Whether the durable monitor may ask a model what to do about a terminal
failure the structured rules did not settle.
Off by default, and not merely as a courtesy: enabling it lets a
background daemon send monitor context to a model on its own schedule,
with no one watching. Nobody watching is not permission, so this is a
decision a user makes once, explicitly, rather than something an upgrade
makes for them.
The bound on how often it may ask is NOT here: one proposal per
observation cycle is an invariant of the design, not a knob (see
mur_core::monitor::resolver). A tunable would let a user turn a bounded
feature into an unbounded one.