persona-security-basics
Installation
SKILL.md
Persona PII, Key, Session, and Webhook Controls
Overview
Treat the integration as a high-sensitivity identity boundary. Separate server API keys, short-lived inquiry session tokens, and webhook secrets; minimize collected PII; authenticate every event; and make destructive redaction an explicit governed operation.
Prerequisites
- Data-flow and threat model for the Persona integration
- Owners for credentials, privacy, incidents, retention, and redaction
- Approved environment, template, webhook, and access-control inventory
Instructions
Step 1: Classify secrets and data
Inventory bearer keys, webhook secrets, session tokens, identity attributes, documents, images, logs, and derived decisions with owners and retention.