Secrets management is the discipline of controlling sensitive credentials throughout their lifecycle: creation, storage, access, use, rotation, revocation, and audit. It applies to both human and machine access.
What counts as a secret?
A secret is information that grants access or proves identity. Business passwords are the most familiar example, but technical environments also depend on API keys, access tokens, database credentials, private keys, certificates, webhook secrets, and recovery codes.
- Passwords and shared accounts
- API keys and application tokens
- Database and infrastructure credentials
- Private keys and certificates
- Recovery and integration secrets
Why ordinary storage creates risk
The problem is not simply whether a value is encrypted. Organizations also need to know who owns it, who can access it, why access exists, where copies remain, when it should rotate, and what happened before an incident. Chat, spreadsheets, tickets, source code, and personal browsers rarely provide that complete control model.
The core controls
A practical secrets-management program combines secure storage, access governance, and auditability. It organizes secrets by business context, limits access according to role and need, supports safe delivery to people and workloads, and preserves evidence for review.
- Inventory and assign ownership
- Separate customers, teams, projects, and environments
- Apply least privilege and individual accountability
- Rotate and revoke based on lifecycle events
- Review access and activity regularly
How to begin
Start with a narrow, high-risk workflow such as shared administrator passwords, production API keys, or customer credentials. Define ownership and access first, migrate the values, remove uncontrolled copies, and establish review and rotation responsibilities before expanding.