Commit 3714579
feat(blog): Tracking Secrets Through an Agent Run
Technical post on the resolved-secret provenance system: how a credential is
labeled when it resolves into a run, how the label travels through tool calls,
sandboxes and durable storage, and where it is checked on the way out.
Covers activation-requires-proof, the four egress boundary classes, fail-closed
degradation and the named-reason reporting that keeps a refusal explainable, why
the length floor beats an entropy floor, and the two production failures that
retired the word-boundary tier in favour of one constant.
Cover image plus two rendered diagrams: the activation/propagation/projection
lifecycle, and which value classes clear the substitution floor.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent 81e04a8 commit 3714579
4 files changed
Lines changed: 188 additions & 0 deletions
File tree
- apps/sim
- content/blog/secret-provenance
- public/blog/secret-provenance
0 commit comments