farm_history layer learns from what happened on a farm, Estate Group reconciles forecast against actual harvest by field, and the Aggregation Model defines forecast, confidence degradation, and k-anonymity. The methodology adds no new aggregation category, invents no new causal machinery, and refuses more claims than it makes.
Amendment D routes public money. A confident wrong answer here costs more than an honest not yet. The largest section of this page is When no claim can be made; read it before reading the positive case.
Three claim strengths
The methodology carries three claim tiers, in increasing strength and decreasing availability. Every effect measure, baseline, and disclosure below anchors to which tier it can support.
Every downstream artifact discloses which tier it supports. A bundle that claims counterfactual impact but only demonstrates observed change fails the disclosure rule and cannot ship. This is the same discipline the Aggregation Model reproducibility rule applies to rollups.
Vocabulary
These terms are strict; do not use them interchangeably. In particular the three claim-strength words above (observed change, attributable change, counterfactual impact) carry distinct disclosure rules and are not synonyms for “effect”.
What counts as an intervention
An intervention is a logged operation intended to change an outcome. The list is deliberately narrow: an operation that leaves no on-farm signal cannot support an effect claim at field granularity regardless of how much money is attached to it.Measurable at field granularity
Not measurable at field granularity
Decision: subsidy attribution. Field-granularity attribution of a subsidy disbursement to a field-level outcome is refused. Scheme-level cohort attribution is the honest answer and is the only path by which a subsidy claim reaches counterfactual impact. This is written as decision rather than option because the alternative (letting agencies claim field-level subsidy attribution on any signal correlated in time) is the failure mode the Verification Model already refuses for
did-it-happen claims; extending the refusal to did-it-help is consistent.
Effect measures, ranked by claim strength
Four measures. They are not a menu; they are a hierarchy. The methodology maps each intervention type to a primary measure and lists the fallbacks in order.Avoided-loss and the resolver-layer gate
The Risk Model resolves yield-impact through four layers, in order:farm_calibrated → by_region → by_ecosystem → literature_v0. The resolved layer is the trust score for the avoided-loss measure: it is graded, already computed, and already inspectable on every rulecard-firing.
The gate.
A monetary avoided-loss figure may be reported only where the rulecard’s yield-impact resolved at
farm_calibrated. At any layer above that, the platform reports the physical response and declines the ringgit figure. This is stricter than untrusted curve → refuse: a literature-default curve is not untrusted for physical response; it is untrusted for money. Publishing a ringgit figure derived from literature_v0 against an agency disbursement is the single most expensive error available on this page.
The chain to farm_calibrated. The farm_calibrated layer is built from farm_history per Risk Model → yield-impact layers. farm_history calibration was gated on corroboration in Finding Provenance → Feedback into farm_history. So the chain that unlocks a ringgit figure on a given farm is: corroborated resolved finding → feeds farm_history → enables farm_calibrated resolution on that hazard for that farm → unlocks monetary avoided-loss. A farm with no corroboration history sees physical response only, regardless of how many interventions it has logged.
Primary measure per intervention type.
Saturation is a structural precondition, not a degradable confounder
Above roughly NDVI 0.80, the index stops discriminating. A closed oil palm canopy at prime and a tapped rubber block at full canopy sit above that ceiling permanently, not intermittently. Two of the four crops cannot demonstrate effect on their default index at their most valuable stage: not sometimes, not under cloud, structurally and always. The failure mode this closes is the worst one this page can produce. A scheme report that silently ran NDVI on prime oil palm or on tapped rubber measured nothing at all and will return a null effect that looks like an honest null. An agency reading it cannot tell the difference between the intervention did nothing and we did not measure. That is worse than a refusal because it is indistinguishable from one. Rule. Effect measurement on oil palm atprime phenology and on rubber under tapping must run on NDRE per Indices, not NDVI. If NDRE is unavailable for the attribution window (drone imagery does not provide the red-edge band, or the corroborating pass is missing NDRE), the claim is refused, not degraded. The refusal cites saturation and states which pass or index was missing.
This is a precondition on the effect artifact, enforced in Guardrails → Preconditions. It is not one confounder among many. The confounder table below carries saturation only for the intermittent case (a paddy field driving into saturation late in the season, a young pineapple canopy approaching closure); the structural case for oil palm at prime and rubber under tapping is resolved here, above the confounder table, and never degrades to observed change.
