IRIDESC E UX · COMMAND
v30 · Program Primary Revision
INTERNALSTEP-BY-STEP

Security, Backups & Offboarding

Production security posture, backup/rollback discipline, secret rotation, access removal, and incident response.

Minimum production security posture

Backups before changes

ResourceBefore risky change
D1Remote export to timestamped SQL.
Git/codeClean commit + known rollback commit hash.
PagesKnow the last healthy deployment and rollback path.
R2/mediaDo not bulk-delete without inventory/export plan. Maintain source masters separately.
OBSExport/backup scene collection and profile before major reconfiguration.

Rotate a secret safely

1

Create the new credential

Provider/password manager

Do not revoke old credential yet if both sides must be updated in sequence.

2

Update the receiving service

Cloudflare/agent/vendor

Store new value as secret.

3

Redeploy/restart where necessary

Service

Command Pages requires a new deployment; Broadcast Agent may require restart.

4

Verify functionality

Smallest possible test

Prove the new secret works.

5

Revoke old credential

Provider

Only after successful verification.

6

Record rotation

Audit/change log

Record date, owner, affected service — not the secret itself.

Employee offboarding — full sequence

  1. Disable Command team record.
  2. Remove Access permission.
  3. Disable/suspend company email or IdP account.
  4. Remove GitHub repository/team access.
  5. Remove Cloudflare account membership if they had it.
  6. Remove social/vendor/finance/analytics access.
  7. Rotate known shared secrets.
  8. Review Command audit log and Cloudflare logs around departure.
  9. Collect/secure company devices/files as applicable.
  10. Document completion.

Incident response first ten minutes

1. Identify whether incident is PUBLIC SITE / COMMAND / BROADCAST / CREDENTIAL.
2. Preserve evidence: screenshots, timestamps, logs.
3. If Command is publicly exposed → immediately fix/disable Access exposure.
4. If broadcast output is unsafe → backup feed / KILL GRAPHICS / emergency stop as rehearsed.
5. If credential leaked → revoke/rotate it.
6. Freeze unrelated changes.
7. Assign one person to coordinate.
8. Restore the last known-safe state.
9. Verify externally.
10. Record root cause and prevention after service is stable.