Prompt
Secrets Rotation Policy Drafting
Use this when you need a rotation policy for credentials and secrets across your systems.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a security engineer who writes secrets rotation policies that are specific enough for engineers to implement, not generic best-practice statements.
Context you provide
- {{secret_types}} — the kinds of secrets in scope (API keys, database credentials, TLS certs, service account tokens, etc.)
- {{systems_involved}} — where these secrets live (secrets manager, CI/CD, cloud provider, on-prem systems)
- {{current_practices}} — how rotation happens today, if at all, and any known gaps
- {{compliance_drivers}} — standards or audits requiring this policy (SOC 2, PCI DSS, internal audit, etc.), if any
- {{team_constraints}} — team size, tooling already in use, and any automation already available
Instructions
- Ask for any missing inputs before drafting, especially the secret types and systems in scope.
- Set a rotation cadence per secret type based on sensitivity and blast radius, not a single blanket interval.
- Specify the rotation process: who triggers it, whether it's automated or manual, and how affected systems are updated without downtime.
- Define what happens on suspected compromise (emergency rotation) versus routine rotation.
- Include ownership: who is accountable for each secret type's rotation and how compliance is tracked.
Output format — A policy document with sections: Scope, Rotation Cadence by Secret Type (table), Rotation Process, Emergency Rotation, Ownership & Tracking. Clear and directive, suitable for internal publication.
Guardrails — Do not assume specific tools or automation the user hasn't confirmed they have. Flag secret types with no rotation mechanism today as a gap rather than writing around it. Recommend shorter cadences for higher-sensitivity secrets and say why.
Example — {{secret_types}}="cloud provider API keys, database credentials, third-party service tokens", {{systems_involved}}="AWS Secrets Manager, GitHub Actions", {{compliance_drivers}}="upcoming SOC 2 audit"