Reference

Agency → Client Deploy Handoff

Checklist + Interactive Key Rotation ceremony. This document is the normative handoff procedure for transferring a deployed CRM Sync / headless commerce stack from the implementing agency to the client organization's own infrastructure (their GitHub, their Cloudflare, their Shopify/Xano accounts). It exists so that security custody is provable: every credential is re-minted (never copied), every rotation is performed by a named human with an agent verifying and documenting, and the resulting audit trail is usable as evidence for Legal/Compliance (PII processor documentation) and for recurring Security-Scaling reports.

Referenced from Functional Spec §13. Roles below map to the spec's Document Control roles (DPO, Engineering Lead) plus the handoff-specific Security Human and Agent.


0. Roles

RoleWhoDoesNever does
Agency Operatorimplementing agency engineerruns the stack pre-handoff; prepares inventory; revokes own access at the endretains any working credential past Phase E
Security Humanclient-side named individual (recorded in the audit log)executes every mint/rotation interactively (dashboard or CLI); approves scopedelegates execution to automation
AgentAI/automation operator (e.g. Claude Code session, CI)prepares runbooks, pre-checks, verifies old-dead/new-alive, writes the audit recordmints, holds, or transports production credentials
DPO / Complianceclientreceives the PII map + audit trail; signs §6—

The Interactive in Interactive Key Rotation is a policy, not a mood: agents prepare and verify, humans execute. Credential creation is a human act with a named owner, which is what makes the audit trail meaningful to a regulator.


A. Pre-handoff inventory (Agency Operator + Agent)

B. Infrastructure transfer (Client + Agency)

C. Secret re-mint — the core rule: nothing is copied, everything is replaced

Execute as an Interactive Key Rotation ceremony (§D) per credential class, in dependency order (consumers after producers):

D. Interactive Key Rotation — the ceremony

One sitting per credential class. Human executes, Agent verifies, both are recorded.

  1. Schedule — Security Human + Agent session; change window noted.
  2. Prepare (Agent) — runbook for the specific credential: where it lives, every consumer that must be updated, the verification probes, the rollback (overlap window where old + new are both valid, when the system supports it — admin keys and signing keys do; bearer tokens get a short dual-accept window or a maintenance moment).
  3. Execute (Security Human) — mints in the provider dashboard or runs the CLI command themselves. Agents may display the command; the human runs it.
  4. Verify (Agent) — probes: new key authenticates on every consumer surface; old key is rejected everywhere; no service interruption signals.
  5. Record (both) — append one audit entry:
   date: 2026-06-12T18:40Z
   credential: ADMIN_KEY (rotatable tier)
   action: rotate            # mint | rotate | revoke
   executed_by: <Security Human name>        # the human, always
   verified_by: <Agent session/run id>
   reason: scheduled-90d     # handoff | scheduled-90d | personnel | incident | scope-change
   old_fingerprint: 3fa1b2c4 # sha256[:8] — never the secret
   new_fingerprint: 9d77e012
   overlap_window: 24h       # or "none"
   consumers_updated: worker secret, CI secret

E. Agency access revocation (the handoff moment)

G. Security-Scaling Report (recurring, quarterly or per-market launch)

The matrix appendix, channel cursor lag, and consent tally are emitted live by the platform's governance report so this section assembles from real data, not by hand.


1. Credential Inventory table (template)

#CredentialSystemScopeStored inFingerprintMintedOwnerNext rotation
1ADMIN_KEY (root)workerplatform adminCF secret____________Security Human+90d
2ADMIN_KEY (rotatable)workeradmin surfacesCF secret + KV meta____________Security Human+90d
3EXPORT_TOKENworker + CIbuild data feedCF secret + GH secret____________Security Human+90d
4GitHub PAT (dispatch)worker1 repo, contentsCF secret____________Security Human+90d
5Cloudflare API tokenCIWorkers/Pages editGH secret____________Security Human+90d
6Xano master meta keyworkerworkspace metadataCF secret____________Security Human+90d
7Xano entitlement:readworkerread-onlyCF secret____________Security Human+90d
8Shopify app secretworkerclient-credentials grantCF secret____________Security Humanper Shopify
9Webflow site token(s)workerper-site CMSCF secret / KV____________Security Human+90d
10Tenant tokens crm_t_*KVper-tenantKV (revocable)per-tenant____tenant adminon personnel change
11Entitlement signing keysXano (192)token signingnext→active→retiredkey version____Security Human+90d staged

Add rows for market-specific tokens as markets launch; the table is the living object the quarterly report (§G) diffs against.