Note in README and design that lossless restore makes revocation
IdP-authoritative: a member revoked in the vault is re-activated on the next
sync if the IdP still shows them active, and a leaked token can reinstate any
previously-confirmed member. Document token-management audit events and the
omitted-vs-empty members and externalId-uniqueness semantics. Add TODOS.md
tracking the deferred follow-ups (config-gated denial tests, live Entra
validation, coverage edges, perf backlog, upstream ip_constant lints).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>