research-integrity agent. The Monte Carlo will be executed only after this document is committed (git hash recorded). The execution agent receives the locked parameters and the model code; it does not receive latitude to re-center priors.

---

## 1. Purpose and the forking-path threat

Question 4 asks whether the 1,500-hour rule is net-positive or net-negative in expected lives once we offset (a) the Part 121 lives the rule may save against (b) the road deaths it may induce by shrinking small-community/EAS air service, netting out the avoided air deaths on the displaced legs. The danger is the garden of forking paths (Gelman & Loken): the experience-vs-safety literature admits many operationalizations (counts vs rates; total hours vs PIC vs recency vs in-type; GA vs Part 135 vs Part 121; linear vs gamma vs spline; bare vs fully-adjusted covariate sets; central rate vs left tail; realized-evidence vs precautionary decision standard), and the cost side admits four planning dials the net scales linearly in. An analyst could reach either sign by selecting among these AFTER seeing results. This document fixes every such choice in advance.

## 2. The TWO competing confirmatory hypotheses

There are exactly two pre-specified, mutually-contrasting hypotheses. They differ in EXACTLY ONE parameter: the hypothesis-dependent benefit term `lives_saved_per_decade` (equivalently the in-band 250→1,500 experience-risk slope that generates it). Every other parameter — the entire cost side and all coupling structure — is SHARED and byte-identical across the two hypotheses. This is the central integrity guarantee: separation between hypotheses can come ONLY from the benefit mechanism, never from silently re-tuning a shared cost dial.

**H_A — Monotonic experience-floor (pro-rule).** Statement: Across the band the rule actually moves a co-pilot through (250→1,500 TFH), the correctly-denominated Part 121 first-officer accident RATE — and specifically its catastrophic left tail (loss-of-control, icing, startle, unstabilized approach) — carries a genuine, materially-negative marginal slope that is a within-pilot skill-dose effect surviving exposure correction and survivorship adjustment. The rule therefore buys a positive expected number of Part 121 lives per decade. Falsifiable distinguishing prediction: the benefit term has a median materially above zero (the rule prevents on the order of 1+ relevant events per decade).

**H_B — Structure-and-selection-dominated, non-monotonic shoulder (anti-rule-as-instrument).** Statement: The 250→1,500 band sits on the slow-declining shoulder of a curve whose hump lies below ~350 hr (Knecht/Craig) and whose only large documented protective gradient (Li/Baker RR=0.43) lies out of band at 5,000–9,999 hr; at the policy margin, structured-pathway membership and recency screen off raw TFH (Pilot Source Studies: lower-hour structured ≥ higher-hour time-builders on TRAINING outcomes), and high-hour risk reduction is substantially survivor/healthy-worker enrichment, not dose. The rule's marginal Part 121 benefit is therefore small and the rule is an inefficient instrument for it. Falsifiable distinguishing prediction: the benefit term is one-sided non-negative with median near zero (~0.1–0.5 lives/decade) and P5 = 0, but with a thin precautionary right tail.

**Symmetric honesty constraint (binds both directions).** H_B does NOT score the benefit at a hard zero. The literature establishes that the FAA "no quantifiable relationship" and the absent MPL-vs-time-builder accident comparison are POWER/DATA failures, not measured nulls; the precautionary left-tail floor is genuinely underpowered but non-negative. Scoring the benefit at exactly 0 is the single illegitimate move that flips the ledger sign, and is forbidden under BOTH hypotheses. Symmetrically, H_A may NOT import the out-of-band Li/Baker 5,000–9,999 hr RR=0.43 gradient into 250→1,500 (the cardinal band-swap), and may not read Colgan as hours-causal (both Colgan pilots exceeded 1,500 hr). Both benefit priors keep a negligible LEFT tail (the rule is very unlikely to INCREASE Part 121 deaths) and are anchored to the observed base rate of ~2 Part 121 passenger fatalities in 15 years post-2009.

