bdced83b46
Deterministic structural guard blocks every capability-question row (0/126 on all three stress views), never blocks a true action (0/796), declines 196 malformed action rows as ambiguous, and grows no safety leak under compose: sparse alone FA 9 (capQ 1) → guard→sparse FA 6 (capQ 0). Execution eligibility recorded as a deterministic policy boundary, separate from semantic routing and capability selection; next slice returns to the coarse non-action router instead of another pragmatics training run. Task/725.