Cryptographic keys must be replaced when there is suspected or known compromise, when custodians leave their roles, or when the cryptoperiod expires. Replacement must use approved methods.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.