Skip to main content
reopt Handbook
reopt Handbook
Enterprise Project Architecture

Monorepo Foundation

Monorepo ArchitectureWorkspace DesignShared PackagesTurbo Pipeline

Apps and Delivery

Next.js PatternsVercel DeploymentCI/CD PipelineTesting Strategy

Agents and Operations

Agentic DevelopmentSkills EcosystemSecurity GovernanceMonitoring and Incident

Appendix

TemplatesReferencesUpdatesVerification
Handbook›Enterprise Project Architecture›Security Governance
한국어English

Security Governance

Manage secrets, access, dependencies, permissions, and approval rules in enterprise projects.

Key takeaways

  • Security governance turns risk into routine rules visible in development, CI, deployment, and incident response, not bolted on after an audit.
  • Governance areas cover secrets, access, authentication, authorization, dependencies, and data classification, each with a required rule.
  • Changes touching auth, roles, tenant boundaries, payments, secrets, or third-party data sharing require explicit review.
  • Never commit or paste production secrets, rotate exposed credentials immediately, and audit env vars during deployment changes.
  • Codex teams enforce agent rules via requirements.toml: approval policies, sandbox modes, filesystem deny_read, prefix rules, and MCP allowlists.

Security governance turns risk into routine operating rules. It should be visible in development, CI, deployment, and incident response, not added only after an audit.

Governance Areas

AreaRequired rule
SecretsStore in approved secret managers or platform env vars
AccessGrant least privilege and review regularly
AuthenticationDefine supported identity providers and session policy
AuthorizationKeep role and permission checks close to protected actions
DependenciesReview vulnerable or abandoned packages
DataClassify sensitive data and logging restrictions

Change Review

High-risk changes require explicit review when they touch:

  • Authentication or session logic.
  • Authorization, roles, or tenant boundaries.
  • Payment, billing, or customer data.
  • Secrets, environment variables, or deployment config.
  • Logging, analytics, or third-party data sharing.

Secret Handling Rules

  • Never commit secrets to the repository.
  • Do not paste production secrets into issue trackers or chat logs.
  • Rotate exposed credentials immediately.
  • Keep local development secrets separate from production credentials.
  • Audit environment variables during deployment changes.

Security Metrics

MetricPurpose
Open critical vulnerabilitiesDependency risk
Secret scan findingsCredential handling quality
Access review completionPermission hygiene
Incident time to containOperational readiness
Policy exceptionsGovernance debt

Agent Governance

LayerRule
FilesystemDeny reads for secrets, private data, and regulated exports
CommandsForbid destructive commands and prompt before git history changes
MCPAllow only approved MCP servers and tool identities
ReviewRequire human or automatic approval for sensitive actions
CIEnforce tests, ownership, and deployment gates after agent changes

Codex teams can enforce these rules with requirements.toml, including allowed approval policies, sandbox modes, web search modes, managed hooks, command rules, and MCP allowlists.

allowed_approval_policies = ["untrusted", "on-request"]
allowed_sandbox_modes = ["read-only", "workspace-write"]
allowed_web_search_modes = ["cached"]

[permissions.filesystem]
deny_read = ["./.env*", "./private/**"]

[rules]
prefix_rules = [
  { pattern = [{ token = "rm" }], decision = "forbidden", justification = "Use an explicit cleanup script instead." },
]

Related docs

Access Control and Secrets

AI Security and Compliance Operations · Govern human, service, and agent permissions with least privilege and rotation.

Security

Advanced Codex Usage · Secure Codex usage across secrets, network access, telemetry, and auditability.

Vercel Deployment

Organize project, environment, preview, and production deployment rules for enterprise teams.

Security Governance

Vercel Enterprise AI Platform · Govern identity, secrets, provider policy, data handling, WAF, BotID, and approvals.

References

Reference categories for adapting the enterprise project handbook to a specific organization.

Skills Ecosystem

Build reusable agent skills, commands, and documents for repeated engineering workflows.

Monitoring and Incident

Operate logs, metrics, traces, alerts, runbooks, and post-incident learning.

On this page

Governance AreasChange ReviewSecret Handling RulesSecurity MetricsAgent Governance