acm-pca-design.md Section 0: Key Custody Model
Start your analysis document today. Write §0 Introduction and Key Custody Model:
# ACM Private CA Architecture: Leo Provisioning Service
## §0. Key Custody Model
### 0.1 CA Hierarchy Overview
<diagram or table: tiers, validity periods, where each key lives>
### 0.2 Root Key Custody Decision
<ACM PCA managed vs. CloudHSM self-managed — which and why>
### 0.3 Key Access Controls
<IAM policies, CloudHSM users, or ACM PCA resource policy>
### 0.4 Blast Radius Analysis
<If issuance CA key is compromised: how many certs? how long to rotate?>
Quality bar: this section should be readable by your security team lead
without prior PKCS#11 or HSM knowledge.