
About the company
Keiki is a product company focused on mobile apps for early childhood development. Its solutions combine learning with interactive play, helping children build foundational skills through games, exercises, and engaging content.
Its flagship app, Keiki World, has reached over 12 million downloads, bringing together games, activities, and animations in a single, safe environment. As adoption grew, the company expanded both its product and infrastructure to support increasing demand.
Project Period: April–June 2025
Ukraine
EdTech
Single Sign-On (SSO)
Multi-Factor Authentication (MFA)
Centralized Access Management
Onboarding time reduced from 1–2 days to 10–30 minutes
IT requests dropped by 50–70%
Offboarding access revoked in 5–15 minutes
When a company grows quickly, access management shifts from a background IT task to a critical part of daily operations. Each new hire requires access to 20+ tools, and shared accounts across teams add further complexity.
In this setup, security must not slow people down. It needs to work automatically, without delays, repeated approvals, or manual errors.
To bring structure to access management and prepare for further growth, Keiki partnered with Cloudfresh, an official Okta partner.
As the team expanded, so did the number of services required for everyday work.
At the start of the project, Keiki had around 40 employees, each using more than 20 tools. Manual provisioning meant hundreds of repetitive actions during onboarding, plus additional checks during offboarding.
Their previous password manager stored credentials but did not provide centralized control. The team needed a system that would work reliably for both 40 and 100+ employees without adding operational overhead.
After implementing Okta, access to all company services was consolidated into a single system.
Instead of assigning tools one by one, Keiki introduced role-based access groups. Each role is linked to a predefined set of services.
Now, access is granted automatically based on position. New employees start with everything they need on day one, without waiting for manual setup.
When someone changes roles or joins a project, additional permissions are assigned through the same system—no email chains or approval loops required.

Okta established consistent access control rules across the organization:
Administrators also introduced password policies (length, complexity requirements), reducing the risk of compromised accounts and improving overall security posture.
This approach made access easier to manage and simplified audits.
Shared accounts are common across marketing, product, and operations teams—but they often introduce risk.
Together with Cloudfresh, Keiki introduced an approach to manage shared access through Okta.
The team can now grant access without sharing passwords, control MFA from a single place, and keep operations running smoothly regardless of team changes.
As a result, access to critical tools no longer depends on a specific person or device.
The new system supports Keiki’s current structure and scales without requiring redesign as the team grows beyond 100 employees.
Okta now serves as the foundation for managing access as the company grows.

After centralizing access, the Keiki team and Cloudfresh plan to introduce Okta Identity Governance and extend security with Okta Identity Threat Protection.
Okta Identity Governance will allow employees to request access directly in Okta, while team leads approve requests without involving administrators. This will shorten access approval time and further reduce the number of IT requests.
In addition, Keiki plans to use Okta Identity Threat Protection to monitor user activity and respond to risks automatically. The system evaluates behavior, session context, and security signals to detect anomalies and trigger actions such as additional authentication or session termination.
Working with Cloudfresh helped Keiki deploy Okta as a centralized access management system and prepare for team growth. The company received not just a tool, but a structured access model aligned with its organizational setup.
Cloudfresh provided professional Okta configuration services, helped define the right setup, prepared the Implementation Plan, and introduced a controlled approach to shared accounts with clear ownership and access rules.
Support remained a key part of the collaboration: guidance during launch, консультации after implementation, and assistance with further system improvements.
As a result, Keiki now operates with a managed access model that reduces IT workload, speeds up onboarding, and supports growth while maintaining strong security controls.
