← Operations Web Function

Govern Web Access Skill

CANDIDATE DELEGATE EXISTING CANONICAL · Operations Web Function 0.1.0. Request, grant, verify, review, rotate, and revoke least-privilege access for CMS, hosting, DNS, repositories, analytics, tag management, Search Console, forms, and web operations without exposing secret values. Use for onboarding or offboarding, missing access, credential rotation, access audits, agent connector setup, expired permissions, or when plaintext credentials appear in tickets, spreadsheets, files, or public-bound artifacts.

Canonical owner: blitzmetrics-skills:client-access-checklist · Task registration: NOT_A_BOUNDED_TASK

Broader definitive hub · Exact Task Library page: NOT_A_BOUNDED_TASK

Download the complete plugin · Source skill SHA-256: d012fc6cf5c9efee277f4f58f85debc5e8f5e4d3b56e920230d88e5512bb0943

Candidate source: dennisyu/blitzmetrics-skills · commit: PENDING_MERGE · path: skills/govern-web-access/SKILL.md

This is a Web-specific lifecycle profile around canonical client-access-checklist, not a second access-intake method or credential register. That canonical skill owns collection and the initial access gate. This profile owns expiry, periodic review, rotation routing, revocation, and their receipts. Manage capabilities and references, not copied passwords.

Access workflow

  1. Consume the approved access inventory/gate produced by canonical client-access-checklist; do not collect the same facts into another register.
  2. Identify the job, target scope, requested capability, principal, duration, and business reason.
  3. Compare the request to the job's permission ceiling. Reject excess capability.
  4. Reuse an approved connector or vault reference when possible; never move the secret value into context, chat, examples, or receipts.
  5. Obtain the policy-required approver and record the approval digest.
  6. Grant the narrowest role, property scope, and duration that can finish the job.
  7. Verify the capability with a harmless read or bounded test.
  8. Record grant time, expiry, review time, source system, principal, target scope, and credential reference in the canonical access record.
  9. Review on schedule and after role, property, vendor, or incident changes.
  10. Revoke and independently verify revocation. Link the revocation receipt.

Secret exposure

If plaintext credentials or credential-bearing files are discovered:

Definition of Done

The required job can use only the approved capability; the secret remains in the approved provider; access has an owner, expiry/review, and scope; the verification receipt exists; and unneeded access is revoked.

From the plugin root, use schemas/access-manifest.schema.json for the record shape. Route property coverage changes to $inventory-web-properties and production rotations through $change-web-production.


This is a generated candidate implementation page, not automatically a definitive article or accepted Task Library task. It delegates to the named canonical owner until reviewed registration and merge receipts exist.