Use NO KEY UPDATE for identity locks so audit foreign-key checks can proceed while identity writers remain serialized. Preserve task-before-run ordering, company scoping, and foreign keys.
Verified with PostgreSQL concurrency regressions, focused tests, typecheck, build, and full CI.
Co-Authored-By: Paperclip <noreply@paperclip.ing>