A finalized run cannot have its methodology silently re-declared. Per
AC5 (soft-lock with audit trail; methodology change creates new run),
callers check this flag before mutating methodology-affecting state on
a prior run; if TRUE, they fork via clone_run_with_new_mode.