## 3. Model structure (estimand)

```
net_lives = lives_saved_Part121  -  net_road_deaths

net_road_deaths = induced_road_deaths  -  avoided_air_deaths_on_displaced_legs

displaced_roundtrips_effective =
      communities_lost_all_service
    × rule_attributable_share          (rule-attribution gate)
    × rule_binding_fraction_on_EAS     (Part-135 9-seat exemption gate)
    × displaced_roundtrips_per_community_per_yr
    × DECADE (×10)

added_passenger_miles =
      displaced_roundtrips_effective
    × fraction_who_drive
    × added_oneway_road_miles_to_hub × 2   (round trip)
    × (1 / 1)                               (already per-passenger; occupancy enters the RATE conversion, not the mileage)

induced_road_deaths   = added_passenger_miles × road_fatality_rate_per_pax_mile
avoided_air_deaths    = added_passenger_miles × displaced_air_leg_fatality_rate_per_pax_mile

lives_saved_Part121   = lives_saved_per_decade            (HYPOTHESIS-DEPENDENT)
```

All fatality rates are carried in consistent units of **deaths per 100 million passenger-miles** (the road rate of 7.3 per billion pax-mi = 0.73 per 100M pax-mi; mainline air 0.07 per billion = 0.007 per 100M pax-mi). Vehicle-occupancy converts VMT-based road rates to passenger-mile rates and is carried as an explicit named scalar so it cannot be silently double-counted.

**Integrity coupling (NON-NEGOTIABLE).** A single latent "how-binding-is-the-rule" draw `B ∈ [0,1]` drives BOTH the benefit side and the cost side. Operationally the benefit term and the cost-side `rule_attributable_share` / `rule_binding_fraction` co-move with correlation `rho_AB` ≈ 0.75 (fixed). The admissible sampling region is the correlated diagonal, NOT the independent-corner rectangle. Sampling benefit and cost independently — which would permit pairing Side A's floor against Side B's ceiling — is the specific analytic choice that manufactures a spuriously wide/negative (or wide/positive) net and is FORBIDDEN. The in-band experience-risk slope IS effectively a draw on `B`: if the rule barely binds, both lives saved and road deaths induced are small.

## 4. Confirmatory vs exploratory split

- **CONFIRMATORY (the only two locked hypotheses):** H_A vs H_B, distinguished solely by the benefit-term prior. The confirmatory output is the net-lives distribution and P(net<0) under each.
- **EXPLORATORY (labeled as such, never used to flip the headline sign):** pathway×TFH interaction (US time-builder vs MPL/cadet); recency partial-R²; covariate-attenuation sequence (bare TFH → +recency → +structure → +survivorship); left-tail-vs-central-rate as separate estimands; subgroup splits (jet-regional vs turboprop, EAS vs non-EAS). All exploratory analyses are reported if run, but cannot substitute for or override the two confirmatory hypotheses.

## 5. Decision criteria and mandatory reporting rule

See Section 7 (decision_criteria field). In brief: ALL pre-specified outputs are reported regardless of outcome — full net distribution (5/25/50/75/95 quantiles), E[net], and P(net<0) under EACH hypothesis; the sensitivity of P(net<0) to `rule_attributable_share` and to the four linear cost dials; and the net SIGN under BOTH the realized-evidence and precautionary/maximin decision standards. No outcome-dependent selection of quantiles, scenarios, hypotheses, or decision standards.

## 6. Forking-path safeguards (locked)

1. **Rates not counts.** The benefit mechanism is anchored to correctly-denominated rates (Knecht/Li-Baker), never Craig frequency counts.
2. **In-band window only.** Benefit is evaluated over 250→1,500 hr; the out-of-band Li/Baker 5,000–9,999 hr gradient is excluded from the benefit term and reported only as a curve-bounding reference.
3. **No GA-rate substitution for the displaced leg.** The displaced air leg is scheduled commuter/Part 135 / 50-seat regional (0.07–2 per billion pax-mi), never the GA rate (~10–30× higher). This is the single highest-leverage cost-side fork and is locked.
4. **Benefit prior includes zero honestly but never AT zero.** One-sided non-negative, P5=0, negligible left tail, under both hypotheses.
5. **Shared cost parameters byte-identical across hypotheses.** Only the benefit term differs.
6. **Single coupled binding-ness draw; correlated diagonal only; no hand-paired corners.**
7. **Outcome-level matching.** Training-completion evidence (Pilot Source Study, MPL pass rates) and service-contraction evidence (GAO) are INTERMEDIATE outcomes. They inform plausibility but are never promoted to accident-rate or road-death TERMINAL claims; benefit and cost are scored at the same inferential level.
8. **Decision standard is a fixed parameter, reported under both values; the choice is labeled normative-not-empirical.**
9. **Cost dials registered ex ante; mandatory one-at-a-time and joint sensitivity; no post-hoc re-centering.**
10. **Convergence/sample size fixed in advance:** 1,000,000 Monte Carlo draws, antithetic-free, with the Gaussian-copula coupling at rho_AB=0.75; report Monte Carlo standard error on P(net<0).

## 7. Parameter table

All numeric low/mode/high values are given in Section "parameters". Cost-side priors are SHARED; the benefit prior is the only HYPOTHESIS-DEPENDENT entry.

