# Log secret-sharing checklist

- Use the smallest time window and identifiers needed to diagnose the issue.
- Remove emails, tokens, cookies, credentials and unnecessary user content before sharing.
- Never share authorization headers, session cookies, passwords or private keys.
- Record which fields were removed and which reviewer approved the handoff.
- Stop when a field's sensitivity is unknown; ask the data owner.
- Redaction is not a guarantee that every secret was discovered.
