Revocation and delay
Taking authority back, and making sure there is still time to.
Two different kills
Revoking a mandate stops spending under that mandate. Revoking an identity stops that key entirely. Both exist because they answer different incidents: a budget you no longer want is not the same problem as a key somebody else now has.
The agent's identifier is its public key, so without an identity-scoped kill a stolen key stays valid for as long as its disclosure stays fresh. Identity revocation is published as a status list and resolved by anyone checking.
Revocation only helps if someone notices
A mandate is standing authority: a cap that persists across many payments with no human check in between. Revocation is the defence against a compromised one. But without a delay, a compromised mandate drains to its cap faster than a revocation can propagate, and the status list is defeated by speed rather than by any flaw in it.
So settlement is delayed in proportion to value. Small payments move immediately. Large ones wait long enough that noticing is possible. The model is pure: given the parameters, the mandate, the value, the instant and the action, anybody can recompute the delay and disagree with it.
Stopping everything
The kill switch freezes the settle path. Engaging and releasing are signed as distinct operations, so a credential captured for one cannot be replayed as the other. Circuit breakers trip automatically and are cleared deliberately.
Both take the operator credential and both require a rationale. Use them when something is wrong and work out what happened afterwards, from the record.