Different secrets grant different authority
A handset secret permits an endpoint relationship. A trunk credential can permit chargeable service. Administrative access can change the entire platform. Backup credentials can expose configuration and other stored data. Reusing one secret across these roles increases the consequence of a single compromise.
Provision without broad disclosure
Use unique strong secrets and a controlled provisioning process. Do not store them in screenshots, public issue reports or ordinary call-flow diagrams. Restrict configuration exports and remove temporary copies after their authorized purpose ends.
Track ownership
Maintain an inventory of account owner, device or service, permission scope and rotation/revocation procedure. Shared-area phones need an accountable owner even when no employee is named on the device.
Revoke completely
When staff or contractors leave, review forwarding, voicemail, remote access and management permissions as well as the visible extension name. Rotate relevant credentials and verify that retired devices cannot re-register. A factory reset of one handset does not invalidate copies of its secret elsewhere.
Sources & applicability
Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.