# Credential Rotation Checklist

- [ ] Identify the issuing provider.
- [ ] Revoke or disable the old credential.
- [ ] Create a minimum-scope replacement.
- [ ] Update the legitimate integration through its secure configuration path.
- [ ] Verify expected operation.
- [ ] Review audit logs and usage.
- [ ] Record rotation date and operator.
- [ ] Confirm the old value is absent from chat, tickets, commits, and logs.

Record only metadata in this checklist.
