Credential rotation
Rotating credentials, API keys, or tokens requires explicit authorization from a human operator. Autonomous agents may detect expiration or exposure, but they must not perform the rotation without human approval. Document the rotation request indocs/proposals/active/<id>/ITEMS.md and obtain consensus before proceeding.
Banned artifact classes
Do not commit the following Class 3 and Class 4 artifacts to git:
If you find these files in your working tree, add them to
.gitignore and remove them from history before opening a PR.
ARCHW1Z gate
Every merge tomaster must pass the ARCHW1Z gate. The gate consists of two mandatory scripts:
0. If either fails, the merge is blocked. See the CI gates reference for full details.
Security remediation process
When a security issue is found, follow the process indocs/SECURITY-REMEDIATION.md:
1
Report
Open a private proposal or alert the human operator. Do not post secrets in public chat.
2
Assess
Classify the severity and identify affected files, credentials, or agents.
3
Remediate
Rotate exposed credentials, remove artifacts from git history, and patch the vulnerability.
4
Verify
Run both CI gates and confirm no residual exposure remains.
Tracked findings
Confirmed credential exposure findings are recorded indocs/CREDENTIAL-EXPOSURE.md. Review this file before proposing changes to secret handling or authentication flows.
Next steps
- Read the CI gates reference for the full gate checklist
- Follow the Proposal process to request credential rotation