Marks a fail-closed operational error from a guarded LM or program call.
Ordinary model, task, and adapter failures may be scored by an evaluator or
optimizer. Budget, route, cost, transport, and explicit cancellation guards
must instead remain fatal across optimization boundaries. A guard inside a
normalized Imp callback should return {:error, exception}; a guard outside
that boundary may raise the exception directly.