Digital public services must control fraud, error, and consequential mistakes without excluding legitimate users. Existing reasonableness, proportionality, sludge audit, screening, and digital-burden approaches identify relevant principles but do not specify how incomplete evidence about one friction should change its operational status. This conceptual analysis develops behavioral risk–friction fit (BRFF), which treats justification as a time-indexed, revisable state. It separates design form into parallel claimed-mechanism and group-conditioned burden pathways, assessed through protection- and user-side outcomes before normative status. After a legal-authority precondition outside the trivalent structure, three behavioral criteria operate in a conditionally iterative procedure. Gate 1 tests incremental protection. Gate 2 screens lower-burden alternatives across primary and all material secondary protection outcomes using prespecified protection-loss margins (ε_k). G3(f) evaluates the current design, whereas G3(a|f) evaluates a protection-screened candidate. Candidate Found—Pending G3(a|f) is an intermediate routing state; completed behavioral assessments return Pass, Fail, or Unknown and map asymmetrically to four statuses and actions. Protection margins apply only to protection outcomes; access and rights floors remain non-compensable. Only controls with at least Grade C support may be used provisionally, with safeguards, evidence milestones, and constrained renewal. A worked SNAP application converts a measured access gain and unmeasured integrity effect into a testable action. Two hypothetical records demonstrate completed Justified and Sludge paths without treating illustrative values as evidence. BRFF contributes an auditable evidence-to-status transition framework with empirically testable behavioral inputs and revisable decision consequences.