Lyra's safety boundary is deterministic code, not a prompt. Configure the fund-control policy and a proposed action below; the verdict is computed by the same pure function that guards the agent on-chain. The model proposes, this disposes.
Permitted, but material-risk — the agent pauses and asks for human approval before it broadcasts, even under YOLO. The deterministic floor sits beneath the session mode.