Wires secrets management so no secret is hard-coded: externalized config, Key Vault / environment injection, and rotation-friendly access. Use when a service needs credentials/keys/connection strings, when removing a hard-coded secret, or when wiring Key Vault. Do NOT use for authentication logic or authorization rules.