The baseline
Three candidates, each with a failure mode named in the brief. Amendment D’s decision is a per-crop primary and per-crop fallback, because the crop cycle models differ enough that a single global primary would be dishonest.The candidates
Per-crop decision
Before-and-after is never primary. In every crop it is the last-resort fallback, used only when neither prior-cycle nor cohort can form. When it is used, the claim-strength ceiling is observed change; the methodology refuses to promote a before-and-after comparison to attributable change.
Amendment A’s band resolver keys on
crop, ecosystem, and stage. Reusing those keys as cohort comparability keys is what makes cohort baselines computable for what a healthy band looks like. It is not enough for what an untreated arm looks like: see Cohort selection bias and the fifth key immediately below.Cohort selection bias and the fifth key
Fields that received an intervention were usually the worse ones. That is why they got it. A cohort matched only oncrop, ecosystem, stage, and region therefore compares a distressed treated arm against an average untreated arm and systematically understates the effect. The bias is not noise; it has a direction, and it is always the same direction.
This matters more than it would elsewhere because cohort is the primary baseline for paddy and pineapple per Per-crop decision. Two of the four crops rest their strongest available claim on an arm that is systematically not comparable unless the deviation gate is enforced.
Rule. Cohort comparability requires a fifth key beyond Amendment A’s four: pre-intervention deviation from band at the attribution window’s opening. Amendment A already computes deviation on every field to place it inside or outside the healthy band; the key is available without new signal work. Untreated arm members must fall inside the same deviation bracket as the treated arm at the window’s opening, at bracket widths defined per crop (draft: 0.5σ of the crop’s band width; the exact widths are a Risk Model calibration and are noted in Open Questions).
Failure mode. A cohort drawn without deviation-matching produces a counterfactual-impact claim that reads as an honest number and understates the intervention. An agency using that number to decide the next round of disbursement under-funds a working programme. The refusal is loud rather than a downgrade: no counterfactual-impact artifact ships from a cohort that has not passed the deviation gate.
What degradation looks like. If deviation-matching drops the untreated arm below k=5, the artifact degrades to attributable change (per-field), not to a counterfactual-impact claim on the un-matched cohort. Attributable change on the treated field with its own baseline (prior-cycle where possible, before-and-after as ceiling-at-observed-change fallback) is honest; a bias-inflated counterfactual-impact is not.
The attribution window
The window during which an effect claim is admissible. Tied to the rulecard’sdays_to_mitigate per Risk Model, capped by per-crop cycle geometry.
Rulecard-anchored, crop-capped
Per-crop ceilings
Rulecard-anchored, not calendar-anchored. An intervention against a fast-cycle disease (rulecard
days_to_mitigate = 14 days) has a nominal window of 14 to 28 days after intervention. An intervention against a slow-cycle nutrient deficiency (rulecard days_to_mitigate = 45 days) has a nominal window of 45 to 90 days. The methodology does not apply a single “60 days after any intervention” rule; the rulecard already knows the biological horizon and the effect methodology inherits it.
Confounders
The claim is only as strong as the disposition of these confounders. Each is either controlled for (the methodology has a rule that neutralises it) or refused if uncontrollable (the claim degrades to observed change or to no-claim).
An effect claim that ignores any applicable confounder is refused, not downgraded. The refusal is loud; see Guardrails.
When no claim can be made
The largest section, per the brief and per the product’s habit. Every condition below produces a no-claim state: a positive assertion that the answer is not yet, with a stated reason and a stated condition that would allow a claim to become possible. Silence is not permitted; the platform’s honest posture is to say we cannot tell yet, here is why, here is what would need to be true.
The no-claim state is a first-class artifact. It bundles into the Verification evidence envelope, is logged per the Audit Envelope, and is displayed on every surface an effect claim would be displayed on. An agency that receives a no-claim artifact has the same tamper-evident guarantee as a positive claim: they can prove the platform refused, when, and why.
