Skip to main content

Secrets hygiene

  • Do not put PATs, API keys, WorkOS secrets, or .env values in this runbook or in screenshots in docs.
  • GitHub bot accounts (PL-Morgan, PL-Remy, etc.) use classic repo PATs scoped to org access — store only in secure agent secret fields / password managers, never in markdown.
  • Prefer documenting variable names and owners, not values.

See also Working agreements and Deploy & environments.