Your two-tier setup (master list + category-specific) is the right structure. The question is what goes where, and most people get this wrong.
Master list should stay lean obvious intent mismatches that apply universally regardless of niche. "Free", "jobs", "salary", "tutorial", "what is", "Wikipedia". Don't put anything niche-specific in here or you'll accidentally import irrelevant exclusions when you reuse the list across accounts.
Category lists are where the real work happens, and these should be built from actual search term data, not pre-loaded guesses. first two weeks of a new campaign: run it, collect search terms, then build the category list from what you actually saw not what you assumed you'd see. What burns budget in SaaS affiliate is completely different from what burns it in e-commerce.
On automation: the concern is valid but the framing is slightly off. The risk isn't automation itself, it's automation adding negatives without a conversion whitelist. If you build a script that flags potential negatives for review but doesn't add them automatically, you get the efficiency without the traffic risk. Auto-add with a whitelist is also workable any term that has ever converted gets protected regardless of what other signals suggest. Scripts that add negatives purely based on zero conversions or high spend without the whitelist layer are the dangerous ones.
Matchaaaaa's point on ad group level sculpting is worth expanding. With loose match types now, the internal cannibalization problem is real wrong ad group captures the click because intents overlapped. using negatives at ad group level to route traffic to the right ad group is underused and makes a meaningful difference in how efficiently smart bidding learns.
Weeekly search term review is the right cadence. Daily is overkill, monthly is too slow to catch budget bleed early.