Main npub could sign for valid derived keys and invalidated ones via an event?
Consistency is a big problem, events do not broadcast