handbook: allow scoped credentials for AI agents under review - #5520
handbook: allow scoped credentials for AI agents under review#5520robmarcer wants to merge 4 commits into
Conversation
Replaces the blanket ban in point 5 with a conditional: discuss the use case with another team member, document it, scope to the minimum needed, read only by default, and revoke when done. Admin-scoped PATs and passwords stay prohibited.
This is a problem, if this is the case then it needs to STOP now and be discussed. As part of that discussion we need to understand what "there is legitimate work that needs an agent to hold a token" is and if it really does meet that criteria. This can be discussed when Nick and Jam are back, but all work using tokens must stop until then, it is explicitly against stated policy. |
✅ Deploy Preview for flowforge-website ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
| - **Discuss it first.** Talk the use case through with at least one other team member before you create or share the credential. If you cannot explain to a colleague what the agent will do and why it needs this access, that is your answer. | ||
| - **Document the discussion.** Record who you spoke to, what the agent will be doing, the scope granted, and when the credential will be revoked. Open an [Access / Permission Request](https://github.com/FlowFuse/admin/issues/new?template=access-request.md) issue in the admin repo on GitHub, the same place other access decisions are recorded. A verbal or DM conversation nobody can find later does not count. |
There was a problem hiding this comment.
Step 1 should be to raise the the permission request - and it isn't just there to document the discussion, it is to get approval from leadership.
There was a problem hiding this comment.
I felt someone should discuss it with a team member before asking for permission so to try to mitigate requests being created where they are not needed.
I didn't take requesting permission to be 'just there to document the discussion'. How about if I refer to the Access Control Policy https://flowfuse.com/handbook/company/security/access-control/#access-control-policy-1 if you feel it reads like just a formality rather than an actual permission request?
There was a problem hiding this comment.
Nowhere in the steps you've proposed is 'receive permission' - its just chat about it, document it, do it (with the added guidance you've outlined). It should be explicit that permission is required.
Changed so seeking permission is explicit.
Missed the number from the section in my prior edit.

Description
Rewrites point 5 of "Internal Use of AI by FlowFuse Team Members" in the AI Development and Customer Data Policy.
Point 5 currently bans giving any credential to an AI tool or agent outright. In practice there is legitimate work that needs an agent to hold a token, and a rule that is routinely inconvenient tends to get quietly ignored rather than followed. This replaces the blanket ban with a conditional that is stricter in the places that actually matter.
Under the new wording, a credential may be given to an AI tool or agent only when all of the following hold:
Two things stay prohibited outright, because neither can satisfy "minimum needed":
The net effect is a narrower blast radius than today. The current rule says no, which means the cases where someone does need it happen with no discussion, no record, and no scoping. This makes those cases visible and bounded.
Related Issue(s)
None. Follow-up to #5107, which introduced point 5.
Checklist
Most of the template checklist does not apply to a handbook policy change.
Note for reviewers
@knolleary is the listed policy owner. @hardillb wrote the original point 5 and @allthedoll broadened it during review of #5107, so both have context on the intent being changed here.
The effective date in the header table has deliberately been left at 2026-02-18, matching how #5107 handled an amendment. Happy to bump it if the policy owner would prefer amendments to move that date.