The key identities a grant answers to: its key now, and every key it was rotated from under section 6.1.1 (keyLineage, written by gnap_grants.ts), so a rotation is never read as a removal.
keyLineage
gnap_grants.ts
the grant
the identities, possibly none
The key identities a grant answers to: its key now, and every key it was rotated from under section 6.1.1 (
keyLineage, written bygnap_grants.ts), so a rotation is never read as a removal.