What to change
Separate descriptive handover evidence from secret transfer. Reports can identify an account's purpose, owner and approved access route without containing live passwords, tokens or recovery codes. Use the organisation's agreed secure process to establish the recipient's access. If a live secret has already been exposed, involve the authorised security owner to revoke or rotate it as appropriate, check the exposure and restore legitimate access. Removing the visible copy is only one part of that response.
A worked example
Illustrative example
Illustrative test: A handover screenshot contains a fictional deployment token. The rehearsal records who would invalidate an exposed live token, restore the authorised publishing route and verify that the retired route no longer works. A rehearsal screenshot may contain a fictional deployment token to demonstrate the handover review. The team identifies who would replace an exposed live token and verify approved publishing still works afterwards. The general report uses safe identifiers only. This shows why redaction alone would not invalidate distributed copies, while also recognising that careless revocation could interrupt legitimate automation unless replacement access is tested as part of the response.


What this means for your practice
A handover should describe an account's purpose, owner and approved access route without embedding passwords, tokens or recovery codes in general project material. Establish the recipient's access through the organisation's agreed secure process. If a real secret has already been exposed, involve the authorised security owner to assess and replace or revoke it appropriately. Merely redacting the visible screenshot does not invalidate copies already distributed. At the same time, an unplanned revocation can interrupt legitimate publishing, so verify the replacement route and any approved automation. Keep safe identifiers and completion evidence in the report, with secret values managed separately.
How to check the result
The general handover contains suitable descriptive information, legitimate access works, and any exposed live credentials have an owned response.
A mistake to avoid
Redacting a screenshot does not invalidate copies already distributed; an unplanned revocation can also interrupt legitimate automation.
Turn reading into a next step
Your action checklist
Work through these checks with your team or supplier. Tick the ones you have resolved and leave unknowns open.
Record what you know, what is still missing and the answer you need from your team or supplier.
Use project decisions only, without personal, patient or confidential details. Entries stay in this page and are not submitted to Kay & Co. Copy or download before leaving; this page does not save your notes.
Further reading
These sources provide background for the topic. The practice examples and checklist are illustrative planning suggestions from Kay & Co.
Related guides
Need help with this?
Tell us what is getting in the way. Kay & Co. can help you understand the options and turn the next step into something that works for your practice.
Explore support & operations services or discuss your project.
Try the free Healthcare Digital Planner to find your starting priority.
