It makes sense at scale. If you are a company of two there are probably better solutions.
At scale, you can very granularly define policies for each secret. When a secret is accessed, it is done so through a user or application identity. Each access is also logged.