# Credential Management ## Definition Credential management is the lifecycle practice of creating, storing, rotating, recovering, revoking, and retiring the secrets and factors used to authenticate or authorize access. ## Notebook evidence [[Scanned_20260730-2016]] preserves a large credential ledger across email, carriers, social platforms, banking, brokerage, travel, domains, and self-custody wallets. The reconstruction redacts passwords, PINs, security answers, payment-card data, recovery codes, and mnemonic phrases while retaining the service and page relationships. ## Critical distinction The notebook frequently places identifiers, authenticators, recovery factors, authorization data, and asset-control keys in one category. They are not equivalent: - an identifier says which account or subject is involved; - an authenticator helps prove control; - a recovery factor restores access; - an authorization scope defines permitted action; - an asset-control key can directly confer control and may be effectively nonrevocable. ## Archival lesson Concentrating all classes in one portable object improved personal recoverability while increasing the consequences of loss or copying. The redacted notebook must remain evidence, not an operational credential store. ## Source - [[Scanned_20260730-2016]], especially PDF pages 2, 16–25, and 30–42.