I'd add one closing rule to step 9: a detect or mitigate action is done when someone has seen it work, not when the PR merges.
Your certificate alert is a good example. It can ship, pass review and still never page anyone, because it reads the wrong secret store or routes to a channel nobody watches. Issuing a 10-day certificate in staging and confirming the page reaches on-call is a short exercise, and it gives the action item something to link when it closes: the alert that fired.
That link pays off later too. When a future incident lists a missing alert as a contributing factor, and an older postmortem already has an action item for that alert, the closing evidence tells you whether it was tested or only merged.