Key/Lockbox Management: Who Has Access to Which House and How You Track It

When a client called Nadia to ask why her old cleaner still had a key to the house eight months after switching companies, Nadia didn't have a good answer. She checked her records, a mix of texts, a note in her phone, and a memory that a keybox code had been shared with someone at some point, and couldn't say for certain who currently had access to that house. It turned out to be an employee who'd left the company five months earlier and never returned the physical key. Nothing bad had happened. But Nadia spent the rest of that day rekeying the lockbox, apologizing to a rattled client, and realizing she had no idea how many other houses had the same problem sitting quietly unresolved.
Key and lockbox access is the kind of thing that feels fine right up until the moment it very much isn't.
Why this slips through the cracks
Access to a client's home usually gets handled in the moment, a code gets texted to whoever's cleaning that day, a physical key gets handed off between employees, a lockbox combination gets shared once and then just assumed to still be accurate. None of that gets written down anywhere central, because in the moment it feels like a quick logistical detail, not a security record. It only becomes a problem later, when an employee leaves, a client changes locks, or someone needs to know who currently has access and there's no single place that answer lives.
The deeper issue is that access changes constantly and nothing prompts anyone to update a record when it does. An employee who leaves the company doesn't automatically trigger someone checking which keys and codes they had. A client who gets a new lockbox doesn't automatically trigger an update to whatever list you're keeping, if you're keeping one at all. The record, if it exists, drifts out of date the moment reality changes and nobody notices until something forces the question.
What you actually need
- One list of every client's access method, physical key, lockbox code, garage code, whatever it is, tied to that specific property, not scattered across texts and memory.
- A record of who currently has access, by name, not just "the crew." If three employees have been given a code over the years, you need to know which of them still should.
- A trigger for updating access when an employee leaves. This is the single most important habit, because a departing employee is exactly when old access becomes a real risk instead of a theoretical one.
- A trigger for updating access when a client changes their lock or code. Clients don't always think to tell you, so build in a periodic check rather than waiting to be told.
- A way to revoke access fast. If a lockbox code needs to change today, you should be able to do it without hunting for who else needs to be notified.
A simple system
- List every client property and its current access method in one place, key, lockbox code, gate code, whatever applies.
- Record which employees currently have access to each one. Not "the team," actual names.
- When an employee leaves, immediately review every property they had access to and change codes or collect keys before their last day, not after.
- When a client mentions a new lock or code, update the record the same day, don't let it wait for the next visit.
- Do a quarterly access review across all properties, checking that the list of who has access still matches who should have access.
- Keep physical keys logged and accounted for, a simple sign-out system if multiple employees share a set, so a missing key gets noticed immediately, not eight months later.
A worked example
After the lockbox scare, Nadia builds a real access list. Every client property gets an entry: address, access method, current code if it's a lockbox, and the names of every employee who currently has that code. She goes through her active client list and realizes three other properties still have codes that were shared with employees who've since left, information that had just been sitting there unnoticed the same way the first one had.
She updates all three that week. Going forward, when an employee gives notice, reviewing their property access becomes a standard part of the offboarding checklist, not an afterthought. When Marcus leaves the company two months later, Nadia pulls up his name against the access list, sees he has codes for four properties, and updates all four before his last day instead of finding out about a lapse later from an unhappy client.
She also sets a quarterly reminder to review the whole list. On the first review, she catches a lockbox code that was changed by a client but never updated in her records, a gap that would have meant a locked-out crew showing up to a job with a code that no longer worked. Small problem, easily caught, because the review happened on a schedule instead of by accident.
What this actually buys you
- You always know who has access to what, instead of reconstructing it from memory when a client asks a hard question.
- Employee departures stop being a security gap. Access gets revoked as part of leaving, not discovered as a lapse months later.
- Clients trust you with their homes. Being able to answer "who has access to my house" clearly and immediately is the kind of thing that builds real confidence in a service business.
- Small changes get caught before they become a locked-out crew or an angry phone call. A quarterly review catches drift before a client has to be the one to flag it.
If Nadia had kept one list showing exactly which employees had access to which property, the eight-month-old key would have been flagged and collected the day that employee left, not discovered by an unsettled client months later. Bindful keeps access details attached to each client's property record, so it's clear at a glance who currently has a key or code and easy to update the moment that changes. That's the difference between an answer you can give a worried client on the spot and one you have to piece together after the fact. bindful.app