Skip to content
Gated

Credential boundaries

Map the credentials outside your approval path

Inventory alternate provider authority without collecting secrets, then state exactly which agent actions the pilot controls.

Gated · · Private-preview evaluation guide

Draw the route to GitHub

An approval workflow needs a route that respects the decision before using provider authority. Map the route in plain language: the agent submits an explicit request, Gated evaluates policy, a person approves when required, and explicit execution uses the controlled GitHub App path. Name who owns each part.

Then ask where the agent could reach GitHub by another route. A direct provider credential can bypass Gated even if the project instructions say to use the controlled workflow. A skill guides tool use; it does not automatically intercept unrelated tools, shell actions, or network access.

Inventory authority, not secret values

Review the environment in which the agent actually runs. Include configured connections, local tools, environment variable names, credential stores, and automation the agent can invoke. Record the credential type, owner, provider scope, accessible repositories, and where it is available. Never copy the credential itself into the inventory.

An unfamiliar connection should remain an open question until its owner explains the authority and access path. A credential being expired or absent in one shell is not enough to establish that every agent session lacks it. Date each observation and identify the environment it describes.

  • Direct GitHub connections and provider tokens available to the agent.
  • Local GitHub tooling and credential helpers in the runtime environment.
  • Other tools or jobs that can use GitHub authority on the agent’s behalf.
  • Repository automation that branch creation could trigger.

Resolve the boundary with the credential owner

For each route, decide whether it is required for the selected pilot and whether it remains outside the controlled path. Ask the credential owner to handle any access changes through the team’s normal process. Do not revoke a shared credential merely because it appears in an inventory; other workflows may depend on it.

If an alternate route remains available, document the limitation prominently. You can still evaluate request clarity and receipts, but cannot infer that every agent write must pass through Gated. Unresolved authority should narrow the claim the team makes about the pilot.

Recheck when the environment changes

Repeat the inventory after a new connection, agent configuration, or runtime environment is introduced. The useful output is a current list of accessible routes and their owners, not a one-time declaration that the agent is contained. Preserve evidence references in an access-controlled team record and redact details before external sharing.

Gated’s private preview remains one uniquely named branch at an exact existing commit in a selected non-critical repository. Passkey approval and provider readback matter within that path; they do not remove external credentials. Use the worksheet to make this boundary understandable to a reviewer before a pilot begins.

Evaluate one controlled GitHub workflow

Read the verified GitHub scope and pilot entry steps. Join the update list if you want to follow the preview. Signup does not grant immediate access or commit you to a purchase.

Private-preview updates · Joining does not grant immediate access