The "get it installed or rescued" use cases: The most universal image
for this is net install ISO, so one of those being the blocking image
to test on baremetal makes sense to me.
The "live + read only + verifiable" use cases: I'd say either
Workstation or Security spin could meet this use case. Since Security
spin is not a release blocking image, the criterion could say it's met
if either the Security spin or Workstation can boot UEFI and BIOS
computers using optical media. (Security spin benefits from all three