I know it’s not the answer, but I wanted to point out that by starting to use Qubes, I decided previously to change my computer habits. That means that i never use any AppVm for any work, but DispVMs, and then store the files in corespondent offline qubes.
Then, never attach any external USB to a non-dispVM
Then, no net on boot, meaning sys-net’s autostart turned off.
Then, for each template (meaning dvm templates) and AppVMs default NetVm is none.
Then, when leaving the computer unattended, shutdown sys-net and screenlock only, power management disabled.
So, it’s practically impossible for me to get into your situation.
It’s just my so-far vision of “security-meets-conformity”.
Whenever “I’d like something to” or “it would be great if this could be” happens, I tend to step back and ask my self if it’s about conformity and not about usability, and what the possible tradeoffs are against security. If there’s no answer, without exception I interpret it restrictively - it’s against security.