---
title: "Bridging Worlds: How Logical and Physical Access Are Converging and Why Key2XS Is Out in Front"
description: Verken hoe Key2XS IT- en fysieke toegang samenbrengt, met één identiteitsbeheer voor verhoogde veiligheid en naleving van regelgeving. CER  ...
image: https://key2xs.com/hubfs/2keyholekey2xs.png
---

[![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg) ![Key2XS](https://key2xs.com/hubfs/img/logo-blue-horizontal.svg)](https://key2xs.com/?hsLang=nl)

 Why Governance?

[Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=nl) [CER Directive](https://key2xs.com/cer-directive?hsLang=nl) [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=nl) [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=nl) Analyst recognition [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=nl)

 Industries

[Government](https://key2xs.com/sectors/government?hsLang=nl) [Utilities](https://key2xs.com/sectors/utilities?hsLang=nl) [Water management](https://key2xs.com/sectors/water-management?hsLang=nl) [Transport](https://key2xs.com/sectors/transport?hsLang=nl) [Telecom](https://key2xs.com/sectors/telecom?hsLang=nl)

 Platform

[Product](https://key2xs.com/products?hsLang=nl) [How it works](https://key2xs.com/?hsLang=nl#how-it-works) [Integrations](https://key2xs.com/integrations?hsLang=nl) [Book a demo](https://key2xs.com/contact?hsLang=nl)

 Partners

Technology partners [SailPoint](https://key2xs.com/sailpoint-partnership?hsLang=nl) [One Identity](https://key2xs.com/partners/one-identity?hsLang=nl) [Microsoft Entra ID](https://key2xs.com/partners/entra-id?hsLang=nl) [Okta](https://key2xs.com/partners/okta?hsLang=nl) [OpenText](https://key2xs.com/partners/opentext?hsLang=nl) [iLOQ](https://key2xs.com/partners/iloq?hsLang=nl) [ASSA ABLOY](https://key2xs.com/partners/assa-abloy?hsLang=nl) Resell & Implementation partners [Hanab](https://key2xs.com/partners/hanab?hsLang=nl)

 Resources

[Resource center](https://key2xs.com/resources?hsLang=nl) [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=nl) [Events](https://key2xs.com/events?hsLang=nl) Meet us at Navigate [Navigate Austin · Oct 5-8](https://key2xs.com/events/sailpoint-navigate-austin?hsLang=nl) [Navigate London · Nov 2-4](https://key2xs.com/events/sailpoint-navigate-london?hsLang=nl) [ROI calculator](https://key2xs.com/roi-calculator?hsLang=nl) [FAQ](https://key2xs.com/?hsLang=nl#faq)

[News](https://key2xs.com/news-archive?hsLang=nl) 

[Book a demo](https://key2xs.com/contact?hsLang=nl) 

[Book a demo](https://key2xs.com/contact?hsLang=nl)

[← The Key2XS journal](https://key2xs.com/news-archive?hsLang=nl)  
ASSA Abloy Cliq

# Bridging Worlds: How Logical and Physical Access Are Converging and Why Key2XS Is Out in Front

Aug 18, 2025 · 6 min read · by the Key2XS team

![Bridging Worlds: How Logical and Physical Access Are Converging and Why Key2XS Is Out in Front](https://key2xs.com/hubfs/2keyholekey2xs.png)

**In short:** Logical and physical access are converging: identities now span cloud apps, substations and doors, and resilience requires governing both with one policy fabric. Key2XS sits at that intersection, translating IAM decisions into physical key rights with full auditability.

 

# **Bridging Worlds: How Logical and Physical Access Are Converging and Why Key2XS Is Out in Front**

 

## **Executive summary**

The boundary between IT (“logical” access) and OT/facility security (“physical” access) is disappearing. Identities now span cloud apps, data centers, substations, pumps, and doors. To stay resilient, critical entities need one identity fabric that governs both domains with the same policies, telemetry, and accountability.

**Key2XS** sits at the center of this shift: it connects electronic key and cylinder systems (e.g., [ASSA ABLOY CLIQ](https://key2xs.com/integrations/assa-abloy-cliq?hsLang=nl), [iLOQ](https://key2xs.com/integrations/iloq?hsLang=nl)) with leading IAM platforms (Microsoft Entra ID, [SailPoint](https://key2xs.com/integrations/sailpoint-iloq?hsLang=nl), Okta, One Identity and others), so you can govern real-world access with the same rigor you apply to systems and data.

