Singapore – Keeper Security has launched a Freshservice Workflow integration that lets IT and security agents search the Keeper vault and fulfil privileged access requests directly from a Freshservice ticket, the company announced on 1 October 2026.
The app covers Keeper vault access and approval requests, including Endpoint Privilege Manager and Cloud SSO device approvals, according to Keeper Security. The company, which describes itself as a zero-trust and zero-knowledge identity security and Privileged Access Management (PAM) platform, says the tool removes the need for agents to leave tickets or log into a separate system.
It also aims to stop approvals moving through unaudited side channels such as email or chat, Keeper Security says.
Access approvals often stall after the initial request, the company notes. A user submits a helpdesk ticket, but the person fulfilling it must leave that ticket, find the right record or folder and manually grant permission before reporting back.
Each of those handoffs, Keeper Security argues, adds delay and pushes access decisions outside the audit trail.
Under the new workflow, an employee submits a request through a Freshservice service catalogue item. The assigned agent can then search Keeper content, configure permissions and approve or deny the request from a Keeper Vault tab inside the ticket.
Every action runs through a customer-hosted Keeper Commander ServiceMode endpoint, according to the company. As a result, Keeper’s zero-knowledge encryption and access controls stay intact, and Keeper never stores credentials inside Freshservice’s IT Service Management (ITSM) and Enterprise Service Management (ESM) platform.
Addressing that architecture, Craig Lurey, CTO and Co-founder of Keeper Security, said the design keeps sensitive data under customer control.”The cryptographic boundary cannot move outside Keeper,” said Lurey.
“This integration processes every approval through Commander ServiceMode on infrastructure owned and controlled by the customer, so the attack surface doesn’t expand when you wire Freshservice into your approval workflow. Freshservice is the interface for the request, never the place where secrets are stored,” Lurey added.
Meanwhile, Keeper Security’s leadership framed the launch as an audit and governance matter.
“Every access request is an identity decision, and the further those decisions drift from a governed system, the weaker the audit trail becomes,” said Darren Guccione, CEO and Co-founder of Keeper Security.
“Integrating Keeper into Freshservice keeps approval decisions inside a ticketing system that security teams already trust, which means zero standing privilege and full audit control stay intact. This becomes increasingly important in the agentic era, as access requests multiply across both human and machine identities,” Guccione continued.
Beyond standard vault requests, the integration also supports Endpoint Privilege Manager and Cloud SSO device approvals when paired with Keeper’s ITSM for Freshservice app.
That pairing, the company says, gives security admins a single ticketing interface for both incident-driven access requests and routine approval workflows.

