> For the complete documentation index, see [llms.txt](https://corpus-core.gitbook.io/iot-colibri-stateless/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://corpus-core.gitbook.io/iot-colibri-stateless/applications-and-colibri-products/use-cases/device-lifecycle-and-maintenance.md).

# Device Lifecycle and Maintenance

* **Secure Device Provisioning and Onboarding**\
  Initial provisioning and commissioning rely on verifiable authorization state rather than manufacturer-operated onboarding services. Devices validate provisioning credentials and configuration parameters locally, ensuring that onboarding remains possible even if centralized services are unavailable. This supports decentralized manufacturing, installation by third parties, and long-term maintainability independent of vendor infrastructure.
* **Verifiable Software and Firmware Updates**\
  Devices validate update authorization and integrity before applying changes, independent of the update delivery channel or service operator. Update decisions are based on verifiable state rather than trusted distribution servers, reducing the risk of mass compromise through centralized update infrastructure. Devices may defer updates until proofs are available, supporting controlled rollout and offline update scenarios.
* **Decommissioning and End-of-Life Handling**\
  Devices enforce deactivation, revocation, or transfer rules through verifiable state when reaching end-of-life. This reduces security risks from abandoned, repurposed, or resold hardware by ensuring that operational status and authorization are explicitly verifiable. End-of-life handling becomes enforceable without relying on continued support from the original manufacturer.
