Customer Key, Code, and Property Access Management SOP

Purpose

Define a standard procedure for receiving, storing, using, and returning customer property-access credentials - physical keys, garage codes, alarm codes, smart-lock codes, lockbox combinations, and gate fobs. A cleaning service that holds keys for 50 to 500 customers is one mishandled key away from the kind of incident that ends the business: a stolen-from-truck key set, a fired employee who kept their copy, a copy that ended up in a domestic-dispute situation. Access management is one of the highest-stakes operational disciplines a cleaning service operates under, and most shops handle it informally until it goes wrong.

Scope

Applies to:

  • All residential and commercial customer accounts where the cleaning service has independent property access
  • Every employee handling the access
  • Every form of credential: physical keys, electronic codes, lockbox combinations, alarm codes, garage codes, gate fobs, smart-lock app access
  • The transfer of credentials between employees, between locations, and to/from the customer

Responsibilities

  • Owner / GM maintains the master access registry
  • Office manager issues credentials to crew leads at shift start and reclaims at shift end
  • Crew leads carry credentials on shift and are responsible for the chain of custody during the shift
  • Customer is informed of how their credentials are stored and handled

Procedure

Receiving credentials

  1. Customer provides credentials at quote-acceptance time or first service visit
  2. The credentials are logged into the access registry with:
  • Customer name + address
  • Credential type + identifier (e.g., "House key, blue tag #C-247", "Alarm code 1234", "Garage code 5678")
  • Date received
  • Who received it
  1. Physical keys receive a numbered tag, NOT a customer name or address on the tag itself - if lost, the tag does not identify the property
  2. Two signatures (employee + customer) on a receipt acknowledging custody transfer
  3. The customer keeps a copy of the receipt

Storage at the office

  1. Physical keys stored in a wall-mounted, locked key cabinet
  2. Cabinet location is not accessible to customers, vendors, or unauthorized employees
  3. Cabinet has a tamper-evident seal at the end of each business day
  4. Electronic credentials (codes) stored in a password-managed system, NOT in shared spreadsheets or unencrypted documents
  5. Smart-lock app access - each crew lead has a unique account with the customer's smart lock, NOT a shared account; an employee who leaves has their access revoked individually

Daily issuance

  1. At shift start, the crew lead signs out the keys / credentials for the day's customer list
  2. The office records each key against the crew lead's name
  3. Keys travel in a secure pouch attached to the crew lead - never loose in a vehicle, never on a counter
  4. Codes are NOT printed on paper; the crew lead reads them from the dispatch app at the property

On-site use

  1. Crew lead unlocks the property using the credential
  2. If the customer is home, knock and identify before unlocking
  3. Disarm the alarm immediately on entry per the customer's instructions
  4. Lock the door behind the crew on entering (security against opportunistic entry while the crew is working)
  5. At the end of the visit, re-arm the alarm, lock the door, verify the lock engaged before leaving

Daily return

  1. At shift end, crew lead returns all keys to the office
  2. Office verifies every key returned against the morning's issuance log
  3. Any missing key triggers the missing-key protocol below
  4. Tamper-evident seal placed on the key cabinet

Quarterly audit

  1. Office walks the registry against the physical cabinet contents
  2. Verify every customer with a key on file has the actual key in the cabinet
  3. Verify every key in the cabinet has a customer on file (no orphan keys)
  4. Confirm electronic credentials are still active and the customer hasn't changed them without notification
  5. Reconcile discrepancies and re-tag any credential that has lost its tag

Annual customer review

  1. Once per year, contact every customer with credentials on file
  2. Confirm they still want the cleaning service to hold their key / code
  3. Offer to return the credential if they prefer to provide entry each visit
  4. Verify alarm codes and door codes haven't been changed without the cleaning service being informed
  5. Document the customer's affirmation in the file

Missing-key protocol

When a key cannot be accounted for at shift-end:

  1. Within 1 hour: Office searches the cabinet, the crew lead searches the vehicle and personal effects, every property visited that day is contacted for permission to check for the missed key
  2. Within 4 hours: If not found, the affected customer is contacted directly by the owner or GM
  3. Within 24 hours: If still missing, the customer is offered:
  • Free re-keying of the affected entry point (paid by the cleaning service)
  • Replacement of the lockbox combination
  • Replacement of the garage code OR alarm code
  • Whichever applies to the missing credential
  1. The cost is the cleaning service's, full stop. Do not negotiate. Customers tolerate one well-handled incident; they will not tolerate one badly-handled incident.
  2. Document the incident in the access registry; if a pattern emerges across multiple incidents, the crew lead's access privileges need review

Employee separation protocol

When an employee leaves the company (voluntary or involuntary):

  1. Last shift: Collect all keys and reset all electronic credentials the employee had access to
  2. Same day: Revoke smart-lock app access, change codes the employee knew, deactivate the employee's account in the dispatch system
  3. Within 48 hours: Notify customers whose alarm/door codes were known to the departing employee that codes have been changed (do not name the employee; describe as a routine rotation)
  4. Within 7 days: Verify every customer whose credentials the employee handled is confirmed-affected and remediated

Involuntary separations (terminations) trigger this protocol immediately, before the employee leaves the property if practical. Voluntary separations can be scheduled over the notice period.

Smart-lock specific considerations

Increasing adoption of smart locks (August, Yale, Kwikset, Schlage Encode, etc.) changes the model:

  • Ask for a unique code per crew, or a guest code with a schedule. Nearly every smart lock supports both. A code that only works Tuesdays from 9 to 1 turns the whole physical-key problem into a non-event, and it revokes instantly when someone leaves.
  • Never accept the homeowner's own code. If the customer offers the code they use, decline and ask for a separate one. Their code is on their phone, their alarm, and probably their garage keypad, and the day something goes missing you do not want to be one of the people who had it.
  • The audit log is the real upgrade. Smart locks record who unlocked and when. That log has cleared more theft accusations than any policy in this document. Ask the customer to keep it enabled and to check it before they call you.
  • Do not put customer credentials in a personal app account. Access comes through a company account, or through the customer's own account granting a company user. A crew lead who owns the lock invite in their personal login walks out the door with it.
  • Revocation is the whole point, so use it. Same-day removal on separation, and a scheduled rotation of codes on a cadence you set. The dispatch system and the lock app get updated together or the registry is fiction.
  • Plan for the failure modes. Dead batteries, a lock that lost Wi-Fi, a firmware update that dropped the guest codes, a phone with no signal at the door. Every smart-lock property needs a documented fallback, usually a lockbox with a mechanical key, or the crew stands in the driveway.
  • Log it in the same access registry as physical keys. A code is a credential. It gets an entry, an owner, an issue date, and a revocation date exactly like a key.
  • The loss protocol still applies. A leaked code is a compromised credential and gets the same clock: search, notify, and reset at the company's cost. Resetting a code is cheaper and faster than re-keying a deadbolt, which is an argument for smart locks, not an excuse to treat the leak casually.

References

  • ASIS International Workplace Security Best Practices
  • ISSA Cleaning Industry Management Standard (security and access section)
  • NIST SP 800-53 (general access control principles applicable to small business)
  • State data-breach notification statutes (most states require notification of customers when credentials are compromised)
  • Manuall internal: Standard Residential Cleaning SOP, Customer Onboarding Checklist