Status
What exists today
In development KeystoneIT is in development and has not been released.
Everything this site describes, listed under the one status word that is true of it now. KeystoneIT has an evaluation build in independent engineering review, which has not been accepted. No school or Trust runs Keystone yet.
Independent engineering review is an internal engineering control: each stage is reviewed by someone other than its author before it is accepted. It is not an external audit or a certification.
Last checked against the product record on 6 October 2026.
In the evaluation build
Built, and present in the evaluation build that is in independent engineering review. Not released.
KeystoneIT
-
Requester portal
Staff raise a request, follow it and reply. Replying to a resolved request reopens it.
Not yet: No email is sent yet, so a reply is seen when the person next opens the portal. No attachments yet.
-
A view that is safe for requesters
A requester sees their own requests, the public replies and the status in plain words. Internal notes, priority and service targets are never sent to their browser.
-
Agent workspace
A queue and a request page with the whole conversation, each field saved on its own, and “reply and set status” as one action.
-
Queues and saved views
Six built-in views (My open, Unassigned, Waiting on requester, At risk, All open, Recently resolved) and your own saved views.
Not yet: Saved views are personal. They cannot be shared with a team yet.
-
Filters, sorting and columns
Filter by status, priority, assignee, team, school, service, type and target state. Five sort orders. Choose the columns each view shows.
Not yet: No bulk actions and no export yet.
-
Search
Find a request by its number, subject, the requester's name or words in the conversation. Search returns only requests you are allowed to open.
Not yet: In the agent queue only. The portal has no search yet.
-
Internal notes and public replies
Two separate modes in one composer. The composer changes colour and says who will see what you are about to send.
-
Activity timeline
Every change to a request (raised, routed, replied, assigned, status and priority changed, target met or missed) is an entry beside the conversation.
-
Keyboard workflow
Shortcuts to search, move through the queue, assign, note, reply and send, plus a command palette. Single-key shortcuts can be turned off.
-
Dashboard
Open requests by school, team, service and priority, raised against resolved over fourteen days, and targets met over thirty. Every figure opens the list it counts.
Not yet: The dashboard is fixed. There are no reports, exports or custom dashboards yet.
-
Safe editing
Two people changing different fields of a request both succeed. If they change the same field, the second is told beside that field and loses nothing they typed. Unsent replies survive a reload.
-
Routing by service
A request about a named service goes to the team that supports it, and otherwise to your default team. The timeline says where it went and why.
Not yet: There are no other routing rules, no service catalogue and no approval flow yet.
-
Teams and transfer
Create teams, add and remove members, choose the default team, and move a request to another team.
-
Service targets
First-response and resolution targets for each priority. They pause while you wait on the requester, resume with the time left, and show as on track, at risk, breached or met.
Not yet: Nothing alerts or escalates when a target is at risk yet. One policy for the whole Trust.
-
Opening hours
One calendar for the Trust: opening hours by weekday, a time zone, and closures such as half-term. Target time is counted on it, across clock changes.
Not yet: A calendar for each school is not built.
-
School and Trust scoping
A request belongs to a school or to the Trust centrally. Access is granted school by school or centrally, and a school focus narrows every list and figure.
-
Access decided on the server
One rule sits under every list, count, search and action, so a figure never includes something the person looking could not open.
-
Settings
Teams, members, services, opening hours and service targets are set up in the product.
Not yet: Statuses, priorities and request types are fixed. Managing people, roles and schools is planned and is not in the evaluation build.
-
Phone layout and themes
KeystoneIT works in a phone's browser, where the queue becomes cards. Light and dark themes, and a compact density for people who live in the queue.
Not yet: Tested so far in Chromium only. There is no mobile app.
Partly built
Some of it is in the evaluation build. The page says what is missing.
KeystoneIT
-
Audit record
Every change writes an append-only audit record of who did what, where, and with what result.
Not yet: There is no screen to view or export the audit record yet.
-
Accessibility
Built to WCAG 2.2 AA and checked automatically on every page, in both themes, at desktop and phone widths.
Not yet: A manual screen-reader test has not yet been carried out.
Security and trust
-
Append-only audit record
Every change writes an audit record of who did what, where and with what result, and the database refuses to edit or delete those records. There is no screen to view or export the audit record yet.
-
Accessibility
KeystoneIT is built to WCAG 2.2 AA and checked automatically on every page. A manual screen-reader test has not yet been carried out, and we do not publish a conformance claim until it has.
Under qualification
Being proved on the infrastructure it is meant for. Not yet supported there.
KeystoneIT
-
Sign-in with Microsoft Entra ID
Sign-in through your Trust's Microsoft Entra ID is built into the design and is the first provider planned for a pilot.
Not yet: It has not yet been proven against a live tenant.
Deployment
-
Self-hosted
You run Keystone on infrastructure you control. It cannot be installed yet, and no platform is named as supported until its qualification is complete.
Security and trust
-
Products are separated from each other
Each Keystone product is its own application with its own database and credentials, and products do not read each other's data. This separation is built and tested in our pipeline. It has not yet been proved on a production installation.
-
Sign-in with Microsoft Entra ID
Keystone has no passwords of its own. Sign-in through a Trust's Microsoft Entra ID is built and tested against recorded responses. It has not yet been proven against a live tenant.
