1. Start with the custody decision and threat model
Treat custody as a control, evidence and recovery decision. Map every legal entity, workload, environment and person or service needing authentication. Model key copying, support-bundle leakage, staff departure, vault failure and abrupt provider exit; assign detection, containment and recovery. Official fact: a KSeF certificate carries identity, not permissions, which KSeF checks server-side. Recommended control: separate business authority, technical custody and monitoring, with dual approval for export or recovery. Provider, customer or shared custody may be appropriate when evidence matches risk. Do not make a personal certificate a shared integration credential: official guidance restricts its download and use to that person.