*The Key2XS platform is protected by several patents pending, ensuring its unique approach and innovation remain unmatched in the market.*

 

## **Why convergence is happening now**

**1) Shared risk surface.** Hybrid attacks blend credential abuse with on-site manipulation (e.g., opening a cabinet to plug in a rogue device). Treating logical and physical access separately leaves blind spots.

**2) Regulation & accountability.** Frameworks like [NIS2](https://key2xs.com/nis2-directive?hsLang=nl) and the [CER Directive](https://key2xs.com/cer-directive?hsLang=nl) require provable control over identities, suppliers, and incidents across IT and OT.

**3) Workforce dynamics.** Contractors and mobile crews need time-bounded, context-aware access both to apps and to assets in the field.

**4) Tech maturity.** Modern IAM, policy engines, and electronic keys now support real-time provisioning, revocation, and audit at scale.

 

## **What true convergence looks like**

**One identity, one policy, everywhere.**

- **Authoritative source:** HR/IAM is the “single source of truth” for people, roles, and lifecycle events.
- **Policy portability:** The same role/attribute rules that grant a user SCADA read-only access also grant the **right physical keys** for the right doors, cabinets, and padlocks.
- **Just-in-time (JIT) & least privilege:** Keys activate only when needed, for specific jobs and time windows, then expire automatically.
- **Unified telemetry:** Door events and key audit trails stream into the SOC alongside identity and endpoint signals for correlation and response.
- **Automated revocation:** Terminate or offboard once in IAM; both badge/keys and app access are removed instantly.
  
  ![one-key2xs](https://key2xs.com/hs-fs/hubfs/one-key2xs.png?width=1021&height=772&name=one-key2xs.png)

 

## **Architecture at a glance**

1. **IAM / IGA ([Entra ID](https://www.microsoft.com/nl-nl/security/business/identity-access/microsoft-entra-id), [SailPoint](http://www.sailpoint.com), [Okta](http://www.okta.com), [One Identity](http://www.oneidentity.com), [OpenText/NetIQ](https://www.opentext.com/products/identity-manager)** and others**)** holds identities, roles, and SoD policies.
2. - Translates IAM roles into granular physical permissions.
     - Provisions/updates **electronic keys and cylinders** (e.g., [ASSA ABLOY CLIQ](https://www.assaabloy.com/nl/nl/solutions/topics/digital-access-solutions/cliq), [iLOQ](http://www.iloq.com)).
     - Collects audit trails and pushes events to SIEM/SOAR.
     - Applies **AI assistance** to propose keyplans, detect anomalies, and optimize cylinder/route management.
       
       **Key2XS** acts as the **bridge/orchestrator**:
3. **Physical endpoints** (keys, cylinders, cabinets, gates) enforce access offline/online; syncs validate and rotate permissions.
4. **SOC & OT monitoring** receive unified alerts, enabling **playbooks** that include both door/asset response and logical remediation.

 

## **Zero Trust for the real world**

- **Never trust, always verify:** A key alone isn’t enough; **context** (who, when, where, job ticket) is evaluated before activation.
- **Continuous evaluation:** Access can be paused based on risk signals (e.g., compromised contractor identity, unusual travel, failed PIN attempts on multiple cabinets).
- **Micro-segmentation of the physical estate:** Keys activate only for the precise set of cylinders a work order requires.

 

## **Compliance, simplified**

- **Lifecycle evidence:** Every grant, change, and revocation is linked to the identity and business justification from IAM.
- **Incident reporting:** Physical events (forced openings, repeated denials) correlate with logical anomalies for faster root cause and structured reporting.
- **Third-party control:** Contractors get **time-boxed, scope-limited** access with full traceability and easy renewal/termination.

