# Reconcile secret rotation consumers

Illustrative planning brief; no automatic product import.

Illustrative planning case: A credential rotation is planned, but one background worker uses a separately stored old value.

## Decision

Inventory every credential consumer before revoking the old value.

## Owned work

- Map consumer locations
  - Owner role: Release investigator
  - Acceptance evidence: API worker and scheduled job each identify their configuration source.
- Prepare overlap verification
  - Owner role: Migration engineer
  - Acceptance evidence: All consumers demonstrate the new credential without exposing it.
- Review revocation readiness
  - Owner role: Release reviewer
  - Acceptance evidence: The old credential is revoked only after consumer evidence is complete.

## Workflow

1. List API, worker and scheduled-job credential references without copying secret values.
2. Verify the new credential in each consumer and record required reload or restart evidence.
3. Ask the reviewer to reconcile the consumer inventory before revoking the old value; unresolved consumers keep the gate open.

## Judgment

Follow the actual credential platform's validated rotation procedure.


## Filled illustrative release coordination record

The synthetic API picks up the new value immediately, while the nightly worker loads credentials only at startup. The plan restarts that worker in its reviewed window and confirms successful use before old-value revocation. The handover packet stores consumer names and verification status, never secret contents. One green API request does not close the rotation.
Decision: Inventory every credential consumer before revoking the old value.
Review boundary: Follow the actual credential platform's validated rotation procedure.
This example uses synthetic conditions. Replace its observations with project evidence and record any changed assumptions before adopting the plan.


## Working artifact

- Service operator / API credential reference and verification status / Confirms new value is active
- Worker operator / Restart window and successful job evidence / Confirms startup reload completed
- Release reviewer / Consumer inventory without secret values / Accepts revocation gate or records unresolved consumer


## Workflow questions

### Should the old secret appear in the task?

No. Record secret references and consumer evidence without storing credential values in planning artifacts.

### What if a consumer cannot be verified?

Keep revocation pending or explicitly review its service interruption risk with the responsible operator.

## Product connection

Use the manual work brief to discuss task ownership, review evidence and next actions in TeamBoost. Release execution remains a separate project workflow; the download performs no deployment or import.

Confirm account availability before adopting this manual outline.