---

## Amendment 1 to the locked pre-registration

**Amendment date:** 2026-06-13
**Author:** Research-integrity agent (same role-separated author as the locked original).
**Status of original:** UNCHANGED. Sections 1–7 and all of param-spec.json remain locked and byte-identical. This amendment ADDS two questions; it removes, reweights, and relabels NOTHING.
**Provenance:** original-preregistration content hash (sha256, pre-amendment) = `b87d8be74643eaeb67ba70f44ffd6859b094eed6313681d51f93892bbcb19e34`; completed-Monte-Carlo-output hash (sha256 of results.json) = `40258c862e9c00dff16c4ab6d370074d8e83b997a4e4b8f3dc1a98cf13660641`; this amendment authored AFTER the completed-run output existed. The ordering — locked → executed → amended — is disclosed as a deviation-by-addition in the final write-up.

### A1.1 Why this amendment is a flagged post-hoc addition
H_C and H_D are proposed by the principal AFTER the first confirmatory net-ledger results (H_A vs H_B) were known. Post-hoc hypothesis addition is the precise garden-of-forking-paths move this pre-registration exists to gate. They are admitted here under strict conditions and are CLASSIFIED to prevent any retroactive effect on the locked headline.

### A1.2 The two added questions
**H_C (EXPLORATORY — may not be confirmatory).** Does direct/earlier entry into LARGE (transport-category) multi-crew JET operations, or entry at greater age/maturity, correlate with an accident/incident RATE signal INDEPENDENT of total flight hours — such that the protective ingredient is heavy-jet/multi-crew/structured exposure or maturity rather than raw GA TFH? Bears conceptually on the H_A-vs-H_B contest (whether the 1,500-GA-hour requirement is a poorly-targeted instrument).

**H_D (EXPLORATORY by default; CONFIRMATORY-ELIGIBLE only against a newly-named, frozen, rate-denominated dataset per A1.5).** Can European GENERAL AVIATION accident data — a predominantly commercial/ATPL-career-track population — serve as a natural-experiment proxy for experience-vs-safety and for starting-younger-vs-fluency, measured as accident/incident RATES?

### A1.3 Classification ruling (binding)
1. **H_C is EXPLORATORY and may never be promoted to confirmatory.** No dataset identifies the heavy-jet-later effect free of an overwhelming survivorship/selection confound (only pilots who reached the heavy jet are observed; entry age is endogenous to hiring). Li/Baker already reports a NULL age effect and an explicit healthy-worker mechanism; H_C therefore enters as a bounded uncertainty-widener, not a point claim.
2. **H_D is EXPLORATORY unless the A1.5 pre-data identifiability gate is passed in full.** If passed, the SINGLE pre-specified European-GA rate analysis named in A1.5 may be reported as confirmatory FOR ITS OWN restricted estimand — never for the US Part-121 net-ledger headline. If the gate fails (denominator unavailable, pathway/age strata too thin), H_D auto-demotes to exploratory and is reported as a powered-out null-of-data, not a measured null.
3. **HEADLINE LOCK (non-negotiable).** No result of H_C or H_D may change, reweight, relabel, or re-open the locked H_A-vs-H_B confirmatory net-lives distribution, P(net<0), E[net], or the permitted "sign-indeterminate, magnitude-small" verdict. The original estimand set is closed. H_C/H_D yield their OWN conclusions only.

### A1.4 Pre-specification for H_C (fixed BEFORE any data is inspected)
- **Data source(s) (frozen):** NTSB Aviation Accident Database (Part 121 + Part 135 turbojet events) JOINED to a pilot-population denominator from FAA Airman Registry / BTS-derived active-pilot counts by category; entry-age and first-heavy-jet-type proxied from accident-record pilot history fields only where present. No other source may be added after inspection.
- **Outcome variable (frozen):** accident/incident RATE per 100,000 flight hours (or per active-pilot-year), correctly denominated. NOT counts. NOT training outcomes. NOT pass rates.
- **Comparison (frozen):** rate among pilots with early/direct heavy-jet multi-crew entry vs later/GA-route entry, AND a separate age-at-entry contrast, each conditioned on a TFH band so the claim is "independent of total hours."
- **Analysis (frozen):** stratified rate ratio with TFH held in fixed bands (250–1,500 / 1,500–5,000 / 5,000+), reported with CI and exact small-count handling; survivorship explicitly modeled or, where it cannot be, declared non-identified.
- **Decision criterion (frozen):** H_C is "exploratorily supported" only if the TFH-conditioned heavy-jet/multi-crew rate ratio CI excludes 1 in the protective direction AND a sensitivity analysis shows the result is not an artifact of survivorship enrichment. ANY failure of the survivorship sensitivity → reported as "confound-dominated, non-identified," never as support.
- **Identifiability/power flags:** entry-age and pathway are endogenous to hiring (selection on the protective trait); heavy-jet-later has an obvious survivorship/selection confound; Part-121 fatal-event counts are near-zero so the catastrophic-tail version is underpowered. H_C cannot resolve dose-vs-selection cross-sectionally.

