If they could reach the Cloudflare account, or knew the passphrase of
selfhost.json, remove their account membership, choose a new passphrase (
self-host --change-passphrase), and rotate the secrets of every environment. A new passphrase doesn't lock them out of a copy of the file they already have, so the secrets have to change. Give the instance a new encryption key too (
self-host --rotate-key), so a copy of the database taken later doesn't open with the key they know.
self-host can't rotate
BETTER_AUTH_SECRET yet.