Membership and key rotation
Membership changes are represented by authenticated epochs. Enrollment, retirement, replacement and key rotation advance the governed membership state and invalidate stale authority where required.
Applications should persist membership heads and certificates when peer continuity matters. Never reuse an old peer key as evidence of a new lifecycle state.