A couple years into my career, I was trying to get my AWS keys configured right locally. I hardcoded them into my .zshrc file. A few days later on a Sunday, forgetting that I'd done that, I committed and pushed that file to my public dotfiles repo, at which point those keys were instantly and automatically compromised.
After the dust settled, the CTO pulled me into the office and said:
1. So that I know you know: explain to me what you did, why it shouldn't have happened, and how you'll avoid it in the future.
2. This is not your fault - it's ours. These keys were way overpermissioned and our safeguards were inadequate - we'll fix that.
3. As long as it doesn't happen again, we're cool.
Looking back, 10 years later, I think that was exactly the right way to handle it. Address what the individual did, but realize that it's a process issue. If your process only works when 100% of people act perfectly 100% of the time, your process does not work and needs fixing.