How it aggregates
Field-level effect measures roll to scheme-level answers under the existing Aggregation Model discipline. Amendment D adds no new category. It adds one composition rule and one k-anonymity extension.The existing discipline (unchanged)
- Never average an average. Field-level effect claims do not average into a scheme-level claim; they compose per the aggregation category applicable to the measure. Recovery back inside band is a count with an area weight per field; days to recovery is a per-field duration and is aggregated as a distribution (median, IQR), not as a mean.
- Area-weight intensive measures. Yield delta expressed as a percentage is intensive; when rolled to scheme level it is area-weighted by the treated area on each field. Absolute yield delta in kg or tonnes is extensive and sums directly, subject to the reconciliation source.
- k-anonymity at k=5. Any breakdown of the scheme claim that would land below k=5 fields is withheld; the aggregate remains available.
- Confidence as minimum of inputs. The scheme-level effect claim’s confidence is the minimum of the field-level confidences composing it. A single weak-graded field lowers the scheme confidence; it does not average with the strong-graded ones.
The Amendment D additions
Cohort-breakdown k-floor. Once a cohort is defined at k, any breakdown of that cohort (by crop, ecosystem, region, intervention timing) inherits the k floor and refuses breakdowns that would violate it. The failure mode this closes: a scheme covers 12 fields, 7 treated, 5 untreated. The cohort has k=5 exactly at the untreated arm. Any further breakdown (by ecosystem, by region) would drop below k on one side. The methodology withholds the breakdown; the aggregate remains available. This is a natural extension of the existing k rule and is stated explicitly because the shape (subset of a cohort must also respect k) is not obvious from the general rule. Attribution-window composition at scheme level. When rolling field-level attributable-change claims to a scheme-level counterfactual-impact claim, the scheme-level attribution window is the intersection of the field-level windows, not the union. A scheme with 100 treated fields whose windows range from Day 14 to Day 90 supports a counterfactual-impact claim only over the interval where every field’s window is open. The scheme claim outside that interval degrades to observed change. This preserves the minimum-of-inputs discipline the aggregation model already applies to confidence. Cross-crop refusal is structural. As with the band model, effect measures do not average across crops. A national dashboard showing “scheme-level effect: N%” across paddy, oil palm, rubber, and pineapple is refused; the dashboard shows four separate claims or none.What the agency sees
Not a screen design. The claims the platform is willing to make, in tiers, and the evidence attached to each.The claims
The disclosure envelope
Every tier’s artifact carries:- The tier itself, named. No artifact conflates tiers.
- The intervention log reference (event id, actor, timestamp, verification bundle).
- The baseline reference (which of the three candidates was used, why the primary was chosen or the fallback was required).
- The attribution window’s open and close dates.
- The confounders’ dispositions (which were controlled, which if any were noted as weak).
- The verification grade of the corroborating pass; weak grade carries through.
- The reconciliation source if the claim rests on yield delta.
- For counterfactual-impact tier: cohort id, k on each arm, aggregation rules applied.
The subsidy case, stated bluntly
An agency disbursing subsidy under Amendment D can receive:- Not a field-level attributable-change claim tying the subsidy to a specific field’s outcome. Refused; see What counts as an intervention.
- Not a counterfactual-impact claim for the scheme unless a documented untreated cohort exists and satisfies k. Refused otherwise.
- Yes an operation-log summary of measurable interventions taken by subsidy recipients (application plans applied, field checks completed, irrigation actions logged), each carrying its own effect artifact at whatever tier that intervention’s evidence supports.
- Yes a no-claim artifact for the scheme where a claim cannot be made, with the reason stated.
Guardrails
Amendment D follows the shared guardrails template. No new category is introduced.Seed
Fixtures target the observed, attributable, and counterfactual tiers, the no-claim state, and the subsidy case that lands correctly at scheme level only. Fixture ids follow the human-readable convention per Field Data Model; no UUIDs. Theeff_ prefix is decided here.
Coverage properties.
- Every effect measure appears at least once.
- Every no-claim reason appears at least once (attribution window, cohort below k, cohort deviation-gate refused, wintering, resolver above
farm_calibrated, two interventions, no untreated arm). - Every per-crop primary baseline is exercised on its intended crop.
- Weak-grade cloud disclosure travels end-to-end.
- Subsidy is exercised in both the possible-cohort case and the no-comparable-untreated case; field-level subsidy attribution never appears.
