--- since: 0.6.0 --- # Security Runbook ## If a credential is exposed 1. Revoke/rotate it immediately. 2. Remove it from active configuration. 3. Search repository history and deployment logs. 4. Determine exposure scope. 5. Review affected authentication/integration activity. 6. Replace the secret with a newly generated value. 7. Document the incident. ## If unauthorized issue access is reported Check: ```text user identity project membership role/permission issue visibility API authorization audit history ``` Do not rely solely on frontend state when investigating access control.