Skip to content
PROTOTYPE — MOCK DATAFigures are generated fixtures derived from the registry. Not ACF actuals.
Menu (13)

Collections — Nexusti roll rates

HEALTHY
Collections / Debt Recovery · production · 1 dataset
k-2026-03-29-01ACTIVEPRODUCTION
SHA256:2d6787c5272e
Issued 29 Mar 2026 to IT System Development · expires 29 Sep 2026
push:datasetread:receiptread:schema
6
DAYS LEFT

Expiry warnings went to both owners at T‑30, and go again at T‑7 and T‑1. Both, not just the data owner — when a feed dies because a key lapsed, the person who has to explain the gap in the number is the metric owner.

ROTATION

Two keys may be active at once, overlapping for at most 30 days. That overlap is not a convenience — without zero-downtime rotation, the rotation never happens, and an eternal credential is the one nobody replaces.

WHAT WE REFUSE TO ISSUE
  • · An organisation-wide shared key. A Telesales key must not be able to write Finance numbers.
  • · A credential that can both read and write. This one is push-only — it cannot read a single metric value.
  • · An unlimited lifetime. 180 days by default, 365 at most.
  • · “Resend me the same key.” Lost means rotate, never recover.

Each of these would be a one-line feature, and each would quietly undo the row-level security model in 04 §8. That is why they are listed as refusals rather than left unbuilt.