Each installation uses an installation-scoped identity. Rotation registers a replacement key for the same installation and records the lifecycle event before the prior key is retired.
Revocation disables the selected key, installation, or relationship according to scope. A revoked identity cannot authenticate new Gateway traffic, and new action requests fail closed.
Removal does not erase history. Existing receipts and lifecycle events remain available under the configured retention policy. The resulting connection state is visible in Connections and the Bridle Operator Console.