What is in the redacted workflow finding? The sample shows scan scope, workflow reach, credentials, target actions, existing control evidence, unresolved items, and the recommended next check in a shareable PDF.
Inline preview
| Sample field | Redacted example |
|---|---|
| Workflow reach | GitHub Action running AI coding assistant |
| Credential | GitHub PAT referenced from repository secret |
| Reachable actions | Read, write, comment, modify PR branch |
| Unresolved | Owner, approval evidence, policy coverage, outcome evidence |
| Recommended action | Assign owner, confirm credential scope, replace broad PAT, require approval for write actions |
What the sample shows
Scan scope
Repo or workflow scope, source mode, raw-source retention, artifact type, and review purpose.
Reach summary
Counts for AI-assisted or automation paths, write/deploy reachability, standing credentials, and unresolved owners.
Control coverage
The workflow, credential, reachable actions, target, owner, approval evidence, policy coverage, and unresolved evidence.
Recommended action
Specific next steps such as assigning an owner, confirming credential scope, requiring approval, and recording proof.
Example path in the sample
The sample includes a GitHub Action running an AI coding assistant with a repository secret referencing a GitHub PAT. This exact pattern will vary by environment. The sample shows how a normal workflow can gain standing write access without a clear owner or approval record.
How to use it internally
- Share it with platform, DevEx, CI/CD, release engineering, or security reviewers.
- Pick one workflow and ask whether the same fields are knowable in your environment.
- Use unresolved owner, approval, policy, and outcome fields as a short review agenda.
- Keep normal AI coding adoption moving while separating low-risk edits from credentialed actions.
What it is not
This sample is not a vulnerability report and not a claim about your environment. It is a redacted example for the practical question: what can this workflow trigger, which controls cover it, and what remains unresolved?
Download the sample
The PDF requires no form and is safe to share internally. It is intended as a conversation starter for one workflow, not a comprehensive policy document.
Turn the sample into one mapped workflow.
Clyra maps one selected workflow and returns its reachable jobs and actions, credential context, control coverage, unresolved evidence, and review-ready Agent Action BOM.
Map one workflow