@EvanHahn this seems similar to what `keybase` used to do well; and also reflects the GPG trust levels (that seems good)
Q: in the documentation is the word "should" being used in the RFC 2119 sense?