Throughput arguments are made by whoever is holding the pager — sometimes years after the HSM was bought to make the keys non-exportable. So goca refuses to create a pkcs11-wrapped key until the deployment has accepted the trade in writing: a SecurityPosture document with wrappedKeyCustody.accepted: true and a reason a reviewer reads. The acceptance is versioned, audited, gated by multi-person approval where that is on — and it leaves a residue card on the status board for as long as it stands, so nobody later assumes "we have an HSM" means "the keys are in it".
Three things the gate deliberately does not do. The strict modes need no acceptance — making the safe mode the one with paperwork is how operators end up in the fast one. software custody is not gated either; it is the documented default for evaluation, and the posture is about a deployment that has a device not getting device-grade assurance in name only. And nothing stops signing: the gate is on creating a key, so existing wrapped keys keep issuing — the question returns at the next create or rollover.
Now I can record the wrapped-custody trade as a named, reviewable decision.