The detail that makes this credible is that the harness kept refusing you while you were writing the guide about it. Most safety-by-default posts describe a policy nobody has actually lived under, and the friction is the entire design question.
Requiring those four facts is interesting because three are checkable after the fact and one is not. "What the operator actually asked for" is a restatement by the same agent that wants the write approved, so it constrains sloppiness rather than intent.
The gate that refuses to let a session end is the more unusual idea. The number I would want there is the abandonment rate, because a fail-closed default only holds if people do not quietly learn to route around it.