<!-- Generated from business-case-openbao.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — the business case for OpenBao

OpenBao (OpenSSF (Linux Foundation)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.

Source: https://riskmandate.ai/business-case-openbao.html

---

# OpenBao, by the risk it changes

A secrets manager that issues dynamic credentials with leases. Revoking a lease invalidates the secret at once, and a prefix revokes every lease under it in one command. Written as answers, an agent whose credentials all come from OpenBao can be stopped in one action, in minutes.

**Open source:** MPL-2.0 · OpenSSF (Linux Foundation) · [get involved](https://openbao.org/community/)

**The deployment:** The model's typical deployment, with the answers this project addresses stated as they are without it: stopping it takes more than one action; nobody knows how long stopping it would take.

**The model:** the RiskGraph Explorer's 49 facts, 49 risks and 10 roles, copied into this site with its provenance; the register below is computed, not written. [How](business-cases.html#method).

## In its own words, and nothing more.

- Leases on every dynamic secret, revocable one at a time or by prefix. “When a lease is revoked, it invalidates that secret immediately and prevents any further renewals.” · [openbao.org](https://openbao.org/docs/concepts/lease/), read 24 September 2026

## Same deployment, different answers.

The model asks sixteen questions about an agent deployment. A product’s effect is written as the answers it changes, and each change says what kind of change it is: a statement of what is true, an expectation the agent is asked to meet, a setting, or a boundary enforced by something the agent’s grant does not include.

## 3 retired, 20 unchanged.

Computed from the model for the deployment above: every risk that holds without it, and every risk that holds with it.

Retired

## Who carries less, and who carries the same.

Each risk is assigned to the roles it belongs to, and each role reports to another until the board. The count beside each role is the entries it holds without the product and with it.

### Operators

### Owners

### Executives

### The board

At the board: the corporate register

Corporate risks have no facts of their own. They hold while any risk that leads into them holds, so a single product rarely retires one. What it changes is how many reasons the board is being given.

## Every product is also a new thing in the estate.

It holds every secret it issues, which makes it the most sensitive system in the estate. Its audit documentation says it fails closed: _OpenBao will not respond to requests when no enabled audit devices can record them._

## What adopting it takes, before any of this is true.

An open-source project costs nothing to download and something to adopt. Every change above depends on the work below, and most of it is customisation to your own deployment.

- Move the agent's credentials to dynamic secrets, which means every system it calls has to support them.
- Give each agent its own prefix, so one command stops one agent and nothing else.
- Write down who may run the revocation, and practise it.

## Published unresolved, for OpenSSF (Linux Foundation) to settle.

Each pair was read on the same day. We have not tested which is true, because that would mean testing somebody else’s system.

- **revocation.** The lease page says revocation invalidates a secret immediately; the revoke command documents a force option that deletes the lease even if the secret engine's revocation fails. [lease](https://openbao.org/docs/concepts/lease/) · [revoke](https://openbao.org/docs/commands/lease/revoke/)

## The limits of the case, stated by the case.

- That stopping has been exercised. Whether it was ever done in production is a different question, and it stays unanswered.
- That it was tested. Nothing was installed or run; every change rests on the documentation quoted beside it.
- That the register is complete. It is one model, for one stated deployment. A different deployment changes the answers, and so the case.

**Next.** Published, and sent to the project's maintainers at the same time. If a change is wrong, or another answer should move, the case changes with the date they said so.

## Make the case in the register’s own terms.

If you build a security product for agents, the case for it can be written the same way: what it does in your own words, the answers it changes, and the register before and after. If a case here is wrong about you, tell us and it changes with a date.
