How many people would have to lose their keys before a vault is unreadable by anyone? If the answer is one, you have a problem that no amount of cryptography will fix.
So the tool watches:
It warns when a vault drops below two members holding genuinely distinct keys.
Removing the second-to-last member requires you to type the vault name to confirm, and it prints exactly who would be left. This is the loudest warning in the product.
A vault created with one member is flagged immediately, with a suggestion to enroll a second device or a second person before putting anything valuable in it.
secretsmgr doctor fails if any vault is below policy, so you can catch it in CI rather than during an incident.
Enrolling a second security key for yourself is strongly recommended and never required. It covers travel, a dead battery, and the awkward case of the vault only you use.