The deploy identity itself holds no standing role: the pipeline federates, activates through PIM, deploys, and expires. Portal changes are not blocked outright — they are detected within 24 hours and reconciled back into the repository, because a control that stops an incident response gets switched off.