← Inspection rules
SEC-005 / v1.2.0 / 2026-10-02
Reconcile credential inventory and revocation
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Suspected credential exposure, compromise, or supplier incidents. Routine checks use metadata inventories and revocation procedures.
Where to look first
- Metadata inventory of keys, tokens, service identities
- Revocation results, consumers, post-revocation audit logs
- OAuth expiry, refresh-token reuse, and revocation of unused integrations
Inspection steps
- Reconcile all affected IDs, owners, consumers, and revocation methods, including identities believed unused.
- Verify issuance and revocation separately; escalate unknown accounts and persistence for investigation.
- Inventory long-lived integration and refresh tokens; verify expiry, reuse controls, and rejection after revocation through metadata and authorized test evidence.
Remediation direction
- Prepare staged consumer migration and revocation; production revocation and permission changes require existing authority.
Evidence required for completion
- Record revocation for every affected identity and rejection tests or provider revocation evidence.
Limits and unverified scope
- Issuing a new key alone is not completion. Never provide leaked keys to an AI; missing access means unverified.