Customer Key, Code, and Property Access Management SOP
Purpose
Define a standard procedure for receiving, storing, using, and returning customer property-access credentials - physical keys, garage codes, alarm codes, smart-lock codes, lockbox combinations, and gate fobs. A cleaning service that holds keys for 50 to 500 customers is one mishandled key away from the kind of incident that ends the business: a stolen-from-truck key set, a fired employee who kept their copy, a copy that ended up in a domestic-dispute situation. Access management is one of the highest-stakes operational disciplines a cleaning service operates under, and most shops handle it informally until it goes wrong.
Scope
Applies to:
- All residential and commercial customer accounts where the cleaning service has independent property access
- Every employee handling the access
- Every form of credential: physical keys, electronic codes, lockbox combinations, alarm codes, garage codes, gate fobs, smart-lock app access
- The transfer of credentials between employees, between locations, and to/from the customer
Responsibilities
- Owner / GM maintains the master access registry
- Office manager issues credentials to crew leads at shift start and reclaims at shift end
- Crew leads carry credentials on shift and are responsible for the chain of custody during the shift
- Customer is informed of how their credentials are stored and handled
Procedure
Receiving credentials
- Customer provides credentials at quote-acceptance time or first service visit
- The credentials are logged into the access registry with:
- Customer name + address
- Credential type + identifier (e.g., "House key, blue tag #C-247", "Alarm code 1234", "Garage code 5678")
- Date received
- Who received it
- Physical keys receive a numbered tag, NOT a customer name or address on the tag itself - if lost, the tag does not identify the property
- Two signatures (employee + customer) on a receipt acknowledging custody transfer
- The customer keeps a copy of the receipt
Storage at the office
- Physical keys stored in a wall-mounted, locked key cabinet
- Cabinet location is not accessible to customers, vendors, or unauthorized employees
- Cabinet has a tamper-evident seal at the end of each business day
- Electronic credentials (codes) stored in a password-managed system, NOT in shared spreadsheets or unencrypted documents
- Smart-lock app access - each crew lead has a unique account with the customer's smart lock, NOT a shared account; an employee who leaves has their access revoked individually
Daily issuance
- At shift start, the crew lead signs out the keys / credentials for the day's customer list
- The office records each key against the crew lead's name
- Keys travel in a secure pouch attached to the crew lead - never loose in a vehicle, never on a counter
- Codes are NOT printed on paper; the crew lead reads them from the dispatch app at the property
On-site use
- Crew lead unlocks the property using the credential
- If the customer is home, knock and identify before unlocking
- Disarm the alarm immediately on entry per the customer's instructions
- Lock the door behind the crew on entering (security against opportunistic entry while the crew is working)
- At the end of the visit, re-arm the alarm, lock the door, verify the lock engaged before leaving
Daily return
- At shift end, crew lead returns all keys to the office
- Office verifies every key returned against the morning's issuance log
- Any missing key triggers the missing-key protocol below
- Tamper-evident seal placed on the key cabinet
Quarterly audit
- Office walks the registry against the physical cabinet contents
- Verify every customer with a key on file has the actual key in the cabinet
- Verify every key in the cabinet has a customer on file (no orphan keys)
- Confirm electronic credentials are still active and the customer hasn't changed them without notification
- Reconcile discrepancies and re-tag any credential that has lost its tag
Annual customer review
- Once per year, contact every customer with credentials on file
- Confirm they still want the cleaning service to hold their key / code
- Offer to return the credential if they prefer to provide entry each visit
- Verify alarm codes and door codes haven't been changed without the cleaning service being informed
- Document the customer's affirmation in the file
Missing-key protocol
When a key cannot be accounted for at shift-end:
- Within 1 hour: Office searches the cabinet, the crew lead searches the vehicle and personal effects, every property visited that day is contacted for permission to check for the missed key
- Within 4 hours: If not found, the affected customer is contacted directly by the owner or GM
- Within 24 hours: If still missing, the customer is offered:
- Free re-keying of the affected entry point (paid by the cleaning service)
- Replacement of the lockbox combination
- Replacement of the garage code OR alarm code
- Whichever applies to the missing credential
- The cost is the cleaning service's, full stop. Do not negotiate. Customers tolerate one well-handled incident; they will not tolerate one badly-handled incident.
- Document the incident in the access registry; if a pattern emerges across multiple incidents, the crew lead's access privileges need review
Employee separation protocol
When an employee leaves the company (voluntary or involuntary):
- Last shift: Collect all keys and reset all electronic credentials the employee had access to
- Same day: Revoke smart-lock app access, change codes the employee knew, deactivate the employee's account in the dispatch system
- Within 48 hours: Notify customers whose alarm/door codes were known to the departing employee that codes have been changed (do not name the employee; describe as a routine rotation)
- Within 7 days: Verify every customer whose credentials the employee handled is confirmed-affected and remediated
Involuntary separations (terminations) trigger this protocol immediately, before the employee leaves the property if practical. Voluntary separations can be scheduled over the notice period.
Smart-lock specific considerations
Increasing adoption of smart locks (August, Yale, Kwikset, Schlage Encode, etc.) changes the model:
References
- ASIS International Workplace Security Best Practices
- ISSA Cleaning Industry Management Standard (security and access section)
- NIST SP 800-53 (general access control principles applicable to small business)
- State data-breach notification statutes (most states require notification of customers when credentials are compromised)
- Manuall internal: Standard Residential Cleaning SOP, Customer Onboarding Checklist