Agreed. And the thing both approaches share is that they assume a root you still control. Backups recover the same root, delegation hands off from a working one. Neither helps once the root itself is gone, because there’s nothing trusted left to sign the handover. That’s the part we just design ...