Commercial Property Key & Access Management Checklist for Landlords

Why property access needs a repeatable process
Keys, fobs, gate codes, lockbox combinations, and access credentials tend to multiply quietly. A tenant needs another key. A vendor needs access before opening. A manager changes. A suite turns over. Then someone asks who still has the master key, whether a former contractor's code is active, or when a tenant returned its fobs.
The problem is usually not the number of access items. It is the lack of one dependable record for issuing, changing, returning, and revoking them.
A simple workflow helps a landlord answer three questions quickly:
- What access exists at this property?
- Who is authorized to use it now?
- What happened when that access changed?
This checklist is an operational framework, not a substitute for a property's emergency plan, lease requirements, building rules, or advice from qualified security and legal professionals. Use the controls that fit the property's layout, systems, and risk profile.
Start with an access inventory
Before issuing another item, list the access methods already in use. Do this by property and, where useful, by building, suite, common area, or secured space.
Include more than metal keys:
- exterior door keys and suite keys
- master, sub-master, utility-room, roof-hatch, and mechanical-room keys
- mailbox, storage, loading-area, and cabinet keys
- fobs, cards, mobile credentials, and parking credentials
- gate, keypad, lockbox, alarm, intercom, and garage codes
- vendor-held keys, lockbox access, and after-hours credentials
Give each physical key ring, fob, card, or credential a unique identifier. The identifier should be easy to record without writing a sensitive code or a full master-key combination into a general spreadsheet.
For each item, note what it opens or permits access to, where it is normally stored when unissued, and who can approve its use. Keep sensitive combinations and system-administrator details in the appropriate restricted record rather than a broadly shared register.
Set clear approval and access rules
Access should be tied to a purpose, a person or business, and a time period. That makes everyday requests easier to handle consistently.
Decide in advance:
- who may request access for a tenant, employee, vendor, or visitor
- who may approve suite, common-area, master, and after-hours access
- which roles may issue, duplicate, change, or revoke credentials
- when vendor access must be escorted, temporary, or limited to a scheduled window
- what documentation is required before a tenant representative receives or transfers access
- how access requests are handled during an emergency or after-hours event
The lease, tenant contacts on file, property rules, and the applicable service agreement should guide these decisions. Do not assume that an employee, occupant, broker, or contractor can authorize access merely because they are familiar with the space.
Use one issuance record every time
Every issued item should create a record at the time it changes hands. A signed paper log can work for a small property, but a shared system is usually easier to search and review when more than one person handles operations.
Record the following for each issuance:
| Field | What to record | | --- | --- | | Access item | Credential ID and access type, such as key, fob, card, or temporary code | | Location | Property, building, suite, area, or system covered | | Holder | Individual name, company, and reliable contact method | | Purpose | Tenant operations, scheduled repair, inspection, showing, delivery, or other specific need | | Authorization | Requestor, approving person, and any related work order, lease record, or appointment | | Dates | Issued date, expected return or expiration date, and actual return date when applicable | | Limits | Escort requirement, access window, areas excluded, or other restrictions | | Acknowledgment | Confirmation that the holder received the item and understands the return process |
For a new tenant or authorized tenant representative, connect the record to the current lease contact list. This avoids relying on a name from an old email thread when staff changes later.
Give tenants access without losing the record
Tenant access is often ongoing, but it still needs a starting point and a clean transfer path.
At move-in or commencement, confirm the authorized tenant contacts before releasing keys, fobs, or codes. Log each item separately if several people receive access. If a tenant needs additional credentials later, treat that as a new issuance rather than editing the original handoff until it is impossible to see what changed.
When a tenant contact changes, ask for direction from an authorized tenant representative using the communication method your lease and property procedures require. Update the tenant contact list and access register together. If a departing employee retains a credential, the tenant should have a clear route to report it so the landlord can follow the property process for return or deactivation.
The commercial tenant move-out checklist is a useful companion for setting final access-return steps before a suite is surrendered.
Make vendor access temporary and traceable
Vendor access is easiest to manage when it is linked to a real service need. Before issuing access, create or confirm the work order, appointment, or written scope that explains why the vendor needs entry.
