ctrlrun.Principal — class, defined at src/ctrlrun/action.py:139
claims, issuer and expires_at are what an IdentityProvider verified (SPEC-v0.3 §2.1).
None of the three is part of the canonical form (§2.2): an approval binds to an action hash,
and a hash that moved when a token rotated would invalidate it for a reason no human could
see and no agent could fix.