yeah, so it should also be signed by an authority key
the current primary key should become an authority key and only get used to sign metadata and things like nip-05 messages and kind 0 user metadata - and that itself is another example of a place that could have multiple subkeys specified
also, they could maintain actual HD path coordinates in them as well so you only need the primary key and the world also has the necessary pubkeys that derive out of them