# Phase 0 — Access Checklist

Track credentials and access before enabling live integrations. Store secrets in a secrets manager or local `.env` (never commit).

## Jira

| Item | Status | Notes |
|------|--------|-------|
| Project key(s) | ☐ | e.g. `SALES` |
| Service account / API token | ☐ | Min permissions: read issues/comments/attachments, write comments, remote links |
| Base URL | ☐ | e.g. `https://your-org.atlassian.net` |
| Webhook secret | ☐ | Shared secret for HMAC / header validation |
| Webhook events | ☐ | `jira:issue_created`, `jira:issue_updated`, `comment_created` |
| Agent-ready trigger | ☐ | See [TRIGGER_RULES.md](TRIGGER_RULES.md) |

## Confluence

| Item | Status | Notes |
|------|--------|-------|
| Allowed space keys | ☐ | Restrict RAG to these spaces |
| API token / OAuth | ☐ | Read-only preferred |
| Priority pages / runbooks | ☐ | Architecture standards, naming, coding guides |

## Git (default: GitHub)

| Item | Status | Notes |
|------|--------|-------|
| SFDX Salesforce repository URL | ☐ | Source of truth for metadata |
| Bot identity (commit author) | ☐ | Dedicated machine user |
| PAT / App credentials | ☐ | Contents + PR write for later phases |
| Default branch | ☐ | e.g. `main` |

## Salesforce (lower org only — no production in v1)

| Item | Status | Notes |
|------|--------|-------|
| Sandbox / scratch / DEV org | ☐ | Deploy + validate + Apex tests |
| Auth (JWT / OAuth / SFDX auth) | ☐ | Service account |
| Confirmed **no** prod credentials | ☐ | Required |

## LLM

| Item | Status | Notes |
|------|--------|-------|
| Provider | ☐ | Default scaffold: OpenAI |
| API key | ☐ | |
| Model name | ☐ | e.g. `gpt-4o` |

## Infrastructure

| Item | Status | Notes |
|------|--------|-------|
| Postgres (+ pgvector) | ☐ | Local via Docker Compose |
| Redis | ☐ | Local via Docker Compose |
| Artifact storage path | ☐ | Default: `./data/artifacts` |
