Secrets scattered across a separate permission model create risk teams have to manage on top of the CI job itself.
GitLab Secrets Manager, now in limited availability, injects each secret into the CI job that needs it, scoped to that job's environment and branch, with no separate permission model to maintain.