Govern Web Access Skill
CANDIDATE DELEGATE EXISTING CANONICAL · Operations Web Function 0.1.0. Request, grant, verify, review, rotate, and revoke least-privilege access for CMS, hosting, DNS, repositories, analytics, tag management, Search Console, forms, and web operations without exposing secret values. Use for onboarding or offboarding, missing access, credential rotation, access audits, agent connector setup, expired permissions, or when plaintext credentials appear in tickets, spreadsheets, files, or public-bound artifacts.
Canonical owner: blitzmetrics-skills:client-access-checklist · Task registration: NOT_A_BOUNDED_TASK
Broader definitive hub · Exact Task Library page: NOT_A_BOUNDED_TASK
Download the complete plugin · Source skill SHA-256: d012fc6cf5c9efee277f4f58f85debc5e8f5e4d3b56e920230d88e5512bb0943
Candidate source: dennisyu/blitzmetrics-skills · commit: PENDING_MERGE · path: skills/govern-web-access/SKILL.md
This is a Web-specific lifecycle profile around canonical client-access-checklist, not a second access-intake method or credential register. That canonical skill owns collection and the initial access gate. This profile owns expiry, periodic review, rotation routing, revocation, and their receipts. Manage capabilities and references, not copied passwords.
Access workflow
- Consume the approved access inventory/gate produced by canonical
client-access-checklist; do not collect the same facts into another register. - Identify the job, target scope, requested capability, principal, duration, and business reason.
- Compare the request to the job’s permission ceiling. Reject excess capability.
- Reuse an approved connector or vault reference when possible; never move the secret value into context, chat, examples, or receipts.
- Obtain the policy-required approver and record the approval digest.
- Grant the narrowest role, property scope, and duration that can finish the job.
- Verify the capability with a harmless read or bounded test.
- Record grant time, expiry, review time, source system, principal, target scope, and credential reference in the canonical access record.
- Review on schedule and after role, property, vendor, or incident changes.
- Revoke and independently verify revocation. Link the revocation receipt.
Secret exposure
If plaintext credentials or credential-bearing files are discovered:
- do not quote, display, copy, upload, or feed them to a public generator;
- record only the affected system/type and private artifact reference;
- determine whether the credential is still valid through an authorized private process;
- rotate or revoke through an approved change;
- remove or restrict the exposed copy without destroying required incident evidence;
- scan the intended public allowlist again;
- add a preventive test or publishing gate.
Definition of Done
The required job can use only the approved capability; the secret remains in the approved provider; access has an owner, expiry/review, and scope; the verification receipt exists; and unneeded access is revoked.
From the plugin root, use schemas/access-manifest.schema.json for the record shape. Route property coverage changes to $inventory-web-properties and production rotations through $change-web-production.
This is a generated candidate implementation page, not automatically a definitive article or accepted Task Library task. It delegates to the named canonical owner until reviewed registration and merge receipts exist.
