The same profile must issue from several CAs — prod/dev pairs, parallel classical/PQC hierarchies. Copy the template and you now maintain two documents that will drift one edit at a time. So don't copy: derive. A derived template's entire document is two fields:
derivedFrom: tls-server-pqc # the master issuerRef: ica-tls-dev # the only thing allowed to differ
It mirrors the master's latest version at resolution time — edit the master once, every derivation follows. Anything else in a derived document is rejected ("edit the master instead"), and derivation is one level deep by design: no inheritance chains, ever. When a derivation needs to start diverging, the console's Convert to standalone makes the divergence explicit and owned.
Now I can share one profile across CAs — and I know the current build's caveat before I depend on it.