This is my problem with key management; at some point you have to have some sort of bespoke key management strategy for the key manager itself. I've yet to find a satisfactorily clear and modern way to accomplish this securely.
It is important to understand the threat model in order to place the appropriate mitigations into the security architecture.
A tool will never solve a security problem by creating an optimal design. That requires someone with security knowledge. There are threat modeling tools that can help but only when the tools are used as designed.