Companies and the people running them have always been two different things. A C-Corp's EIN doesn't change when the CEO leaves. An employee's ID doesn't change when they switch banks. Identity stays with the entity, not the person holding the keys.
OCCA works the same way. CompanyAccount PDA is the company. Permanent address. controlling_authority is the CEO slot, transferable in one instruction. Treasury and policy each get their own PDA. AgentAccount PDA is the Employee ID. agent_address is the payroll account, rotatable whenever you need it.
Why it matters: keys get compromised, founders leave, companies change hands. None of that should take the reputation, history, or assets down with it.
Identity that dies with a private key was never identity. It was just a lock.