Hey @SFA, good questions.
Whenever the “Workforce Passwords” feature is enabled on a User Group, the users will gain access to a Personal Folder in Secrets Safe. The only way to hide that would be to remove that feature for those users.
As for whether or not these secrets are recoverable by a true Administrator, our documentation states that these should be:
Workforce Passwords should only be used for business credentials. Information stored in a personal folder is recoverable by an administrator of the site.
Ref: Workforce Passwords user guide | BI On-prem
As long as the account is not deleted, but rather quarantined instead, then the personal folder with secrets will not be removed.
Ref: KB0022538: Can users recover abandoned accounts, i.e. terminated or employees who quit?