Fields for this record
Role; system; controlled secret location; approved users; replacement role; review date.
What to record
Record account owners, recovery locations and approval roles without secrets. Keep the source of each fact, the decision owner and the next review date.
Safe handling
Keep passwords, wallet seeds and private keys only in their controlled store. The manual should point to the owner and access process, never reproduce a secret.
Filled illustrative entry
Illustrative ownership map: the domain has a registrar-owner role; the recovery store has two authorized custodians; the service has a primary and backup maintainer. The entry lists roles and locations, never secret values.
Outcome
A second maintainer can understand the decision, find the responsible person and see what remains unconfirmed.