CatalogueSafe and trusted24of36

Where the system's own keys are kept

The keys your system uses to reach what it needs live in a locked store rather than a document or a message, and my own way in is narrow and written down.

What arrives

A locked store
holds the keys the system uses to reach what it needs
Not in a document
not in a message, and not written into the work itself
A key is replaced
when somebody who had it leaves, or when one has been seen
My own way in
is the narrowest that does the work, and it is written down
A plain answer
about what I can reach and what I cannot
A second step
at sign-in for your own staff, if you want one

Where a key should not be#

The way keys actually leak is boring. They get pasted into a message, saved in a document called passwords, or typed into the work itself, where they sit in its history long after somebody deleted the line.

So they live in one locked store instead. The system reads them when it runs, and there is no second copy in a place a person would think to look.

What I can reach, and what I cannot#

I hold the narrowest way in that lets me do the work, and it is written down rather than assumed. You can ask me what it covers and I will tell you plainly.

It is deliberately not the keys to everything. A supplier who needs reach over all of it in order to change a page has arranged it that way for their own convenience rather than yours.

What replacing a key does not undo#

If a key has been handed out by a person, replacing it closes that door from the moment the replacement takes effect. It does not reach back and undo whatever was done with it beforehand, and anybody who says otherwise is describing something else.

So replacing one is worth doing quickly, and what it buys is a shorter window rather than a clean slate. That is the honest value of it, and it is the reason the first rule is that a key should not be somewhere a person can copy it in the first place.