 

## **Where Key2XS leads ![11E4DBC6-36FB-45C2-894C-6D9DE1EA2AEF](https://key2xs.com/hs-fs/hubfs/11E4DBC6-36FB-45C2-894C-6D9DE1EA2AEF.png?width=40&height=60&name=11E4DBC6-36FB-45C2-894C-6D9DE1EA2AEF.png) **

**1) Native bridge between IAM and key systems**

Key2XS natively integrates with **ASSA ABLOY CLIQ** and **iLOQ** (among others) while speaking the language of **Entra ID, SailPoint, Okta, OpenText and One Identity**. No brittle custom glue.

**2) Role-driven keyplans**

Turn roles and attributes into **automated keyplans**. When a technician joins a team or picks up an on-call shift, Key2XS issues the minimum set of grants to both applications and cylinders then retracts them when the shift ends.

**3) AI-assisted operations**

- **Auto-generated keyplans** from org roles, site topology, and uploaded infrastructure data.
- **Anomaly detection** (e.g., unusual route/sequence across cabinets, repeated after-hours attempts).
- **Optimization** for cylinder maintenance, permission hygiene, and field efficiency.

**4) Unified audit & response**

Stream standardized events and audit trails into your SIEM/SOAR so playbooks can: disable a user, **pull all electronic key rights**, alert the field team, and lock down sensitive cabinets **in one motion**.

**5) Built for critical entities**

Offline-capable keys, robust audit trails, and privacy-by-design controls suit utilities, transport, water, telecom, healthcare, and government infrastructure.

**6) Protected innovation**

The Key2XS platform is safeguarded by **several patents pending**, covering its unique orchestration between IAM systems and electronic key ecosystems ensuring customers benefit from capabilities unavailable anywhere else.

 

## **ROI you can quantify**

- **Fewer truck rolls & re-cylindering:** Electronic permission changes replace mechanical rekeying after loss or role change.
- **Faster contractor onboarding:** Provision once in IAM, **keys + apps** follow automatically.
- **Audit without heroics:** Evidence is generated by default, cutting prep time for assessments and investigations.
- **Reduced downtime risk:** Correlated telemetry shortens detection and response for hybrid incidents.

 

## **Implementation roadmap (90 days to value)**

**Weeks 0–2: Foundations**

- Connect IAM and import roles; define critical sites and cylinders; map contractors.

**Weeks 3–6: Pilot & JIT**

- Select a region/asset class; enable JIT keys for maintenance and emergency crews; integrate SIEM.

**Weeks 7–10: Scale & automate**

- Expand to additional vendors/sites; switch on AI keyplan recommendations; align SOC playbooks.

**Weeks 11–13: Prove & optimize**

- Validate KPIs (MTTR, audit readiness, onboarding time, permission hygiene); tune policies and SoD.

**Suggested KPIs**

- Time to provision/revoke (apps + physical).
- % of JIT vs. standing permissions.
- Audit exceptions and remediation time.
- MTTR for hybrid incidents.
- Contractor onboarding time.

 

## **Example use case (anonymized)**

A grid operator needed to grant weekend access to a contractor for timed substation work. Through Key2XS, the operations lead approved a **work-order role** in IAM. Key2XS generated the minimal keyplan, activated it for a six-hour window, and streamed all door events to the SIEM. When the ticket closed, both logical and physical rights expired. The SOC retained a unified audit trail for compliance reporting.

 

## **What to look for in a convergence platform**

- **Tight, supported integrations** with your IAM and key systems no bespoke one-offs.
- **Policy & SoD alignment** between logical and physical domains.
- **Offline resilience** with verifiable audits.
- **Event normalization** for your SIEM/SOAR.
- **AI that explains itself** (transparent recommendations and change logs).
- **Vendor partnerships** and a roadmap for additional lock/key ecosystems.
- **Patented or patent-pending innovations** to ensure long-term differentiation.

 

## **Conclusion**

Logical and physical access are no longer separate problems. Identities, policies, and evidence must move as one especially for critical entities facing hybrid threats and rising regulatory pressure. **Key2XS**, protected by **several patents pending**, is purpose-built for this reality: a reliable bridge that turns IAM intent into precise, auditable control over the physical world without friction for your workforce.

*Interested in a deeper dive?* We can tailor a short workshop to your estate and show how your existing IAM roles translate into safe, just-in-time physical access with unified audit and response.

