Pending reissue proposals
Lost-wallet and inheritance reissues always stage here first — a registered beneficiary only ever establishes who should receive a certificate, never whether the triggering event actually happened. Confirm only after independently verifying that off-chain.
Pending revocation proposals
Revoking a certificate is now a two-step proposal, same as a lost-wallet or inheritance reissue — whoever proposes it (an issuer, or you) only stages it here. Confirm only after independently verifying the underlying claim (e.g. confirmed fraud); a revocation cannot be undone once confirmed.
Grant or revoke a role
Role hashes are read live from the contract, never hardcoded — ISSUER_ROLE
and DEFAULT_ADMIN_ROLE below reflect what's actually on-chain.
Emergency pause
Freezes every certificate mint, burn, and reissue execution immediately — deliberately not gated by the upgrade timelock, since the point is stopping active harm the instant it's found, not after the timelock's mandatory delay. Staging new reissue proposals and every metadata-only action (approveSale, registerBeneficiary, grantRole, registerEstate, etc.) still work while paused — those don't move a certificate, and you may still need them while investigating.
Issuer fallback
Emergency escape hatch, not a routine tool. DEFAULT_ADMIN_ROLE can act on any estate/plot/certificate directly, without holding ISSUER_ROLE, so registration and issuance don't stop entirely if an issuer's signers are unreachable or compromised. Prefer the issuer's own dashboard for day-to-day work — these forms take raw hex hashes (no upload/hashing helper here) and every action below still shows up correctly attributed to the estate's real issuer, not admin (see the top-level README's Status section on the access-control fix this depends on).
Multisig queue
Every action above submits here instead of sending directly, since ADMIN_MODE is "multisig". Confirm and execute once enough owners have signed off. Confirmed by mistake? Revoke your own confirmation any time before it executes.
Multisig governance
Adding/removing an owner or changing the threshold only ever happens through this exact same submit-confirm-execute flow, calling back into the multisig itself — there's no separate, faster path to change who controls it. Submitting one of these adds it to the queue above like any other proposal.