Service teams never write a VirtualService by hand to get mTLS. The platform gives them defaults; the journeys they own are declaring dependencies and choosing when to go strict.
The rollout controller is an actor, not a tool. It is the only writer of canary weights, so it needs an identity, a permission boundary and a journey of its own.
The auditor's goal is why issuance records keep attestation evidence for 13 months and why every change carries before and after digests.
Journeys drawn in full
Move a service to strict mTLS (view 04): where the mesh's security promise becomes real for a team.
Canary a release at 1% (view 05): where the mesh earns its keep with release engineers.
Contain a compromised workload (view 06): where identity-based design is tested under pressure.
Assumptions
About 250 service teams and 900 releases a week at the design ceiling. Both are planning estimates, not requirement figures.