Use case · By risk
Track the config change without copying the secret
For developers changing credentials or environment configuration.
A config task needs a variable name and a responsible person. It does not need the credential itself. Create a Work task with the variable names, target environment and owner. Link non-secret setup documentation and record completion in a comment.
Secrets and env files
Update the webhook configuration
- 1
Next action
Ask the environment owner to set the value
- 2
Context
Environment and variable name
- 3
Evidence
Non-secret setup instructions
What to put in the task
- Assign the task to the person responsible for the next action.
- Add evidence links and explain what they show in a comment.
- Update the task when the work changes so the next reader has the current state.
Before you rely on it
Command interception depends on your client's hooks or proxy; see the setup guide for Claude Code, Codex, Cursor and other MCP clients.
- Work is not a secret store. Do not paste credentials into task descriptions, comments or evidence links. File interception depends on separately configured client controls.
- Work must be enabled for the selected account, and you need permission to read or change the task. Security access and device setup are separate.
Related use cases and clients
By riskProduction changesThe person reviewing the release can read the proposed change and its supporting evidence in the same task.By clientCursorSetup requirements for Cursor.By clientAny MCP clientSetup requirements for any MCP client.
All use cases →