Sample workflow finding

See how one AI-assisted delivery path is reviewed.

This three-page sample shows a GitHub Action with a repository PAT, its available write actions, missing ownership and approval records, and the next review step.

Last updated: August 3, 2026

What is in the redacted workflow finding? The sample shows scan scope, workflow reach, credentials, target actions, existing control evidence, unresolved items, and the recommended next check in a shareable PDF.

Inline preview

01What can change?
02What authority is used?
03Which controls apply?
04What is unresolved?
05What proof remains?
Sample field Redacted example
Workflow reach GitHub Action running AI coding assistant
Credential GitHub PAT referenced from repository secret
Reachable actions Read, write, comment, modify PR branch
Unresolved Owner, approval evidence, policy coverage, outcome evidence
Recommended action Assign owner, confirm credential scope, replace broad PAT, require approval for write actions

What the sample shows

Scan scope

Repo or workflow scope, source mode, raw-source retention, artifact type, and review purpose.

Reach summary

Counts for AI-assisted or automation paths, write/deploy reachability, standing credentials, and unresolved owners.

Control coverage

The workflow, credential, reachable actions, target, owner, approval evidence, policy coverage, and unresolved evidence.

Recommended action

Specific next steps such as assigning an owner, confirming credential scope, requiring approval, and recording proof.

Example path in the sample

The sample includes a GitHub Action running an AI coding assistant with a repository secret referencing a GitHub PAT. This exact pattern will vary by environment. The sample shows how a normal workflow can gain standing write access without a clear owner or approval record.

AI-assisted PR -> workflow file -> repository secret -> write-capable action -> owner / approval / outcome unresolved

How to use it internally

  • Share it with platform, DevEx, CI/CD, release engineering, or security reviewers.
  • Pick one workflow and ask whether the same fields are knowable in your environment.
  • Use unresolved owner, approval, policy, and outcome fields as a short review agenda.
  • Keep normal AI coding adoption moving while separating low-risk edits from credentialed actions.

What it is not

This sample is not a vulnerability report and not a claim about your environment. It is a redacted example for the practical question: what can this workflow trigger, which controls cover it, and what remains unresolved?

Download the sample

The PDF requires no form and is safe to share internally. It is intended as a conversation starter for one workflow, not a comprehensive policy document.

Turn the sample into one mapped workflow.

Clyra maps one selected workflow and returns its reachable jobs and actions, credential context, control coverage, unresolved evidence, and review-ready Agent Action BOM.

Map one workflow