clari-security-basics

v2026.09.24

Secure Clari identities, credentials, exported revenue data, Copilot content, and ingestion mutations. Use when threat-modeling or reviewing least privilege and data handling. Trigger with: "secure Clari", "threat-model Clari", "review Clari access".

GitHub
Install command
npx skhub add jeremylongshore/clari-security-basics
Markdown
SKILL.md

Secure Clari Data Integration Boundary

Overview

Protect both control-plane credentials and the business data they unlock. Clari exports can contain hierarchy, identity, forecast, quota, CRM, activity, and conversation data, while ingestion and Copilot CRM endpoints can mutate provider state.

Prerequisites

  • Integration data-flow diagram and endpoint inventory
  • Named secret, privacy, retention, and incident owners
  • Destination encryption, access-control, audit, and deletion capabilities

Instructions

Step 1: Classify every flow

Identify credentials, user and participant identifiers, revenue values, activity metadata, transcripts, recordings, and CRM objects by sensitivity.

Step 2: Minimize authority

Use dedicated identities, separate Revenue, ingestion, and Copilot secrets, narrow hierarchy or workspace access, and deny mutation endpoints unless required.

Step 3: Protect credentials

Store only references in configuration, redact all documented auth headers, rotate on schedule, and test revocation without exposing values.

Step 4: Protect data in motion and at rest

Require HTTPS, encryption, restricted landing zones, field-level minimization, retention limits, and governed deletion.

Step 5: Constrain mutations

Gate ingestion and Copilot create, update, or delete actions behind validation, reconciliation, explicit operator approval, and rollback planning.

Step 6: Exercise response

Test credential exposure, overbroad access, incorrect export publication, and unauthorized mutation scenarios; retain redacted evidence.

Authentication

Revenue apikey, ingestion partnerkey, and Copilot key/password credentials are distinct high-impact secrets. Never log them, accept them in free-form prompts, or reuse one surface’s credential in another client.

Tool Discipline

Use Read and Grep to inspect configuration, provider contracts, fixtures, logs, schemas, and existing tests before proposing a change. Use Write or Edit only for the approved plan, implementation, test, or redacted receipt; do not issue, rotate, revoke, create, update, cancel, delete, export, ingest, or publish provider data without explicit operator approval.

Output

  • Threat model and data-classification matrix
  • Least-privilege credential and endpoint policy
  • Rotation, revocation, deletion, and incident drill receipts

Return the exact surface, environment, resource or job identifiers, contract fingerprint, evidence, unresolved risks, and final decision without exposing credentials or sensitive customer data.

Examples

A pipeline grants a forecast integration user access only to the required hierarchy, stores raw exports in a restricted landing zone, publishes minimized aggregates, and denies ingestion and Copilot CRM mutation endpoints.

Error Handling

FailureResponse
Secret appears in a log or fixtureRevoke or rotate it immediately, contain the artifact, and document affected access.
Identity sees unexpected hierarchy dataStop exports, reduce provider access, and review already-landed data before resuming.
Unauthorized mutation occursDisable the writer, preserve audit evidence, reconcile provider state, and execute the approved rollback.

Resources

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/.curated/clari-security-basics

Default branch

main

Latest commit

e5a6c3b

Tree SHA

c2dc8e8