Healthcare runs on a workforce that changes composition every single day: shifts around the clock, flex pools, agency staff, students and interns rotating through departments, volunteers, and external technicians maintaining medical equipment. Every one of them needs access to some spaces, and none of them should keep it a day longer than their role justifies.
Manual key administration cannot keep up with that motion:
In a sector where the doors protect controlled substances, patient privacy and care continuity, the gap between the staffing reality and the key administration is not a back-office problem. It is a patient safety and compliance problem.
Healthcare providers in the Netherlands work under NEN 7510, the healthcare information security standard, which includes physical access controls for spaces where patient information and critical systems reside. NIS2 brings the health sector into scope of EU cybersecurity law, with its explicit requirement for policies governing access to premises. And around controlled substances, pharmacists and inspectorates expect demonstrable control over who can reach medication storage. Hospitals are also designated critical entities under the CER Directive, which extends resilience obligations to their physical infrastructure.
The common denominator is demonstrability. With Key2XS, every key right exists because an identity holds a role that policy maps to that space, and every grant, change and revocation is recorded in a tamper-evident audit trail. When an inspection asks who could open the medicine room in a given week, the answer is a query, not a reconstruction from handover notes.
Key2XS is middleware between the IAM system you already run and the digital locking system already on your doors. Nothing about your locks, keys or locking plan changes.
A typical flow: an agency nurse joins the flex pool for the surgical wards. Their registration in the IAM carries the flex pool role and an engagement end date. Key2XS translates that into key rights for exactly the wards and supply rooms the role covers, and, where the role justifies it, the medicine room. When the nurse moves to a different pool, the rights move with the role in near real-time. When the engagement ends, the physical access ends with it, on the date the IAM already knows.
For support and technical staff, the same principle governs server rooms, technical spaces and archives: access derives from role, expires with the assignment, and is logged throughout.
Implementation does not burden care operations: a standard integration is live in under two hours through pre-built connectors, with no custom development and no interruption to running systems.
The platform is engineered for 99.99% availability, matching an environment that never closes, and all communication is encrypted with TLS 1.3 in transit and AES-256 at rest.