The short answer
Three records: what access exists per site, who currently holds it, and when it was last changed. The third is the one almost nobody keeps, and it is what determines your exposure when someone leaves.
This is a risk register as much as an operational tool, and it should be treated that way.
What has to be tracked
- Physical keys, individually identified, and who signed for each
- Alarm codes and who knows them
- Key safe codes, and when they were last rotated
- Electronic access cards or fobs
- Client-held access that your staff rely on
- Out-of-hours contact arrangements per site
Key safe codes are the common weak point. They are shared for convenience, rarely changed, and known by people who left months ago.
The leaver problem
| Access type | On leaving |
|---|---|
| Physical key | Returned and signed in, or noted as lost |
| Alarm code | Changed if they knew it |
| Key safe code | Changed, which nobody does |
| Access card | Deactivated |
| App or system access | Revoked |
The middle row is the practical failure. Changing key safe codes across dozens of sites is real work, and because it is real work it does not happen unless a system prompts it.
Make it operational, not administrative
A register that lives in a spreadsheet updated occasionally will be wrong. Tie key issue and return to the same system that manages shifts, so the record updates as a by-product of the work.
- Issue and return recorded at the point it happens, on a phone.
- A daily view of what is outstanding, per person.
- Prompts when a leaver has unreturned access.
- A scheduled review of codes, by site.
- An audit trail of who held what, when.
It is a client obligation too
Clients are increasingly asking how access is controlled, and a clear answer is a commercial advantage in tenders. A vague one is a risk they will price in.
Being able to show the register, the return process and the code rotation schedule turns a due diligence question into a differentiator.