- Hardware binding: License.HwBinding (none | fixed | firstActivation).
firstActivation leaves the license unbound until the first activation,
which claims the machine; afterwards it behaves like fixed. Legacy rows
backfilled to fixed when a fingerprint was already set.
- Rebind: POST /panel/licenses/{id}/rebind moves a license to new
hardware (or releases the binding), deactivating existing activations
and re-signing a new version; 409 on revoked/expired. Operator or
company admin. Audited, emits license.rebound.
- Operator management: list, invite, promote and demote operators
(operator-only), guarding self-demotion and the last operator — until
now a second operator could only be seeded directly into the database.
- SDK packaging: CertifiEd.Client is now a proper NuGet package (id,
version, MIT license, README, XML docs, symbols) and gained the
missing public XML documentation.