← Inspection rules

SEC-005 / v1.2.0 / 2026-10-02

Reconcile credential inventory and revocation

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Suspected credential exposure, compromise, or supplier incidents. Routine checks use metadata inventories and revocation procedures.

Where to look first

  • Metadata inventory of keys, tokens, service identities
  • Revocation results, consumers, post-revocation audit logs
  • OAuth expiry, refresh-token reuse, and revocation of unused integrations

Inspection steps

  1. Reconcile all affected IDs, owners, consumers, and revocation methods, including identities believed unused.
  2. Verify issuance and revocation separately; escalate unknown accounts and persistence for investigation.
  3. Inventory long-lived integration and refresh tokens; verify expiry, reuse controls, and rejection after revocation through metadata and authorized test evidence.

Remediation direction

  • Prepare staged consumer migration and revocation; production revocation and permission changes require existing authority.

Evidence required for completion

  • Record revocation for every affected identity and rejection tests or provider revocation evidence.

Limits and unverified scope

  • Issuing a new key alone is not completion. Never provide leaked keys to an AI; missing access means unverified.