Deterministic first, model last
Most answers are already in local state: running, failed, automated, interrupted, or carrying the agent's own status footer. ThreadBear reads a read-only local index and decides without a model call, and every classification records how it was reached — runtime, structured_error, automation, interruption, footer, luna, or unknown — so provenance is auditable rather than implied.