pub fn remove_authorized_key(device: &str) -> Result<()>
Remove device’s marked block from authorized_keys (the “removable” half of the audit story; used by filament revoke). No-op if absent.
device
filament revoke