RFC 8901 describes modes for operating a domain with multiple independent signers. We discuss how the setup and dissolve a multi-signer arrangement. We describe our current status for the draft, implementation and testbed. And we will describe future development and some specific problems with algorithm usage and validation.
As it turns out this is the exact same operation for changing name server operators without going insecure.