Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would solve this using the equivalent of a service account - I would give that "agent" an identity - "CodeBot" or whatever - and then that as an actor which has permission to read things on Jira, permission to send notifications to Slack, permission to access the GitHub API etc.

Then I would control who had permission to tell that to do, and log everything in detail.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: