plan_signing_changes
Plan a single Apple signing lifecycle action—certificate, device, or profile—while keeping CSRs under an approved root and rejecting private keys. Preview affected profile counts before applying the exact approved operation.
Instructions
Plan one explicit sensitive certificate, device or profile lifecycle action. CSR files stay under an approved root; private keys are rejected. Destructive revocation/deletion is separate and shows affected profile counts. Apply requires the exact approved operation.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| root | Yes | ||
| action | Yes |