Hardcoded credentials scattered across repos, servers, CI jobs and laptops each carry their own breach risk that grows the longer they go unrotated. Because rotating a secret means finding and updating every copy of it, the more copies exist the less reliably rotation actually happens — sprawl doesn't just create more targets, it also makes the fix itself harder to execute. This simulation models that feedback loop directly: raw copies age and occasionally fail their rotation attempt, drifting into overdue, high-risk red; secrets migrated into a central vault instead become short-lived brokered leases that auto-rotate every cycle and stay a reassuring green. Adjust sprawl, rotation interval, vault adoption and simulated speed to see how centralizing secrets collapses aggregate breach exposure compared to just scheduling rotations more often.