One of the cleanup tasks not currently directly integrated in the proposed workflow is the ability to tell the old MDM that the computer now has tooling from the new MDM and it's safe to free up its seat (there's no 'removeFramework' capability I'm aware of that can be triggered server-side). While it adds risk to remove all agent hooks in the old MDM too soon, this already proxies an API token with creds to perform actions and integrates a secret to prevent misuse.