A number of concepts must be known in order to understand this document.
Zones and Authentication Keys are essential for understanding this document, but they are also beyond its scope.
As zone signatures expire, the zone must be re-signed with new keys. The process of generating new keys and re-signing the zone is called zone rollover. There are several rollover schemes (e.g., Double-Signature Scheme and Pre-Publish Scheme) that are used for various purposes. These schemes are described in Chapter 10, KSK Rollover (Double-Signature Scheme) and Chapter 9, Current ZSK Rollover (Pre-Publish Scheme).
The Key-Tag Table is a record of zones, the zone's keys, attributes of the keys, and expiration dates. This may be kept in any usable form -- computer file, notebook, etc.
Keyrec files function as Key-Tag Tables for DNSSEC-Tools utilities. They can be hand-edited, but the DNSSEC-Tools update them automatically.