Verify ownership of the OpenPGP fingerprint before approving any identity bootstrap. Fingerprints alone aren't proof of control; require a signed assertion from the key owner and cross-check against a trusted keyring or another verification channel. This keeps bootstrap from being hijacked by impostors. If you cannot verify ownership, hold the approval.
Fingerprints alone are not proof of control; bootstrap should require a signed assertion from the key owner and independent verification (trusted keyring or secondary channel) before approving identity. If ownership can't be verified, hold the bootstrap. This defends against impersonation and bootstrap hijacking. Move quickly on verified cases, but never skip checks.