Android devices use dm-verity to make sure that the OS hasn't been tempered with - bootloader checks signature of first stage bootloader on flash and that one checks the next stage all the way to kernel and contents of the flash.
This prevents all kinds of attacks where people could push things onto your phones OS. In desktop world, this is known as "secure boot".
Many devices will, however, only accept OS signed by their manufacturer - e.g. Apple iPhones/iPads will only boot an OS signed by Apple and noone else. This is why you can't ever run Linux on an iPhone or iPad.
In Android world, many manufacturers allow users to disable this verification (known as "bootloader unlock"). This allows running of non-manufacturer provided OSes (e.g. LineageOS, GrapheneOS, etc.). However, except for Pixels, they don't allow you to supply your own signing key to the bootloader, so you lose the security benefits of the secure boot chain and open yourself to big set of security attacks against your phone.
On a Pixel (at least some of them), you can provide your own signing key and reenable secure boot when installing another OS.