defineAction gives the model a name,
description, risk, approval requirement, and optional input schema.
The renderer validates the registered name and input schema before emitting a
frozen action event. Approval metadata does not mean the user approved anything.