handbook: allow scoped credentials for AI agents under review - #5520
Open
robmarcer wants to merge 1 commit into
Open
handbook: allow scoped credentials for AI agents under review#5520robmarcer wants to merge 1 commit into
robmarcer wants to merge 1 commit into
Conversation
Replaces the blanket ban in point 5 with a conditional: discuss the use case with another team member, document it, scope to the minimum needed, read only by default, and revoke when done. Admin-scoped PATs and passwords stay prohibited.
Contributor
This is a problem, if this is the case then it needs to STOP now and be discussed. As part of that discussion we need to understand what "there is legitimate work that needs an agent to hold a token" is and if it really does meet that criteria. This can be discussed when Nick and Jam are back, but all work using tokens must stop until then, it is explicitly against stated policy. |
✅ Deploy Preview for flowforge-website ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Description
Rewrites point 5 of "Internal Use of AI by FlowFuse Team Members" in the AI Development and Customer Data Policy.
Point 5 currently bans giving any credential to an AI tool or agent outright. In practice there is legitimate work that needs an agent to hold a token, and a rule that is routinely inconvenient tends to get quietly ignored rather than followed. This replaces the blanket ban with a conditional that is stricter in the places that actually matter.
Under the new wording, a credential may be given to an AI tool or agent only when all of the following hold:
Two things stay prohibited outright, because neither can satisfy "minimum needed":
The net effect is a narrower blast radius than today. The current rule says no, which means the cases where someone does need it happen with no discussion, no record, and no scoping. This makes those cases visible and bounded.
Related Issue(s)
None. Follow-up to #5107, which introduced point 5.
Checklist
Most of the template checklist does not apply to a handbook policy change.
Note for reviewers
@knolleary is the listed policy owner. @hardillb wrote the original point 5 and @allthedoll broadened it during review of #5107, so both have context on the intent being changed here.
The effective date in the header table has deliberately been left at 2026-02-18, matching how #5107 handled an amendment. Happy to bump it if the policy owner would prefer amendments to move that date.