One active owner
A normalized handle, identity identifier, or wallet cannot silently belong to two active principals.
The registry is the controlled record of which handle, identity, wallet, device, service, role, and policy references belong together. It rejects conflicting ownership rather than guessing from similar names.
A normalized handle, identity identifier, or wallet cannot silently belong to two active principals.
Handle-to-identity and identity-to-handle results must agree, including the wallet binding used by account login.
Issuance, migration, suspension, recovery, replacement, and revocation need timestamps and an approved cause.
Status changes preserve the record. Replacement identifiers point to their history rather than rewriting it.
Repeating the same approved operation produces the same binding; a conflict fails without partial mutation.
Explanatory and approved resolution surfaces stay narrow. Registry mutation remains authenticated and audited.
Check handle normalization, identity uniqueness, wallet checksum, and existing bindings.
Preserve the pre-mutation state and record the intended migration.
Write identity, ONS, wallet, and account references as one approved relationship.
Resolve both directions, authenticate, create a session, and confirm restart persistence.