I'm probably just missing it, but I'm not seeing a step where the firmware itself is locking itself to an individual RPi, which would mean you can simply change out the USB drive itself and boot whatever you want.
Does it do that transparently, maybe when the keys are enrolled?
Sure, but also normally you aren't manually installing the relevant firmware. There's different semantics when the 'firmware' lives on the same block device as your root filesystem.
Does it do that transparently, maybe when the keys are enrolled?