Skip to content

Enterprise ​

Enterprise is coming soon. It will extend Pro with external delegated identity, stronger change control, and stronger audit guarantees. The account-local control plane, Cognito operators, capability grants, and authorization decision log already ship as Pro foundations; the items below add organisation-wide identity and compliance posture.

Coming soon

Enterprise-only capabilities are not available today. Everything listed below is planned unless explicitly marked as a Pro capability that has already shipped. The order of delivery is not fixed.

The control plane foundation ​

Keel's optional control plane already runs inside your AWS account. IAM sessions use it for shared, cached reads and can fall back to direct AWS access. Pro operators have no direct AWS credential: the control plane evaluates their per-capability grants and brokers narrowly scoped operations.

That shipped foundation supports:

  • Shared reads and caching give every dashboard the same account-level view while avoiding repeated ECS, CloudWatch, and resource queries for each person watching it.
  • Operator authorization applies identity, capability, app and environment grants before a served or brokered operation proceeds.
  • Authorization history records allowed and denied requests, with correlation IDs that connect them to later AWS activity.

Keel does not host the API or gain standing access to it. Enterprise work will build external identity, approvals, schedules, and stronger audit storage on that same boundary rather than introducing a Keel-hosted dependency.

Identity ​

External federated identity (planned) — use Okta, Entra ID, or Google as the source of truth for who may operate Keel instead of the Pro operator pool. SCIM and joiner-mover-leaver support (planned) would remove Keel access when a person is removed from the directory, without a separate manual step.

Directly federating operators into IAM roles is not sufficient. AWS cannot verify whether an external identity provider actually required MFA. The shipped operator model already avoids that weakness by giving an operator no general-purpose AWS credential; Enterprise will replace Cognito's local roster with the organisation's identity source.

Identity and authority

Authenticate the person. Authorize the action.

Pro already separates a trusted operator identity from AWS authority. Enterprise delegates that identity and lifecycle to the company directory.

Pro — shipped

Cognito authenticates the operator; Keel authorizes each capability.

IdentityOperator Cognito poolPassword + pool-enforced MFA
Keel verifiesPrincipal + grantsCapability · app · environment
AuthorityOne served or brokered operationNo general AWS session

IAM team members remain the bootstrap and break-glass path, so the control plane cannot lock administrators out.

The operator pool is local to Keel and its lifecycle is managed manually rather than by the organisation's directory.

Enterprise

The identity provider authenticates the operator; Keel authorizes each action.

Customer managedCompany directoryIdentity · MFA · groups · lifecycle
Signed identityID tokenStable subject + group claims
Self-hosted in your AWS accountKeel control plane
  • Verify issuer, signature, and expiry
  • Resolve capability, app, and environment grants
  • Check action, approval, and window
  • Record both allows and denials
SCIM revokes departed usersGrants scope app × environmentContext adds approvals and windows
Allow
Operator actionOne approved AWS operationNo general AWS session on the laptop
Application accessAuthorized internal serviceIdentity plus enforced group membership
DenyNo AWS authority is created; the attempt is still recorded.

The API keeps the shipped capability checks and adds external identity, approvals, and deploy windows.

Credentials are short-lived and operation-scoped, and both allowed and denied requests are recorded server-side.

Customer identity Keel policy AWS enforcement

Per-service authorization (planned) — extend the login Pro puts in front of an internal service with an authorization decision: not only “this person signed in,” but “this person may use this application.” Keel would enforce group membership instead of merely forwarding it as a claim.

Change control ​

Approval gates and deploy windows (planned for Pro and Enterprise) — require a second person to approve a production deploy and define hours when deployment is refused.

Both editions will include the workflow, but the strength of the guarantee differs. Pro's client-side check is useful but can be bypassed by someone holding an IAM session. Enterprise would evaluate operator-path decisions through the control plane while keeping direct IAM assumption as an explicit, visible break-glass event.

Audit ​

A segregated audit account with Object Lock (planned) — write the decision log somewhere the people it describes cannot alter. A log held in the same account as the systems it records cannot provide the same separation.

Allowed and denied authorization decisions (shipped in Pro) — the control plane records both outcomes before serving or brokering the operation.

Effect capture and detections (planned) — record what an operation changed and alert on important patterns, extending the evidence beyond an exec transcript.

Recorded exec sessions (shipped in Pro) — AWS applies the cluster-level recording configuration even when a session starts outside Keel. Because ECS Exec records the terminal stream, a process can still suppress its own output; Enterprise will build on the transcript with effect logs rather than claim that every keystroke is captured.

Data access ​

Brokered database sessions (planned) — Pro gives each person a database identity so the engine can attribute statements. Enterprise would also place the decision to open a session behind a broker: who is requesting access, to which environment, for how long, and for what reason.

Pricing ​

Enterprise will be priced per AWS account and will include everything in Pro. Prices are not published yet. The intention is to list it on AWS Marketplace so organisations can purchase it against committed AWS spend.


  • Editions overview — compare all three editions and see how licensing works
  • Free — the edition everything is built on
  • Pro — the team capabilities already shipping and those still planned

Keel — the missing platform layer for AWS.