Soft-delete. The Stakeholder record is preserved with events.revokedAt set; subsequent GET .../{stakeholderId} returns the record with status semantics indicating revocation. List endpoints filter out revoked records by default; pass ?includeRevoked=true to retrieve historical entries (e.g., for compliance audit). Fires Stakeholder.Revoked. Cannot revoke the only active Principal while the Account state requires one; create or promote a replacement isPrincipal=true Stakeholder first (409).
Requires a session with recent MFA step-up for StakeholderChange. If step-up is missing or expired, this operation returns 403 StepUpMfaRequired; create and verify an MFA challenge at /v3/platform/mfa-challenges with requiredFor: "StakeholderChange", then retry.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
204Stakeholder revoked (soft-delete; record preserved historically)