# Certificate and Device Identity Ledger
A certificate and device identity ledger binds device identifiers, keys, certificates, signers, enrollment records, renewal or revocation state, and recovery routes into one time-aware register.
## Minimum record
- canonical device and hardware identifiers;
- key or certificate fingerprint;
- issuer, subject, and validity period;
- enrollment tenant or management authority;
- first and last observed timestamps;
- revocation, replacement, and migration history;
- source artifact and confidence tier.
## Purpose
The ledger supports [[Identity Continuity]] without treating a friendly device name, account label, or certificate subject as sufficient proof of custody or authorization.
## Source
[[Index - Stages of Interception#Stage 14 — Account, domain, and identity continuity|Stage 14]] · [[Continuity Ledger]] · [[Recovery Capability Matrix]].