We follow automation approach provided by CyberArk for accounts onboarding, template driven approach for platform configuration, we have successfully managed password rotation for so many different endpoints, endpoint gets auto detected within hours of build completion (AD Joined machines), vaulted and password rotated. Manually managing vaulting is not a good design.