{"id":"cross-service-kms-irrevocability-creates-permanent-operational-constraints","text":"Multiple AWS services make KMS key decisions irrevocable through different mechanisms — DynamoDB archives data after 7 days if a CMK is disabled, CloudTrail Lake KMS keys cannot be changed or removed — creating a cross-cutting pattern where encryption key management permanently constrains operational flexibility across unrelated service tiers","truth_value":"IN","source":"","source_url":"","source_hash":"","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"cross-service-kms-irrevocability-creates-permanent-operational-constraints","truth_value":"IN","reason":"premise"}]}}