In development
Being built now.
Products
-
KeystoneIT
The IT service desk built for schools and multi-academy trusts. Evaluation build in independent engineering review.
Security and trust
-
Backup and point-in-time recovery
Recovery to a point in time is part of the design and is rehearsed on test data in our pipeline on every change. The tooling you would use in production is not built yet, and recovery objectives are not set.
Implemented
In place today.
These are principles and controls in how Keystone is built and checked. They are in place today. That is not the same as the product being released.
Security and trust
-
One installation for one organisation
Keystone is not a shared service that every customer logs in to. Each organisation has its own installation and its own databases. Another organisation's data is not a permission check away from yours, because it is not there.
-
Access is decided on the server, every time
One rule sits under every list, count, search and action in KeystoneIT. A figure on the dashboard never includes a request the person looking could not open.
-
When access cannot be confirmed, Keystone refuses
If KeystoneIT cannot confirm a person's access with Keystone Platform, it shows a warning, then withholds figures, then stops agent work. It does not carry on with what was true earlier.
-
Access school by school
Permissions are granted for a school or for the Trust centrally. What an agent sees also depends on the teams they belong to, and an agent's own request is only ever shown to them as a requester.
-
Your data stays yours
Your data is held in your own installation, in PostgreSQL databases that belong to it. Keystone does not stop working because maintenance is not renewed, and the data stays where it is.
-
No home-made cryptography
Keystone uses the security mechanisms of its framework and platform as they are designed to be used. We do not invent our own schemes, and we remove a feature rather than build one.
-
Automated gates on every change
Every change must pass static analysis, security scanning for known weaknesses and leaked secrets, dependency advisories, the automated test suites, browser journeys with accessibility checks, and a recovery rehearsal.
-
Independent engineering review
Each stage is reviewed by someone other than its author before it is accepted. This is an internal engineering control. It is not an external audit, a penetration test or a certification. The current KeystoneIT evaluation build has not been accepted.
Planned
Intended. Not started, or designed only. No date is promised.
We promise no date for anything in this section.
Products
-
KeystoneHR
A planned product for a Trust's record of staff employment. Not designed yet.
-
Keystone Provision
A planned product for the identity lifecycle of joiners, movers and leavers. A statement of direction. Not designed in detail.
KeystoneIT
-
Email notifications and reply by email
The evaluation build sends and receives no email.
-
Attachments
No file can be added to a request yet.
-
Asset management
Designed as a likely next step. Nothing is built.
-
Managing people, roles and schools
In the evaluation build these are set up for you.
-
Sign-in with Google Workspace or Active Directory
Designed, not built.
Deployment
-
Keystone Managed
Keystone Managed will be an optional recurring hosting and operations service, in which Alresford runs your installation for you. It is planned and is not available yet. The software licence remains perpetual.
Security and trust
-
No telemetry unless you choose it
The intent is that a Keystone installation sends nothing to Alresford unless you turn that on. This is a design position for the first release, not yet a shipped setting.
-
Signed releases
Releases will be signed, and an installation will check the signature before it updates. No release has been published yet.
-
Source-code continuity
The licence is intended to include source-code continuity rights. The terms are being written; nothing here is a legal promise.
-
Penetration test
No external penetration test has been carried out. One is planned before any internet-facing installation holds real personal data.
Not included
Not in the product, and not promised.
Not in the product and not promised. If one of these is essential to you, Keystone is not the right choice today.
KeystoneIT
-
Service catalogue and approvals
Requests can be about a named service, which decides the team. There are no request forms or approvals.
-
Reports and exports
One fixed dashboard only.
-
Knowledge base, automation and canned replies
Not in the evaluation build.
-
Import from another helpdesk
There is no import tooling yet.
-
Integrations
No connection to an MIS, messaging tool or other system yet.
-
Mobile app
KeystoneIT works in a phone's browser.
-
AI features
None.
If you followed an older link
What the earlier site described, and this one does not.
Keystone has been rebuilt as a new product family, and this site describes only that. The earlier site described modules for estates, health and safety, governance, leadership reporting, recruitment, the Single Central Record and visitor management. None of those is part of Keystone today, and none is on the plan above.
Asset management, staff records and account provisioning appear above as planned. They are not built. The service desk is the part that exists: see exactly what KeystoneIT does and does not do.
Status words
What the words mean.
The site uses a small, fixed set of words for how real something is. They mean the same thing on every page.
Last checked against the product record on 6 October 2026.
- Available
- Released. You can have it now.
- Implemented
- In place today.
- In the evaluation build
- Built, and present in the evaluation build that is in independent engineering review. Not released.
- Under qualification
- Being proved on the infrastructure it is meant for. Not yet supported there.
- Partly built
- Some of it is in the evaluation build. The page says what is missing.
- In development
- Being built now.
- Planned
- Intended. Not started, or designed only. No date is promised.
- Not included
- Not in the product, and not promised.
- Commercial policy
- A term of the offer. The licence agreement is what binds.
Plan with what is true today.
The price list is published and the licence builder shows its working. KeystoneIT has not been released, so a quote is for planning and budgeting. It is not an order.