Redacted first
Protected values stay hidden unless the workflow truly needs them.
Minimum scope
Grants can be limited to one action, one task, or one agent key.
Revocable + auditable
Reusable grants can be revoked and grant events are recorded.
Protected categories
Passwords & passcodes
Authentication secrets and password-like fields.
OTP & verification codes
One-time and verification values.
Payment & card fields
Card numbers and payment-sensitive values.
API keys & secrets
API credentials and secret tokens.
Auth & access tokens
Authorization values exposed in page fields.
Other sensitive fields
Protected values outside the named categories.
Grant lifetimes
Reusable agent grant
1
Choose the agent key
Select the exact reusable key.
2
Choose one category
Grant only the data class the workflow needs.
3
Optionally restrict the domain
Narrow the grant further when possible.
4
Review and revoke
Use the dashboard grant list and audit trail.
Permissions
See the broader authority model.
Task semantics
See how durable state protects retries.