Some operations should never be one person's keystroke. Creating a root is the canonical example: the moment of its birth is the moment its trust is easiest to subvert and hardest to audit afterwards.
For those, plan a ceremony: a named key operation (root-genesis or rollover) that cannot execute until a quorum of named participants approves. Plan it — participants plus quorum — then collect approvals: only named participants, once each, and the creator's plan is not an approval. Before quorum, execution is refused; there is no override.
Every step lands in a hash-chained transcript kept forever — for aborted ceremonies too — independently verifiable and mirrored into the main audit log. Planning, executing or aborting requires ca-officer or system-admin; approving requires being a named participant and nothing else. A custodian is chosen for a particular ceremony and may hold no CA role at all — deliberately.
Now I can make a root's birth a witnessed event, not a keystroke.