- Cross-crop rollup is not seeded; the refusal is structural and is not exercised through fixtures.
Docs Delta
Amendment D is silent, ambiguous, or contradictory against the current docs in the places below. Each item is enumerated, not resolved silently.Open Questions
These are decisions the literature did not resolve. Amendment D enumerates them; it does not answer them.by_regionadmissibility for monetary avoided-loss with a widened error band. Avoided-loss and the resolver-layer gate admits monetary figures only atfarm_calibratedand refuses them atby_region,by_ecosystem, andliterature_v0. Whetherby_regionshould be admissible with a stated widened error band (for schemes in regions where enough estates have calibrated but this specific farm has not) is undecided. The narrower question replaces the earlier open question about the trust-score shape, which is closed: the risk-model resolver layer is the trust score, and it is already graded.- Cohort formation cadence. Cohorts can be formed per-artifact (each effect claim draws its own untreated arm at publication time), per-reporting-period (the scheme’s untreated arm is fixed at the start of the reporting round), or maintained continuously (the platform holds a scheme’s cohorts as a first-class object). Each has integrity and cost trade-offs; the current draft is silent on which is default.
- NADMA disaster relief as a fifth agency use case. Subsidy bodies and takaful insurers fit the intervention-effect model cleanly. NADMA relief is a different shape: the intervention is disbursement after damage, and the counterfactual (would the recipient have recovered without relief) is much harder to construct against a cohort because comparable untreated cases in a disaster zone are politically and ethically constrained. Amendment D does not resolve the disaster-relief attribution model; a companion amendment may be needed.
- Interaction with human-raised findings per Finding Provenance. A
scout.completedfrom a human finding may be an intervention (it changed a decision) or it may be corroboration (it confirmed a machine finding without changing the state). The current draft distinguishes by whether a rulecard-firing state changed; whether a human finding on its own (no machine pairing) can support an attributable-change claim without a paired rulecard is undecided. - Yield-delta reconciliation timing. Estate Group reconciliation lands at end of cycle. For long-horizon crops (oil palm production year, rubber tapping year) the yield-delta effect artifact is a year late. Whether an interim reconciliation checkpoint (mid-cycle FFB yield for oil palm; mid-tapping-year latex output for rubber) is admissible as a partial yield-delta claim is undecided.
- Cross-scheme aggregation for national dashboards. A national dashboard aggregating counterfactual-impact claims across many schemes must respect k on each contributing scheme and preserve the minimum-of-inputs confidence. Whether a national-level cohort (drawing untreated arms across schemes) is admissible or whether national claims are strictly summations of scheme-level claims is undecided; the current draft implies the latter but does not state it.
- Retroactive attribution. An intervention logged and cross-checked months after the fact (a late-log per Verification Model) may still fall within an admissible attribution window on paper. Whether late-log interventions can support attributable-change and counterfactual-impact claims, or only observed change, is undecided.
- Deviation bracket widths per crop. Cohort selection bias and the fifth key requires deviation-matching at brackets defined per crop; the current draft uses 0.5σ of the crop’s band width as the working figure but the exact widths are a Risk Model calibration that should be established against real cohort formation attempts across paddy and pineapple schemes.
Related
- Verification Model — the did-it-happen track this page’s did-it-help track sits alongside.
- Aggregation Model — the rollup discipline effect claims obey; the source of the k-anonymity and never-average-an-average rules.
- Risk Model — the source of the rulecard
days_to_mitigate, the yield-impact curve, and thefarm_historylayer effect claims feed. - Crop Cycle Models — the per-crop cycle geometry that caps attribution windows.
- Finding Provenance — the source of the corroboration rule for
farm_historyfeedback, which composes with Amendment D’s attributable-change tier. - Seasonal Analysis — the descriptive index-vs-yield correlation whose outputs feed effect claims as evidence.
- Estate Group — the forecast-vs-actual reconciliation that yield-delta claims rest on.
- Semai Advisor overview — the safety floor effect artifacts obey, and the advisor behaviour when a claim would land in a no-claim state.
- Guardrails Template — the eight categories this page fills.
- Role Model — the authoring authority effect artifacts require.
- Audit Envelope — the envelope every effect artifact extends.