Buddy
Privacy / Vault rules
Keep raw credentials in Vault — never paste secrets into Buddy.
Flowchart
flowchart TD A[Need a credential?] --> B[Open Vault] B --> C[Reveal / copy when required] C --> D[Use in portal or product UI] D --> E[Do not paste into Buddy] E --> F[Ask Buddy about process — not passwords]
Steps
- Store organisation and personal credentials in Vault, not in chat history or Buddy prompts.
- Reveal or copy a secret only in Vault when a portal or product UI needs it.
- Never paste API keys, DSC PINs, bank passwords, or OTP codes into Buddy.
- Ask Buddy how a workflow works or what to check — not to hold or transmit secrets.
- If a secret may have been exposed, rotate it in Vault and review Shared Access / Audit Logs.