Best practice in bigger environments who is able to create a vault?

Is there any best practices in bigger envs (1000+ users) who’s should be able to create a vault or how a vault is created?
I want to reduce „completely uncontrolled environment“

Regards c

