The four states are a good middle ground, binary allow lists always end up either too loose or blocking real work. The 2,490 deterministic tests are what caught my eye: keeping the risk classification deterministic is what makes it auditable, an LLM judging its own permission would defeat the point. How do you keep the context rules from drifting as you add the 11th and 12th framework adapter?