Design identity before SCIM.
Workday, Entra, Okta, NetSuite, GitHub, and Slack mapped to one canonical Person, Group, and Role model. Keelix stores the shape of the system, not the people in it, and exports the evidence your team can hand off.
Shape only
Every system on a canvas, every attribute mapped back to Person, Group, or Role. The shape of your stack, not a slide deck approximation.
Evidence that travels
Architecture PDFs, SCIM blueprints, SOC 2 evidence bundles, and role playbooks. All generated from the model so they stay current.
Design, not orchestration
No live sync, no agent army, no six-figure IGA contract. Keelix is the workspace where you decide the model before anyone wires SCIM.
Clarity before complexity.
Enterprise IGA assumes the model already exists. Lucidchart doesn’t know what SCIM paths or extension attributes mean. Keelix is the focused workspace for the design layer: the step you take before provisioning, audit season, or a SailPoint SOW.
See the whole stack on one screen.
Drop in Workday, Entra, Okta, NetSuite, GitHub, or Slack from built-in templates or your own CSV. Draw attribute-level mappings to the keel. Coverage and gaps visible at a glance.
One canonical model everyone maps to.
Person, Group, and Role defined once with types, descriptions, and required flags. Change the keel and every mapping inherits it. Full version history with diffs and review tags.
Know when a system's shape changed.
Upload a column snapshot from any system. Keelix compares headers against your mappings and flags missing columns and unmapped fields. Structural drift only, never employee data.
Settle the provisioning map before you wire it.
Project the keel onto SCIM 2.0 User attributes, mark each system as SCIM push, JIT, or manual, and export a machine-readable blueprint for whoever implements it.
Onboarding runbooks that don't rot.
Pick a role. Keelix generates the step-by-step provisioning sequence from your current model: which systems, in what order, with which fields. Export as PDF, Markdown, or JSON.
Three moments where the spreadsheet fails.
Not a feature tour. These are the situations where a designed model beats tribal knowledge and a diagram that nobody updates.
Finance renamed a field. Nobody told IT.
Workday dropped cost_center_code from the export. Three mappings still read from it. Keelix flags the missing column the moment you upload a snapshot, then surfaces any new columns nothing maps to yet. Column-level drift, not employee records.
What you can finish in one sitting.
This is the beta bar, the journey we built the product around. An IT director should reach the exports without opening a support ticket.
- 1
Sign up and create a workspace
No sales call, no security review for API credentials. Keelix stores schema shape only, never people.
- 2
Model your three most important systems
Start from templates for Workday, Entra, Okta, NetSuite, GitHub, or Slack. Or import your own column list.
- 3
Define the keel and draw mappings
Person, Group, Role as your canonical model. Connect every system attribute back to it on the canvas.
- 4
Plan SCIM and exception profiles
Map keel attributes to SCIM paths, mark provisioning targets, and capture how contractors or LOA differ from the default.
The IT director between Lucidchart and SailPoint.
Keelix is for 200 to 2,000 person companies with a dozen identity systems and no dedicated IAM team. You need the model documented before audit season, before a reorg, or before you sign a six-figure IGA contract. Not another runtime to operate.
- Tribal knowledgeThe mapping lives in one person's head. When they leave, it leaves.
- Load-bearing shortcutsWhy does Entra use extensionAttribute7? Nobody remembers, but provisioning depends on it.
- Silent schema changeA renamed column in Workday breaks mappings nobody is watching until onboarding fails.
- Audit scrambleSOC 2 asks for the canonical model. You produce a spreadsheet the morning of the review.
- Exception sprawlContractors, LOA, service accounts. Each provisioned differently, none documented as policy.
Not SailPoint. Enterprise IGA runs what you already designed. Keelix is where you design it.
Not Lumos. Access reviews answer who has access. Keelix answers what your model is supposed to be.
Not Lucid. A diagram doesn’t understand SCIM paths, schema drift, or provisioning order.
Free during beta.
We’re rolling out slowly, in small waves, while we refine the product. Get in and use all of it: no credit card, no sales call. Paid tiers come later, with plenty of notice.
while in beta
Everything on the right, unlocked. No tiers, no feature gates, no usage caps.
No credit card · No API keys · No PII stored
- One workspace, unlimited systems
The model already exists.
It just doesn’t live anywhere you can trust.
Put it in Keelix. Model the systems, define the keel, export the evidence. Stop rebuilding the same diagram every audit season.