### A1.5 Pre-specification for H_D (fixed BEFORE any data is inspected) — and the confirmatory-eligibility gate
- **NEW, not-yet-examined data source (frozen, named now):** EASA ECCAIRS / EASA Annual Safety Review European GA accident series, joined to a pilot/licence-population denominator from national CAA licensing registries (and, where available, national-CAA GA flight-hour estimates). This dataset has NOT been examined for this question. Eligible as a new confirmatory target IF and ONLY IF a true RATE denominator can be assembled.
- **Outcome variable (frozen):** GA accident/incident RATE per 100,000 GA flight hours OR per licence-holder-year, stratified by (i) experience band and (ii) start-age / age-at-licence band. NOT counts. NOT training/check outcomes.
- **Comparison (frozen):** experience-vs-rate gradient within European GA; and earlier-start / earlier-fluency vs later-start rate contrast.
- **Analysis (frozen):** Poisson/negative-binomial rate model with exposure offset = denominator; pre-specified age-bands and experience-bands declared BEFORE inspection; multiplicity across European states and age-bands corrected by pre-declared Benjamini–Hochberg FDR at q=0.05.
- **Decision criterion (frozen):** H_D is confirmatorily supported (for the European GA estimand ONLY) iff the experience and/or start-age rate gradient is significant after multiplicity correction AND a genuine flight-hour or licence-year denominator was obtained. If only counts are available (no denominator), the analysis STOPS and is reported as "not estimable — data/power failure." It may NOT be reported as a measured null or as evidence about US hours.
- **CONFIRMATORY-ELIGIBILITY GATE (decided BEFORE looking at any rate):** confirmatory status holds only if ALL are true: (1) a valid exposure denominator (hours or licence-years) is obtained; (2) pathway/career-track is observable, not assumed, in the European GA records; (3) age/start-age strata each have adequate event counts under the pre-declared minimum. If ANY fails, H_D auto-demotes to EXPLORATORY. The principal does not get to inspect the rate first and then choose the label.
- **Identifiability/power flags:** European GA accident data by pathway/age is thin; predominantly-career-track GA carries a selection confound; no regulator currently publishes pathway-stratified GA accident rates; LUSA is admission/performance, not accident rate; the MPL population is too small/recent for accident rates. Realistic prior: the denominator gate FAILS and H_D is reported exploratory.

### A1.6 Forking-path safeguards specific to this amendment
1. No outcome-dependent selection of which question to report — BOTH H_C and H_D reported regardless of result, including "not estimable."
2. Exploratory results may not be promoted to the confirmatory headline.
3. No retroactive re-opening of the locked confirmatory estimand set.
4. Rates not counts, terminal not intermediate (training/check/pass-rate/admission outcomes may not be substituted for the accident rate).
5. Multiplicity control pre-declared (Benjamini–Hochberg FDR q=0.05); unplanned strata are exploratory-only.
6. Survivorship/selection declared, not silently waived.
7. Symmetric honesty: a "not estimable / data-power failure" outcome is a data/power failure, NOT a measured null.
8. Label-before-look: H_D's confirmatory/exploratory label is fixed by the A1.5 gate BEFORE any rate is inspected.

### A1.7 Reporting block (locked now)
The final write-up reports, regardless of outcome: for H_C — the TFH-conditioned rate ratios + CIs + survivorship sensitivity, under an EXPLORATORY heading; for H_D — either the pre-specified European-GA rate model (if the gate passed) under a clearly-bounded confirmatory-for-its-own-estimand heading, OR an explicit "not estimable — no rate denominator obtainable" statement under the EXPLORATORY heading. In all branches, the locked H_A-vs-H_B headline is restated UNCHANGED.

### A1.8 Bottom line on answerability
- **H_C:** not cleanly answerable with existing public data and not rescuable by new collection — the obstruction is structural (endogenous entry age; survivorship). Runs only as a bounded exploratory analysis; cannot become confirmatory.
- **H_D:** almost certainly requires new data assembly (FOI/licence-registry linkage to GA hours by pathway across national CAAs) and likely fails the denominator gate even then; realistically reported "not estimable — data/power failure," symmetric to the FAA's "no quantifiable relationship."

