Keeper Security has launched a Freshservice Workflow App designed to bring vault access and privileged access approvals into the ticketing environment used by IT and security teams.
The integration enables Freshservice agents to search Keeper vault content, configure permissions and approve or deny access requests from a Keeper Vault tab within a ticket. It supports requests involving Keeper vault access, Endpoint Privilege Manager and Cloud SSO device approvals.
The integration is intended to address a common workflow problem: access requests are raised in a ticketing system, but fulfilment often requires agents to switch to another platform, locate the relevant record or folder and manually apply permissions. Approval decisions may then be communicated through email or chat, creating delays and weakening the audit trail.
Under Keeper’s new workflow, an employee submits a request through a Freshservice service catalogue item. The assigned agent can then process the request without leaving the ticket. The company said this keeps the request, decision and fulfilment activity within a single, auditable workflow.
The integration runs through a customer-hosted Keeper Commander ServiceMode endpoint. Keeper said this allows its zero-knowledge encryption and access controls to remain in place, while credentials are not stored in Freshservice’s IT Service Management or Enterprise Service Management platform.
“The cryptographic boundary cannot move outside Keeper,” said Craig Lurey, chief technology officer and co-founder of Keeper Security. “This integration processes every approval through Commander ServiceMode on infrastructure owned and controlled by the customer, so the attack surface doesn’t expand when you wire Freshservice into your approval workflow.”
“Freshservice is the interface for the request, never the place where secrets are stored,” he added.
Darren Guccione, chief executive and co-founder of Keeper Security, said access approvals should be treated as identity decisions and remain within governed systems.
“Integrating Keeper into Freshservice keeps approval decisions inside a ticketing system that security teams already trust, which means zero standing privilege and full audit control stay intact,” he said.
Guccione added that the approach would become more important as access requests increased across human and machine identities in the “agentic era”.
The new app can also be used with Keeper’s ITSM for Freshservice app. Together, the tools support ticket creation, access fulfilment and approval workflows through a single interface. The company said this gives security administrators a common process for incident-driven access requests and routine approvals.
Keeper’s documentation states that the app allows agents to search the Keeper Vault, configure sharing permissions, generate one-time share links and approve or deny Endpoint Privilege Manager and Cloud SSO device requests from within a ticket.
The Keeper Security Freshservice Workflow App is available through the Freshworks Marketplace for organisations with an active Keeper Commander deployment, according to the company.











