risk is odds x severity; my point is that on 1 and 3 you make this reduce risk on 1, and add severity on 3 trade-off. But that in itself does not change that everything still rests on some key that can gets compromized, which is "catastrophic" regardless and my point in the first place.
The point is that if i fully run your system, and someone steals a main-key, there is this automated infrastructure that inmediately diverts the audience towards wherever the attacker wants them.
Yes i am aware that you can run the scheme without necessarily employing the proxy-logic, which is a scenario i explicitly described
