Home > Identity platforms

One Identity Manager and Key2XS: keys as a governed entitlement

One Identity Manager is a full identity governance suite: business roles, request and approval workflows, attestation campaigns and separation of duties. Key2XS makes physical keys one more entitlement inside that model, governed on iLOQ, ASSA ABLOY CLIQ and ABLOY PULSE by the same roles and the same recertification.

Request a demo

What One Identity Manager is

One Identity Manager is the identity governance and administration platform of One Identity, a Quest Software business. It is the heavier end of the identity market: not just an authentication layer, but a system of record for who may have what, why they may have it, and who signed off. It is generally deployed by organizations that have to defend their access model to an auditor.

The parts that matter for access decisions:

The wider One Identity portfolio surrounds this with privileged access management (Safeguard), access management (OneLogin) and Active Directory administration (Active Roles). Physical keys have never been part of any of it.

Mature governance, ungoverned keys

Organizations running One Identity Manager tend to take governance seriously. Access is modeled in business roles, requests pass through approval workflows, and assignments are periodically attested. Auditors get answers from the system, not from memory. Physical keys usually live outside that model: issued at a service desk, tracked in a separate application or a spreadsheet, disconnected from the role model that governs everything else.

For critical entities under NIS2 and the CER Directive, physical access to premises is explicitly in scope. A governance model that ends at the login screen leaves exactly the gap those directives target.

How Key2XS connects to One Identity Manager

Key2XS ships a companion application for One Identity Manager that exchanges assignments over REST. Synchronization runs on a polling cycle you configure, sixty seconds by default, so a revocation reaches the keys within a minute rather than overnight. Nothing in your role model has to be rebuilt.

ProtocolBidirectional REST API through a Key2XS companion app
AuthenticationSHA-256 hashed API key
DirectionBidirectional: entitlements in, provisioning status back
SynchronizationPolling, configurable, 60 seconds by default

Connect, map, orchestrate, prove

  1. Connect. The Key2XS companion app connects to your One Identity Manager environment over REST, and Key2XS connects to each key system over its own API. A standard integration is live in under two hours, with no custom development.
  2. Map. Business roles, application roles and entitlements are mapped to key rights and lock groups. A role like “Plant Engineer, Site South” can correspond to exactly the production halls, switch rooms and perimeter gates that role requires.
  3. Orchestrate. When an assignment is created, changed or removed, whether directly or through the IT Shop and its approval chain, Key2XS applies the matching change to the person's key rights on the next polling cycle. Deprovisioning a leaver withdraws their physical access in the same movement.
  4. Prove. Every key right traces back to an identity, a role and an approval decision, in one tamper-evident audit trail. Because key rights follow your roles, an attestation campaign that recertifies a role recertifies the physical access it grants.

What moves between One Identity Manager and Key2XS

From One Identity Manager To your key systems via Key2XS
Identities (joiners, movers, leavers) Key holders created, updated or deactivated
Business role and entitlement assignments Key rights and access to lock groups
Deprovisioning and expirations Withdrawal of key rights on the next cycle
IT Shop approval decisions Documented authorization behind every key

One source of truth, every key system

The point of connecting One Identity Manager to Key2XS is not a single lock brand. One Identity Manager becomes the one place where physical access is decided, and Key2XS carries that decision to whichever key systems your sites actually run. Most organizations have more than one: a digital locking system at the head office, electronic keys on the network, mechanical high-security cylinders on the perimeter.

Key system under governance How Key2XS drives it
iLOQ S5 and S50
Self-powered digital cylinders (S5) and Bluetooth/NFC phone keys (S50).
REST API. Key holders, key rights and key validity provisioned per person, with 29 independent sync operations.
ASSA ABLOY eCLIQ
Electronic cylinders, padlocks and programmable keys.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.
ASSA ABLOY PROTEC2 CLIQ
High-security locking combining rotating disc technology with electronic identification.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.
ASSA ABLOY CLIQ Remote
Remote key updates through wall programmers, desktop units or the CLIQ Connect Bluetooth app, so keys never have to come back to a desk.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Validity windows refreshed in the field.
ABLOY PULSE
Self-sustaining locks that harvest their energy from key insertion. No batteries, no wiring.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.

Key2XS is certified by ASSA ABLOY for its locking system integrations. One mapping in One Identity Manager can therefore span brands: a single role or group grants the iLOQ cylinders in one building and the eCLIQ padlocks on a remote site, revoked together the moment One Identity Manager says so.

The same holds on the identity side. Key2XS also connects to SailPoint Identity Security Cloud, Microsoft Entra ID, Okta and OpenText Identity Manager, and to any system that can speak SCIM 2.0, so a landscape with more than one identity platform still resolves to one physical access model. See the integrations overview for the full picture.

Built for critical environments

Key2XS is used where physical access affects public safety, service continuity or regulatory compliance: utilities, government, transport, healthcare and industry.

Why not extend One Identity Manager yourself?

One Identity Manager is famously extensible, and building a custom connector toward a locking system is conceivable. It is also a multi-month project that must be maintained across upgrades on both sides, hardened for edge cases in the leaver flow, equipped with its own audit layer, and repeated for every key system brand on your sites. Key2XS delivers this as a maintained platform:

Frequently asked questions

One Identity Manager and Key2XS, answered.

See One Identity Manager governing your keys

Get a guided walkthrough of how roles, approvals and physical keys come together in one auditable flow.