Its all fun and games until some doofus posts a password in Slack and now your security team demands 30 days retention and you can't use Slack to search for anything any more.
If a doofus posts a password, the doofus gets to run the password rotation runbook for that service, done. If the runbook is too long, a PR to automate it is a great alternative.
In one particularly unfortunate case I can recall, the same engineer, having been thoroughly tired out by the lengthy and stressful (production-critical) rotation procedure, then pasted the new password again when announcing the rotation's completion. But it never happened after that. :-)