For each vendor visit, determine:
- the approved contact person and company
- the specific areas the vendor needs to enter
- the scheduled date and access window
- whether a property representative needs to meet or escort the vendor
- whether the vendor will receive a physical item, a temporary credential, or access through an on-site contact
- what must happen at the end of the work
Avoid leaving an open-ended credential in place simply because a vendor may return someday. When recurring access is necessary, schedule a periodic review of the authorization, contact details, and scope.
Link access activity to the related maintenance record whenever possible. That makes it easier to confirm why a contractor entered the property and what follow-up remains. See commercial property maintenance tracking for a related workflow.
Build returns into the original handoff
An access item is easier to recover when the holder knows the expected return date and method from the beginning.
For temporary keys, fobs, cards, and lockbox access:
1. State the return or expiration date when issuing the item. 2. Name the return location or person responsible for receiving it. 3. Send a reminder before the expected return date if the work or visit is not complete. 4. Inspect the returned item and record the date, receiver, and condition. 5. Close or update the issuance record only after the physical item is accounted for or the credential is confirmed inactive.
For a tenant move-out, use a separate final access checklist. Account for every item in the tenant's record, not just the keys that happen to be returned in one envelope. The remaining record may affect rekeying, credential deactivation, deposits, or other next steps that should be reviewed under the lease and your property procedures.
Treat lost keys or unconfirmed access as an escalation
A lost key, unreturned fob, unknown code holder, or credential that cannot be confirmed should not disappear into a note for later. Create a dated incident record and route it to the person responsible for the property's access decision.
The first record should include:
- the item or credential ID and location it affects
- the holder and company, if known
- when the loss or uncertainty was reported
- the access areas or systems potentially involved
- immediate steps taken, such as suspension, deactivation, retrieval attempt, or restricted entry
- the decision owner and next review time
Do not promise a universal response such as rekeying every lock or charging a particular fee. The right response depends on the type of access, the property, the lease or agreement, and the property's security procedures. What matters operationally is that the issue is recorded, assigned, and resolved rather than left as an undocumented assumption.
For the documentation side of a reported event, use the same discipline described in the commercial property incident reporting workflow: record facts, preserve relevant communications, and assign follow-up with an owner and due date.
Revoke access when the reason for access ends
Revocation is not only a move-out task. It should happen whenever the original purpose, person, company, or time window changes.
Common triggers include:
- a tenant surrender, default-related possession change, or authorized contact update
- an employee or property manager departure
- a vendor contract ending or a vendor contact changing
- completion or cancellation of a work order
- a lost, stolen, damaged, or unreturned access item
- a gate, lock, credential platform, or code change
Create a short closeout entry for each revocation. Identify the credential, the reason, who authorized the change, when the action was completed, and how completion was verified. If a physical key remains outstanding, keep the return effort open rather than marking the record complete just because a code was changed.
Review the register on a schedule
The register works only if it is current. A brief recurring review is usually more manageable than trying to rebuild the whole history after a turnover or incident.
At a practical interval for the property, compare the register with:
- current tenant contacts and occupied suites
- active vendors, work orders, and service agreements
- recent staff, manager, or ownership changes
- outstanding temporary items and overdue returns
- recently changed locks, codes, credentials, and access systems
Flag entries with a missing return date, inactive contact, expired vendor purpose, unknown holder, or incomplete revocation. Assign a next action and owner for each exception.
The same habit of checking a property record against current conditions also supports a stronger commercial property inspection checklist.
What an auditable access register looks like
An auditable register does not need to be complicated. It needs to show a readable sequence from authorization to issuance to return or revocation.
For each access item or credential, a reviewer should be able to find:
- its unique ID and the property area or system it covers
- the current authorized holder or the fact that it is in secure storage
- the request and approval behind the issuance
- relevant dates, limits, and expected return or expiration
- the record of return, deactivation, replacement, or escalation
- supporting references, such as a work order, tenant-contact update, or incident record
Keep the register restricted to the people who need it for property operations. A record that is easy to find by the wrong people creates a different access problem.
The takeaway
Access management becomes manageable when every key, fob, code, and vendor credential follows the same basic path: inventory it, authorize it, issue it with a record, confirm its return or expiration, and revoke it when the reason for access ends.
That discipline reduces the time spent searching through texts and inboxes when a suite turns over, a vendor arrives, or an item goes missing. More importantly, it gives the property team a clear, dated record for the next person who needs to act.
See how PigJet helps commercial landlords keep lease details and tenant billing organized.