# Certificate and Device Identity Ledger A certificate and device identity ledger binds device identifiers, keys, certificates, signers, enrollment records, renewal or revocation state, and recovery routes into one time-aware register. ## Minimum record - canonical device and hardware identifiers; - key or certificate fingerprint; - issuer, subject, and validity period; - enrollment tenant or management authority; - first and last observed timestamps; - revocation, replacement, and migration history; - source artifact and confidence tier. ## Purpose The ledger supports [[Identity Continuity]] without treating a friendly device name, account label, or certificate subject as sufficient proof of custody or authorization. ## Source [[Index - Stages of Interception#Stage 14 — Account, domain, and identity continuity|Stage 14]] · [[Continuity Ledger]] · [[Recovery Capability Matrix]].