4/ Here's the honest part: once added, a viewer can't be removed. Not a bug. A logical reality. If they could already decrypt and store the value, revoking access wouldn't undo that.
The system doesn't pretend otherwise. For sensitive audits, you create a new handle with a fresh ACL. Access isolation at the application layer.