In steady state, an industrial site already stretches manual key administration: operators in rotating shifts, maintenance technicians moving between units, logistics staff, cleaning crews and the occasional external specialist. Keys are issued generously because production cannot wait for paperwork.
Then the maintenance stop arrives, and the population of the site multiplies. Hundreds of contractor workers, from dozens of firms, need access to specific units for exactly the duration of the turnaround. In most plants that becomes weeks of key issuance beforehand and months of incomplete key recovery afterwards, with a registry nobody fully trusts in between.
The stakes are not administrative:
NIS2 extends EU cybersecurity obligations to large parts of manufacturing and the process industry, including its requirement for appropriate policies governing access to premises, precisely because physical entry to a control room or switch room can compromise the OT and IT systems inside. Sites under major hazard regimes face parallel expectations for controlling access to hazardous installations, and customer and certification audits increasingly ask the same questions.
The test every framework converges on: can you demonstrate, for any door and any date, who held access, on whose authority, and when it changed? Key2XS makes the answer structural. Every key right derives from an identity and a role, every change is logged in a tamper-evident audit trail, and audits are answered from the system in minutes.
Key2XS is middleware between the IAM system you already run and the digital locking system already on your site. Nothing about your locks, keys or locking plan changes.
A typical flow: the annual turnaround of a production unit is planned. Contractor personnel are registered in the IAM under the turnaround project with a start and end date. Key2XS translates each registration into key rights for exactly the unit, workshops and gates that firm's scope covers. A scaffolder cannot open the switch room, a specialist can. When the stop ends, every one of those rights ends with it, on the date already in the system, whether or not the physical key has found its way back yet.
In steady state, operators and technicians hold access derived from shift roles and unit assignments, updated in near real-time when assignments change, and withdrawn in the same movement that offboards them digitally.
Implementation fits production reality: a standard integration is live in under two hours through pre-built connectors, with no custom development and no interruption to running operations.
The platform is engineered for 99.99% availability, and all communication is encrypted with TLS 1.3 in transit and AES-256 at rest.