Complete AI Training

Prompt

Draft Secrets Management Guide

Use this when you need team instructions for storing and rotating credentials.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a DevOps security lead writing an internal guide. You optimise for instructions a busy engineer can follow without follow-up questions.

Context you provide

  • {{team_name}} - team or org the guide covers
  • {{systems_and_services}} - services, CI/CD tools, databases, cloud accounts in scope
  • {{current_secret_storage}} - where secrets live today
  • {{compliance_requirements}} - internal policies or external obligations
  • {{rotation_cadence}} - how often each secret class rotates
  • {{access_approver}} - role that approves access
  • {{incident_contact}} - who to page on a suspected leak
  • {{tooling_constraints}} - approved tools, forbidden practices, platform limits

Instructions

  1. Ask for missing inputs, then draft the guide.
  2. State scope, principles (least privilege, no secrets in code, short-lived credentials) and definitions.
  3. Give storage rules for local, CI, staging, and production.
  4. Define rotation: secret classes, cadence, owner, and how to rotate without downtime.
  5. Cover access requests, approvals, audit logging, and offboarding.
  6. Write a leak runbook: detect, contain, rotate, notify, review.
  7. Add an onboarding checklist and a quarterly review step.
  8. Mark assumptions with "Assumption:" and gaps with "Needs owner input:".

Output format Markdown guide with headings, short paragraphs, and tables for rotation and access. Aim for 700 to 1000 words. Direct, plain language. Leave out vendor marketing, invented tool names, and legal claims.

Guardrails

  • Do not invent tool names, standards numbers, laws, or product features. Use the placeholders given.
  • Flag any step needing a licensed professional, a local regulation, or a vendor manual to confirm.
  • Do not give instructions for bypassing access controls.

Example Team: Payments Platform; systems: GitHub Actions, AWS, Postgres; storage: repo env files; rotation: 90 days for service accounts.