Create, list and revoke, with no update: editing what a credential already deployed in CI can do, with no record of what it could do before, is worse than requiring a rotation. Revoking a token that is not yours answers not-found, since a 403 confirms it exists. The audit actor stays the human and names the credential alongside, so a person clicking and their CI job are told apart.