In the CA and RA context too, an externally generated key pair is transferred and loaded securely with the private key kept secret and the public key's integrity assured, and once injected it is unavailable for any other POI.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.