# Automation Credentials Vault Overview
In order to minimize risks as it relates to the implementation of automation in your customers’ environments, the Ansible Satellite does not store any credentials used to access target customer systems. Instead, these credentials are provided by the CMDB base station at automation playbook run time. In following the key principles of separation of duties (SOD) and separation of privilege (SoP), the CMDB base station does not store any of the required credentials, instead pulling those credentials from an encrypted credential files that you may maintain in any appropriately secure fashion.
# Create Your CMDB-360 Automation Credentials Vault Entry
For security concerns, CMDB-360 Automation Credential Vaults are considered “personal” to CMDB-360 users. This means that other CMDB-360 users cannot share your credentials. Even if your encrypted credential file is accessed by someone else, it will not be useable except by your CMDB-360 portal login.
To access your CMDB-360 Automation Credentials Vault, login to your account and then click the Automation Credentials Vault option from your personal menu (top right hand corner).
You will see the list of your personal credentials that are accessible within CMDB-360 when running automation.
Click the New Credential button to add a credential entry to your CMDB-360 account.
Enter a name for your new credential (it is suggested to use something that makes it obvious which client and what purpose this credential is for). This name in CMDB will be displayed when automation playbooks are run and a credential of its type is required. You must now also select the credential type from the dropdown list.
Each credential is tied to an Account and Discovery Satellite. This helps by limiting the options in the selection of appropriate credentials when you are running an automation for an account. Then hit Save.

The credential now appears in your vault. Click on it to see information about it.

The newly created credential entry need to be completed by creating the encrypted key. Press the Create Key button to fill out the credentials fields and create the key file.

In this case, an OCI cloud credential is being created. Fill out all the appropriate fields with information from your OCI API key and add a file name. The file name should be something obvious to link this credential entry to the file, possibly even the same name. When done, hit the Create Key button and an encrypted key file will be downloaded to your workstation. To see more about what information is required for the credential type see: https://docs.cmdb360.com/docs/Satellites/Ansible-satellite/Satellite-Authentication/Satellite-Authentication

This encrypted key file may be stored in any manner you see fit using like a secure digital vault application such as Keeper, or in a cloud vault or simply on a personal secure directory or usb stick. These file can not be used by anyone else. They are only useable by your CMDB-360 login.
Note: The validity of the key is checked before the file is created. If you get an error, please check the values provided
# Using Your CMDB-360 Automation Credential
When deploying an Automation Playbook, credentials are required for the playbook to access the entity being acted upon. In this case, the playbook required OCI cloud access, so a CMDB-360 credentials entries of the appropriate type and related to this Account and the Discovery Satellite associated with the item are displayed to chose from. Select the appropriate credential entry. If the credential has not been validated already for this session, click the ‘Click to Validate’ button

If the credential has not been validated already for this session, click the ‘Click to Validate’ button. Then select the encrypted key file associated with this credential entry and click Upload.

The Automation may then proceed to the next step and be launched against the item.