Summary
- Freshservice agents can search Keeper content and approve or deny access requests inside ticket workflows.
- Actions are processed through a customer-hosted Keeper Commander ServiceMode endpoint.
- The integration also supports Endpoint Privilege Manager and Cloud SSO device approvals.
Keeper Security has connected privileged-access approvals directly to Freshservice, bringing vault, endpoint-privilege, and device-access decisions into the service-management workflow used to receive the request.
Keeper Security said its new Freshservice Workflow App allows assigned agents to search Keeper content, configure permissions, and approve or deny requests from a Keeper Vault tab inside a ticket.
The integration addresses a recurring break in access-governance workflows. A request can begin inside an IT service-management platform, while the administrator fulfilling it has to move into a separate privileged-access system, locate the relevant record, change permissions, and then return to the ticket.
Each additional handoff can separate the approval record from the action that followed it. Decisions may also move into email or chat when administrators are under time pressure, weakening the audit trail around why privileged access was granted.
Keeper says requests initiated through Freshservice are processed through a customer-hosted Keeper Commander ServiceMode endpoint. Credentials are not stored in Freshservice, preserving a separation between the service-management interface and the underlying vault.
Craig Lurey, CTO and co-founder of Keeper Security, described the design boundary succinctly: “The cryptographic boundary cannot move outside Keeper.”
The integration can also support Endpoint Privilege Manager and Cloud SSO device approvals when paired with Keeper’s ITSM for Freshservice application. That gives administrators a common ticketing surface for several classes of privileged access rather than limiting the workflow to passwords stored in a vault.
The security value depends less on convenience than on whether the integration reduces ungoverned exceptions. Privileged-access programmes commonly concentrate on vaulting credentials and limiting standing permissions, while the approval path itself can become a weak point when administrators have to reconcile several systems manually.
Connecting the access decision with the originating ticket can provide clearer evidence of who requested access, who approved it, and which action was executed. It may also make later review easier where ticket records are retained alongside the decision history.
The integration still creates dependencies that have to be governed. Keeping credentials outside Freshservice reduces one class of exposure, but organisations still need to control which service agents are permitted to approve privileged changes and protect the customer-hosted Commander service that executes them.
That becomes more relevant as access requests expand beyond employees. Service accounts, automation, machine identities, and AI agents can require temporary or high-volume privileges that conventional helpdesk workflows were not originally designed to process.
Keeper is placing the integration within that wider identity shift. A workflow designed around occasional human requests may increasingly have to handle decisions involving both human and non-human identities without allowing temporary access to turn into permanent privilege.
The Freshservice Workflow App is available for organisations with an active Keeper Commander deployment. Its operational value will depend on whether customers use the integration to consolidate approval evidence and reduce standing access rather than simply accelerate existing processes.




