1) devops/sre start to provide some guides on top of some cloud, nowdays it's k8s. Like default service templates.
2) service templates transforms into custom DSL with side configuration and k8s abstraction things.
3) Abstraction/libraries on top of secrets management.
4) Service configuration per enviroment.
At with point it's all good. But startup grows, and needs a secops team to get some internal audit. Or it could be a platform team initiative.
5) Audit shows critical issues with permissions and platform team starts to think about how to restrict access.
Mismatch with "old freedom" could be quite high for unprepared product teams. Platform becomes "inconvenient". It takes huge amount of resources to make it actually usable.