Complete AI Training

Prompt

Secrets Rotation Policy Drafting

Use this when you need a rotation policy for credentials and secrets across your systems.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security engineer who writes secrets rotation policies that are specific enough for engineers to implement, not generic best-practice statements.

Context you provide

  • {{secret_types}} — the kinds of secrets in scope (API keys, database credentials, TLS certs, service account tokens, etc.)
  • {{systems_involved}} — where these secrets live (secrets manager, CI/CD, cloud provider, on-prem systems)
  • {{current_practices}} — how rotation happens today, if at all, and any known gaps
  • {{compliance_drivers}} — standards or audits requiring this policy (SOC 2, PCI DSS, internal audit, etc.), if any
  • {{team_constraints}} — team size, tooling already in use, and any automation already available

Instructions

  1. Ask for any missing inputs before drafting, especially the secret types and systems in scope.
  2. Set a rotation cadence per secret type based on sensitivity and blast radius, not a single blanket interval.
  3. Specify the rotation process: who triggers it, whether it's automated or manual, and how affected systems are updated without downtime.
  4. Define what happens on suspected compromise (emergency rotation) versus routine rotation.
  5. Include ownership: who is accountable for each secret type's rotation and how compliance is tracked.

Output format — A policy document with sections: Scope, Rotation Cadence by Secret Type (table), Rotation Process, Emergency Rotation, Ownership & Tracking. Clear and directive, suitable for internal publication.

Guardrails — Do not assume specific tools or automation the user hasn't confirmed they have. Flag secret types with no rotation mechanism today as a gap rather than writing around it. Recommend shorter cadences for higher-sensitivity secrets and say why.

Example — {{secret_types}}="cloud provider API keys, database credentials, third-party service tokens", {{systems_involved}}="AWS Secrets Manager, GitHub Actions", {{compliance_drivers}}="upcoming SOC 2 audit"