Organizations running One Identity Manager tend to take governance seriously. Access is modeled in business roles, requests pass through approval workflows, and assignments are periodically attested. Auditors get answers from the system, not from memory.
Physical keys usually live outside that model. They are issued at a service desk, tracked in a separate application or a spreadsheet, and disconnected from the role model that governs everything else. The consequences are familiar:
For critical entities under NIS2 and the CER Directive, physical access to premises is explicitly in scope. A governance model that ends at the login screen leaves exactly the gap those directives target.
Key2XS is middleware that makes iLOQ key rights behave like any other entitlement in One Identity Manager: derived from roles, driven by lifecycle events, and always traceable to a decision.
| From One Identity Manager | To iLOQ via Key2XS |
|---|---|
| Identities (joiners, movers, leavers) | Key holders created, updated or deactivated |
| Role and entitlement assignments | Key rights and access to lock groups |
| Deprovisioning and expirations | Immediate withdrawal of key rights |
| Approval decisions | Documented authorization behind every key |
Changes flow through in near real-time, so a revocation in One Identity Manager does not wait for a nightly batch to reach your keys.
Key2XS is used where physical access affects public safety, service continuity or regulatory compliance: utilities, government, transport, healthcare and industry.
One Identity Manager is famously extensible, and building a custom connector toward iLOQ is conceivable. It is also a multi-month project that must be maintained across upgrades on both sides, hardened for edge cases in the leaver flow, and equipped with its own audit layer. Key2XS delivers this as a maintained platform: