Private Access Transfer Receipt Template¶
Copy this template into the approved private records system before filling it out. Do not commit a completed copy, attach it to a public issue, or place it in an ignored repository directory. The repository intentionally contains no credential values, recovery answers, personal contact details, billing data, or secret-storage locations.
Transfer Summary¶
Record the project role, effective date, outgoing and incoming role holders, approval authority, and the private record identifier. Use role names rather than personal details wherever the private system permits.
Per-Surface Verification¶
Create one private row for each of these categories:
- GitHub organization and repository;
- Kaggle notebooks, datasets, and competition permissions;
- domain registrar, DNS, hosting, TLS, and deployment controls;
- PyPI and model or dataset registries;
- model-provider billing, quota, and revocation controls;
- monitoring, alerting, backups, and durable archives; and
- shared outreach, support, security, and research channels.
For each row, privately record:
- the platform and scope;
- the least-privilege role granted;
- invitation accepted and access tested date;
- publishing or release authority tested without performing an unnecessary production publication;
- second-factor and recovery path tested date;
- billing and renewal owner confirmed;
- revocation path confirmed;
- backup or export owner and retention policy confirmed;
- open limitation or follow-up owner; and
- verifier and approval evidence retained in the private system.
Use status values such as not started, invited, access tested,
recovery tested, complete, or not applicable. Never paste a token, key,
password, recovery code, unredacted audit log, or private mailbox address into
the row.
Final Private Attestation¶
The outgoing owner and successor should attest that least-privilege access, recovery, billing, backup, and revocation were tested for every applicable surface; unresolved limitations have named private owners; and public project claims do not imply transfer completion before this attestation exists.
The safe public statement is category-level and dated, for example that access transfer was completed for all applicable platform categories and retained in private records. Do not publish the filled receipt.