Evidence record / paperclip
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-08-10-paperclip-agents-can-hand-credentials-to-paperclip-as-inert-proposals-that-only-a
Agents can hand credentials to Paperclip as inert proposals that only a human can activate.
A propose/review/approve/reject lifecycle for secrets. Agent-authored proposals are stored outside the live secret tables, each proposed value is encrypted and exact-value redaction is registered the moment Paperclip receives it, and nothing becomes a live secret or an env binding until an authorised human approves -- at which point the write executes through the normal secret-create and protected agent-config paths as the human approver. Binding proposals can target only the proposer or its downward reporting chain under the V1 policy. The PR explicitly rejected the obvious alternative of live secrets with a 'proposed' status because that would put untrusted rows in resolver, list and sync paths and allow uniqueness squatting.
Channel: tagged-release. Ancestry: PR #9934 merge commit e43f187cad3b05c9f00d1b9d4e924f43f7ab125e, merged 2026-08-06T02:49:40Z, base master. gh api repos/paperclipai/paperclip/compare/e43f187c...v2026.817.0 -> ahead, ahead_by=51, behind_by=0. Credited in the v2026.817.0 release body under 'Human-approved secret proposals'.
Operator consequence: Try it if you have been letting agents paste credentials into work artifacts. This closes the loop opened by run-bound secret access in v2026.722.0: the agent can now hand a credential in without ever holding authority to make it live, and the approval is attributable to a named human.
Receipt
Finding metadata
Run: 2026-08-10-weekly-digest-2026-08-03_2026-08-10-frontier-v0
Finding ID: 2026-08-10-paperclip-agents-can-hand-credentials-to-paperclip-as-inert-proposals-that-only-a
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact