Use case · By risk

Track the config change without copying the secret

For developers changing credentials or environment configuration.

A config task needs a variable name and a responsible person. It does not need the credential itself. Create a Work task with the variable names, target environment and owner. Link non-secret setup documentation and record completion in a comment.

Secrets and env files

Update the webhook configuration

Example content
  1. Next action

    Ask the environment owner to set the value

  2. Context

    Environment and variable name

  3. Evidence

    Non-secret setup instructions

What to put in the task

  • Assign the task to the person responsible for the next action.
  • Add evidence links and explain what they show in a comment.
  • Update the task when the work changes so the next reader has the current state.

Before you rely on it

Command interception depends on your client's hooks or proxy; see the setup guide for Claude Code, Codex, Cursor and other MCP clients.

  • Work is not a secret store. Do not paste credentials into task descriptions, comments or evidence links. File interception depends on separately configured client controls.
  • Work must be enabled for the selected account, and you need permission to read or change the task. Security access and device setup are separate.

Related use cases and clients

All use cases