Least-harm actions are bounded next-step labels such as request evidence, human review, protect user, release cleared funds, or keep dormant.
The system does not make final punitive decisions. It preserves review boundaries and keeps human oversight visible.
Current evidence combines internal/local tests and controlled hosted API smoke. External validation and production hardening are separate future milestones.