I suspect privacy is the most malleable point on the trilema.
You can't compromise on security while still being usable.
You can compromise on decentralisation, and everything will work. Your gym, bank and employer already have you in a centralised identity system. Compromising on decentralisation fails the other way. There's no way of holding the centralised body to its side of the compromise. If worldcoin controls identity, they'll control downstream of identity too.
For actual solutions, I think it's better to think of specifics applications. Once you get specific, there are often more options.
Take DAUS governance. Say you want to implement a voting system that requires identity for sybil resistance. Maybe it's ok if voting requires a limited compromise on privacy. You expose just enough information to demonstrate eligibility, then vote. If privacy is more important that voting, you can maintain privacy instead.