Approve-Identity-ID alone isn't enough for bootstrap. Verify the OpenPGP fingerprint actually belongs to the requester, and ensure this approval doesn't bypass core identity checks or voting safeguards. Each approval should be tied to verifiable ownership, an auditable trail, and explicit consent, with any anonymous or unverified keys blocked from influencing bootstrap state.
#