---

## Amendment 2 / Broad Research Round — Governance Charter

**Charter date:** 2026-06-13
**Author:** Research-integrity agent (role-separated, as in the locked original and Amendment 1).
**Status of prior documents:** UNCHANGED. PRE-REGISTRATION.md §§1–7, param-spec.json, and Amendment 1 (incl. H_C/H_D classifications and the HEADLINE LOCK) remain locked and byte-identical. This charter ADDS governance for a new broad research round; it removes, reweights, relabels, or re-opens NOTHING. Provenance: appended AFTER the completed H_A/H_B run (results hash `40258c862e9c00dff16c4ab6d370074d8e83b997a4e4b8f3dc1a98cf13660641`) and Amendment 1; disclosed as a deviation-by-addition in the final write-up.

**FRAMING (locked):** Hybrid (iii). The round is EXPLORATORY-by-default. The sole route from an exploratory candidate to a confirmatory claim is a NEW, separately pre-registered confirmatory study — distinct from the net-ledger, with its own locked hypotheses, frozen data, and decision rule — executed in a FUTURE round under that fresh lock. No exploratory output, single- or multi-cycle, may enter the locked headline.

**SCOPE — legitimate (own estimands, new evidence):** alternative policy designs (R-ATP/EQP/simulator-AQP credit vs raw TFH); international regulatory comparison beyond Europe (ICAO MPL adopters, CASA, TCCA), rate-denominated, under the §A1.5 denominator gate; full safety-reform-package attribution / decomposition; mechanism studies (fatigue, automation/manual-skill decay, CRM/multi-crew); labor-market & equity/access dimensions; cost-effectiveness vs alternative aviation-safety spending.
**SCOPE — barred (re-litigation):** any re-estimation of `lives_saved_per_decade`, the four cost dials, `rule_attributable_share`, `rule_binding_fraction`, the displaced-air-leg comparator, the road-substitution chain, or rho_AB to move net_lives; the band-swap, Colgan-as-causal, benefit-at-hard-zero, and GA-rate-substitution prohibitions remain in force; no re-opening of H_A/H_B/H_C/H_D.

**PER-CYCLE DISCIPLINE (locked):** (1) pre-commit questions/scope/data/disposition-rule, hashed and dated, BEFORE inspecting that cycle's data (label-before-look); (2) adversarial/red-team review of both pre-commit and output each cycle; (3) cumulative append-only ledger of every question, dataset, analysis, and dead end across all cycles; (4) cross-cycle multiplicity tracked and corrected (pre-declared BH-FDR q=0.05); (5) cumulative exploratory findings may NOT be repackaged as confirmatory — only a fresh pre-registration can.

**HALT CONDITIONS (any one halts):** re-open/re-run/re-weight/re-label of the locked net-ledger or its verdict; data examined before a cycle's pre-commit is locked; exploratory presented as confirmatory without fresh pre-reg; outcome-dependent cycle selection or suppression; a barred domain pursued to move the locked sign; an incomplete ledger; skipped or overridden adversarial review.

**SAFEGUARDS (locked):** all three cycles reported with equal prominence (incl. null / not-estimable / unflattering); no cherry-picking which cycle to elevate; the locked net-ledger headline — *"sign indeterminate, magnitude small, modest adverse lean"* — restated VERBATIM and UNCHANGED in every cycle output and the synthesis; exploratory-vs-confirmatory labels fixed before results are seen and maintained throughout; role separation preserved; symmetric honesty (data-power failure ≠ measured null; favorable findings held to the same identifiability bar as unfavorable).

---

## Integrity note on tamper-evidence (2026-06-13)

The `sha256` provenance hashes recorded above are computed by FRISA, of FRISA's own files, and stored in FRISA's own repository. They establish **internal consistency** — that the document and results referenced match at the moment the hash was written — but they are **not** third-party tamper-evidence: the same party controls both the content and the hash and could recompute both. Honest provenance requires anchoring the lock to something FRISA does not control. The intended fix, flagged here rather than overclaimed: deposit the locked pre-registration on an independent timestamped registry (OSF Registrations / AsPredicted), or anchor the file with OpenTimestamps, or reference the immutable external commit SHA of the locked commit — and then cite *that* as the provenance, treating the self-computed hash as a consistency check only. Until that anchor exists, this document's integrity claim is **disclosed-and-dated honesty about the analysis ordering** (see Amendments 1–2, which state plainly that the amendments were authored after results existed), not cryptographic third-party provenance.
