An inventory of what a second person would need, produced by asking one person to stop using their own machine for a day.
found, in one day:
a registry token in a shell profile, created 2021
a database password in a saved connection, not in
the password manager
an ssh key with no passphrase and no copy
a DNS provider login on a personal account
none of these were secret from anybody. all of them
were absent from the place they were supposed to be.
The DNS account is the one that would have been genuinely difficult — a personal login at a provider with no organisation feature means a recovery process rather than a handover. Finding these needed the constraint of not using the machine; asking the same person what credentials exist produces a shorter and more optimistic list every time.