Assume the credential gets reused
People reuse passwords across the tools they use for work, and no policy document has ever changed that. So the design question is not whether a password leaks, it is what an attacker can reach once one does. Separating access by role limits the blast radius to something survivable.