It's really not; you've argued extensively with me that the moment a user can run an app with root the whole system is insecure. LOS sadly doesn't ship anything but `adb root` by default (although... they do that, so yes they do ship "user accessible root"), but they're still less hostile about it.
Anyways, since you're here perhaps you can answer my question from the other subthread: If I flash GOS and then flash Magisk on it, how hard is it to stay unbricked? Is it as easy as declining to relock the bootloader once, or is the system going to actively fight me on every boot?