What to change
Separate descriptive handover evidence from secret transfer. Reports can identify an account's purpose, owner and approved access route without containing live passwords, tokens or recovery codes. Use the organisation's agreed secure process to establish the recipient's access. If a live secret has already been exposed, involve the authorised security owner to revoke or rotate it as appropriate, check the exposure and restore legitimate access. Removing the visible copy is only one part of that response.
A worked example
Illustrative example
Illustrative test: A handover screenshot contains a fictional deployment token. The rehearsal records who would invalidate an exposed live token, restore the authorised publishing route and verify that the retired route no longer works.
How to check the result
The general handover contains suitable descriptive information, legitimate access works, and any exposed live credentials have an owned response.
A mistake to avoid
Redacting a screenshot does not invalidate copies already distributed; an unplanned revocation can also interrupt legitimate automation.
Your action checklist
Use these checks to prepare a discussion with your team or supplier. Tick a check when you have recorded the decision or evidence, rather than when a feature has simply been promised.
Entries stay in this page and are not submitted to Kay & Co. Download your notes before leaving; the page does not save them.



Further reading
These primary sources provide additional context for the project decisions above.
Related decisions
Turn the brief into a working service
Kay & Co. can help you scope the work, design the experience and deliver the right solution for your organisation.
Explore support & operations services or discuss your project.
Try the free Healthcare Digital Planner to find your starting priority.