![](https://key2xs.com/hubfs/1587550138006.jpeg)![](https://key2xs.com/hubfs/img/niels-bakker.png)![](https://key2xs.com/hubfs/1746630921693.jpeg)![](https://key2xs.com/hubfs/1696359051569.jpeg)

**Written by the Key2XS team**

Key2XS is founder-run. Questions about this piece land with the people who built the platform. [Talk to us](https://key2xs.com/contact?hsLang=nl).

## Keep reading

[![](https://key2xs.com/hubfs/19294161_m.png) **Keeping Rotterdam’s Refineries Safe with Key2XS and Proving CER Compliance**Sep 08, 2025](https://key2xs.com/news/keeping-rotterdams-refineries-safe-with-key2xs-and-proving-cer-compliance?hsLang=nl) [![](https://key2xs.com/hubfs/205665854_m.png) **Using Key2XS in the Transportation Sector under the CER Directive**Sep 22, 2025](https://key2xs.com/news/using-key2xs-in-the-transportation-sector-under-the-cer-directive?hsLang=nl) [![](https://key2xs.com/hubfs/237024142_m.png) **Seamless Transitions: How Key2XS Simplifies Migration Between IAM and Locking Systems**Nov 03, 2025](https://key2xs.com/news/seamless-transitions-how-key2xs-simplifies-migration-between-iam-and-locking-systems?hsLang=nl)

## Govern the keys you already have

See identity, policy and physical keys in one 30-minute demo, scoped to your estate.

[Book a demo](https://key2xs.com/contact?hsLang=nl) [More in the journal](https://key2xs.com/news-archive?hsLang=nl)

### Contact us

[Wilhelmina van Pruisenweg 104, 2595 AN Den Haag](https://maps.google.com/?q=Wilhelmina+van+Pruisenweg+104+Den+Haag)

Kraanspoor 50, 1033 SE Amsterdam, The Netherlands 

[info@key2xs.com](mailto:info@key2xs.com) [+31(0)70 2045180](tel:+31(0)702045180)

### Platform

- [Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=nl)
- [Product](https://key2xs.com/products?hsLang=nl)
- [Integrations](https://key2xs.com/integrations?hsLang=nl)
- [ROI calculator](https://key2xs.com/roi-calculator?hsLang=nl)

### Compliance

- [CER Directive](https://key2xs.com/cer-directive?hsLang=nl)
- [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=nl)
- [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=nl)

### Company

- [SailPoint partnership](https://key2xs.com/sailpoint-partnership?hsLang=nl)
- [Resource center](https://key2xs.com/resources?hsLang=nl)
- [Events](https://key2xs.com/events?hsLang=nl)
- [News](https://key2xs.com/news-archive?hsLang=nl)
- [Contact](https://key2xs.com/contact?hsLang=nl)

[![Penetration tested and verified by Sekurno](https://key2xs.com/hubfs/img/badges/sekurno-pentest-badge-white.svg)](https://www.sekurno.com/verified/key2xs) [![KuppingerCole Analysts Rising Star 2026 badge for Key2XS](https://key2xs.com/hubfs/img/badges/kuppingercole-rising-star-2026-key2xs.svg)](https://key2xs.com/analyst-recognition?hsLang=nl)

---

![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg)

Key2XS, pronounced “key to access”

© 2026 Key2XS B.V. All rights reserved

<https://www.linkedin.com/company/key2xs>

[Privacy](https://key2xs.com/privacy-statement?hsLang=nl)  Cookie Preferences

Patent Pending Nr: 2040721 & 2041284

Key2XS & ActiveAuth are registered trademarks of Key2XS Assets B.V.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Key2XS",
    "url" : "https://key2xs.com/news/author/key2xs-2"
  },
  "dateModified" : "2025-09-16T07:21:28.135Z",
  "datePublished" : "2025-08-18T07:00:00.000Z",
  "headline" : "Bridging Worlds: How Logical and Physical Access Are Converging and Why Key2XS Is Out in Front",
  "image" : [ "https://key2xs.com/hubfs/2keyholekey2xs.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://key2xs.com/news/bridging-worlds-how-logical-and-physical-access-are-converging-and-why-key2xs-is-out-in-front",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://key2xs.com/hubfs/logo%20blue.svg"
    },
    "name" : "Key2XS B.V."
  }
}
```