285 credentials, 5 with known owners: the mess before an org's first production agent
New-Resource-4943 · reddit · 2026-09-17
A founder building a company run by agents instead of employees inventoried credentials before deploying his first agent (which provisions VPSs and needs real credentials on day one). The audit found 285 credentials, 180 in production, only 5 with known owners, plus 5 Cloudflare Super Admin grants with 2FA off, 3 tied to personal Gmail accounts. His open question: should each agent get its own secrets workspace in self-hosted Phase, or share one with scoped access? Per-agent is clean at 3 agents but means 30 things to rotate and offboard at 30; shared is simpler until one compromise reads everything. He asks practitioners which path they chose and at what agent count they regretted it.
More from coding & agent
- Rowboat, an open-source multiplayer work assistant, hits 17.9k GitHub stars — alexcovo_eth · 2026-09-18
- omitClaudeMd: true cuts Claude Code subagent context by 88% in developer test — daniel_mac8 · 2026-09-18
- jev-plays-pokemon: Watch an AI beat Pokémon Red live in your terminal via npx — TheMoonMidas · 2026-09-18
- Dev builds Assist: hold Option, annotate and speak to send screenshots straight to Codex — _plutonic · 2026-09-18
- Grok Build v1.0.35 ships MCP reporting fixes, faster memory UI and lighter syntax highlighting — mark_k · 2026-09-18
- Platformatic open-sources secure-eval-worker for permission-scoped JS sandboxing in Node.js — threepointone · 2026-09-18