Please add TOTP secret key change history to Passwords.
Please add audit logging for when the TOTP secret key is revealed/viewed/copied (just like passwords are)
This is important because in a system with 700+ users, if someone accidentally edits the TOTP secret key or removes it, there is no way to recover it and you might be permanently locked out of an account, if that account does not have any other 2FA methods configured. Some enterprise systems like Microsoft Entra do not issue TOTP one-time account recovery codes.
When users share passwords that have TOTP enabled on them, the TOTP secret key could be copied to a different authenticator app. Since the TOTP secret key is sensitive it should be treated like a password from an auditing and who knows it perspective.