Provisioning and lifecycle
Create physical and v3 identity, unique credentials and ACL, bind asset mapping, validate inventory and then enable commands. Device writes D2P/reads P2D; ingest reads D2P; publisher writes P2D. Rotate by validating new credentials before revoking old ones.