Fewer keys
I had what felt like a very good idea.
My ecosystem keeps a written memory — every brand, every decision, dated and logged. And a memory like that is already most of a piece of writing. The thinking is in there. The reversals, the things that broke, the calls I got wrong. Point the machine at the notes, and the log writes itself.
Then I actually looked at what was in those files.
The same notes that hold my best thinking also hold a client's private matters. A live negotiation, mid-flight, where a single sentence in public would cost real money. Numbers that belong to no one but me. All of it sitting in the same place as the material I wanted to publish, because it all arrived on the same days, from the same work.
Here's the part that stopped me cold. I had built that memory for safety — so nothing important would be lost. And I was about to point it at publication — so nothing good would go unseen. Two opposite intents, sharing one filesystem. Both of them mine. Both of them reasonable.
The instinct is to be careful. To promise yourself you'll check before you publish, that you'd never be so careless, that you'll remember. But care doesn't scale, and neither does memory. Every system that relies on someone being careful at the exact right moment is a system waiting for a tired Thursday.
So I did the opposite of adding caution. I took keys away.
The rule that came out of it is boring, and I think that's the point. Nothing is open unless it was opened on purpose. The sensitive folders aren't "handled carefully" — they're denied by default, and the machine that helps me build is told, in writing, what it may not read. Not as a preference. As a wall. Secrets never enter the permanent record at all — not in a file that gets saved, not in a note that gets synced, nowhere that a record could carry them somewhere I didn't choose. And when I finish work for someone, the work transfers to them. I don't keep a copy for old times' sake. A copy is just a key I forgot I made.
Because that's what a key actually is: not permission, but exposure. Every key that exists is a door that can be left open by someone who isn't paying attention — a contractor from two years ago, a tool you tried once, a shared login that made a busy week easier and never got closed. You don't secure a system by adding rules on top of it. You secure it by having fewer things that can be opened.
Subtraction is the whole craft here. The safest key is the one that was never cut.
And this is where it stops being a technical matter and becomes a business one. Trust in a business isn't a feeling. It's an architecture. People trust you with their words, their money, their private lives — and what protects them isn't your good character on the day. It's whether your system can betray them at all. If it can't, your character never has to be tested.
Three questions. Answer them honestly, right now:
- Who holds a key to your business that you'd have to stop and think about to remember?
- If someone you worked with last year wanted in tomorrow, what would still open for them?
- What sits in one place that, if it got out, you would have to make phone calls about?
If the second one took you more than a second, that's your week.
Want an outside read on what your setup is quietly exposing — what's carrying weight, what's leaking, and the one thing I can't see from out here? It's free, and it takes a few minutes: run the scan.