Across critical infrastructure, utilities, transport, government and industrial environments, organizations are replacing traditional mechanical keys with electronic key and locking systems. The business case is compelling.
Electronic keys can be activated and revoked. Access can be limited in time. Events can be logged. Lost keys no longer automatically mean replacing an entire lock estate. And organizations gain significantly more control over who can enter critical locations. But there is a problem.
In many organizations, it creates another system that needs to be managed.
A modern electronic key system may manage thousands or even tens of thousands of cylinders, keys and access permissions. Technically, the system works.
Operationally, things quickly become more complicated. Employees join, change roles and leave. Contractors need temporary access. Projects start and finish. Emergency access must be granted. Keys get lost. Responsibilities move between departments. Access rights need to be reviewed.
Meanwhile, the information required to make those decisions usually lives somewhere else. Identity information may be held in Microsoft Entra ID. Governance processes may run through SailPoint, One Identity, Okta or another IAM or IGA platform. Service requests may originate in systems such as TOPdesk. Security events need to reach the SOC or SIEM.
The electronic key system is therefore only one component in a much larger access lifecycle. And without integration, somebody has to connect those worlds manually. That somebody is usually the administrator.
Imagine an organization with 5,000 employees and contractors, 15,000 electronic keys and thousands of locks distributed across hundreds of sites.
The organization already knows who its users are. HR knows whether they are employed. IAM knows their identity. IGA knows their roles and entitlements.
But the key management system may know none of this.
The result is duplication.
A user is created in one system and recreated in another. A role changes in IAM, but physical access needs to be adjusted separately. A contractor’s assignment expires, but someone still needs to remove the associated key permissions.
Every manual handover creates another opportunity for delay, inconsistency and error.
Over time, access rights accumulate.
Nobody deliberately designs this situation. It simply emerges because identity management and physical key management evolved as separate disciplines.
For administrators, this fragmentation means work. For auditors, it creates a different problem. They do not simply want to know whether an electronic key system exists. They want evidence:
Who had access to this critical asset?
Why did they have access?
Who approved it?
Was the permission still appropriate?
Was access revoked when the person changed role or left?
Can you demonstrate that consistently?
This becomes increasingly relevant as organizations operating critical infrastructure face stronger governance requirements under frameworks such as NIS2 and the Critical Entities Resilience Directive. A spreadsheet, an IAM report and an export from a key management system may individually contain pieces of the answer. The challenge is proving that they represent one controlled process.
There is another stakeholder who is often forgotten in physical access projects. The person who actually needs to open the door. A field engineer does not care about IAM architecture, APIs, key management servers or identity governance.
They want to arrive at a site and get in.
Ideally, they receive the correct access automatically because their identity, role, assignment and authorization already establish that they should have it. They should not need to understand which system controls the lock. They should not have to call a helpdesk because two databases are out of sync. And they certainly should not have to wait for three different administrators to update three different systems. Good security should not create unnecessary friction.
Key2XS connects the identity world with the physical key and locking world. Instead of treating physical access as an isolated administrative process, Key2XS makes it part of the existing identity lifecycle. The principle is simple:
Key2XS integrates IAM and IGA platforms with electronic key and locking systems, translating identity decisions into physical access permissions and feeding relevant status and events back into the governance environment.
This creates an abstraction layer between two technology domains that historically had very little to do with each other. On the identity side, organizations can continue using platforms such as Microsoft Entra ID, SailPoint, Okta or One Identity. On the physical side, they can operate systems from vendors such as ASSA ABLOY and iLOQ. Key2XS connects them.
That distinction matters because large infrastructure organizations rarely operate one homogeneous lock estate. Different regions, acquisitions, asset types and replacement cycles frequently result in multiple locking technologies being used simultaneously. Replacing all of them simply to achieve centralized governance is expensive and often unnecessary. Key2XS allows organizations to govern across them.
The impact becomes visible when an employee changes role. Without integration, that change can trigger several administrative processes. Logical permissions are updated. Physical permissions are reviewed separately. Somebody may need to update the key management platform. Another person may have to check whether the change was actually implemented.
With Key2XS, the identity change can become the trigger. The appropriate physical access policy is evaluated and translated to the connected key system. The resulting state can be tracked and reported. The same model applies when somebody joins, leaves, changes department, starts a project or receives temporary access. This is particularly important for contractors.
Critical infrastructure organizations often depend heavily on external engineers and service companies. These users may need access to highly sensitive assets, but only for a particular task, region or period. Standing access is convenient. Governed, time-bound access is safer.
Key2XS does not try to give administrators another management console they have to spend their day operating. The objective is the opposite.
Automate routine access lifecycle decisions. Reduce duplicate administration. Use existing identity information. Make exceptions visible. Allow administrators to focus on the cases that actually require human judgment. The best access request is often the one an administrator never has to process manually.
The same architecture creates a stronger audit trail. Instead of reconstructing physical access decisions from separate systems, organizations can connect the permission to the identity and the underlying governance decision. That changes the conversation with an auditor. The question is no longer simply: “Which keys can open this lock?” It becomes:
“Which identities are authorized to access this asset, under which policy, based on which approval, and what happened when that authorization changed?”
That is Physical Access Governance.
For users, most of this technology should become invisible.
An engineer should receive the access required for the job. Temporary permissions should become available when required. Changes should propagate without unnecessary helpdesk intervention.
Depending on the underlying key technology and deployment model, access can be activated or updated through connected infrastructure, online cylinders, mobile devices or electronic keys. The experience becomes much closer to modern digital access. The user does not manage permissions. The identity does.
This is ultimately the larger transition taking place. For decades, physical keys were managed as physical objects. IT managed identities, accounts and applications. Facilities or security managed locks and keys. Electronic locking systems have blurred that boundary.
A modern electronic key is effectively a digital credential controlling access to a physical asset. Once that happens, managing it outside the organization’s identity governance framework becomes increasingly difficult to justify.
The technology is converging. Governance now needs to follow.
Organizations do not need another isolated security platform. They need fewer silos.
Key2XS is designed to make electronic locking systems part of the identity infrastructure organizations already operate. For administrators, that means less manual work. For auditors, it means better evidence and clearer governance. For security teams, it means better visibility and control.
And for the engineer standing in front of a transformer station, railway asset, water facility, data centre or other critical location, it means something much simpler:
The right person. The right access. At the right time. Without the hassle.
That is what physical access should look like when identity, policy and technology finally work together.