July 2026 guide. Apple Home now separates residents from guests. That distinction matters for security: a resident can control the home broadly, while a guest can be limited to selected doors, locks, and other security accessories on a schedule. Use the narrowest role that completes the job, then test and remove it when the visit ends.
Apple’s current home-sharing guidance says guests receive local-only access to selected security accessories on a set schedule. That makes the guest role a better starting point for cleaners, dog walkers, contractors, and short visits than adding every person as a resident.
Resident, guest, and lock-code access are different
| Access type | What it is for | Main security risk |
|---|---|---|
| Resident | Someone who lives in the home and needs broad accessory control | Too much access for temporary workers or visitors |
| Apple Home guest | Scheduled, local-only control of selected doors, locks, and security accessories | The wrong door, time window, or device may be included |
| Lock access code | A credential managed by a compatible lock or its app | A code can remain valid after Home access is removed |
| Alarm user or PIN | Arming, disarming, or monitoring access in the alarm platform | Removing Apple Home access may not revoke the alarm credential |
Before granting guest access
- Name the person and purpose. Avoid shared labels such as “contractor” if several people will use the same record.
- Choose the minimum doors. A cleaner may need the back door but not the garage, office, or interior storage room.
- Set the real work window. Add a small arrival buffer instead of granting all-day access.
- Separate Apple Home from vendor accounts. List any lock code, alarm PIN, camera share, intercom account, or garage app that must also be managed.
- Prepare a fallback. Keep a physical key or owner-controlled recovery path for battery, phone, hub, or network failure.
Build a door-by-door access map
Write down every route a guest could use: front door, side door, patio door, garage entry, gate, and shared-building entrance. For each one, record the lock, sensor, camera, light, alarm zone, and owner who can revoke access. This prevents a common failure: the scheduled door works, but another credential still opens a connected entrance.
| Door | Guest can unlock? | Open-close alert? | Camera view? | Fallback |
|---|---|---|---|---|
| Front door | Only if needed | Owner alert during guest window | Exterior approach only | Owner-held key |
| Side or service door | Often the best worker entrance | Open-too-long rule | Avoid windows and private rooms | Alternate owner contact |
| Garage entry | Exclude unless the job requires it | Door and interior-entry status | Vehicle and tool privacy | Manual release plan |
| Patio or back door | Use a short window | Confirm closed after departure | Exterior yard only | Owner inspection |
Schedules need a start, stop, and exception rule
A schedule is useful only when somebody owns it. Record the start date, end date, days, hours, time zone, and the person who will remove it. Add an exception process for a delayed cleaner or an emergency repair. Do not stretch a one-hour visit into permanent access because changing the schedule feels inconvenient.
Do not expose more camera access than the visit requires
Door access does not automatically justify indoor camera access. Keep exterior cameras aimed at the approach and disclose them to household members and visitors as required. If a guest needs to enter a living area, review the HomeKit security privacy guide before sharing any camera or recording controls.
Pair lock events with alarm response
An unlock is not the same as a verified arrival, and a door opening is not the same as an alarm emergency. A practical routine can notify the owner when the assigned door unlocks, confirm the contact sensor opens, and flag the door if it remains open after the work window. Keep disarming rules conservative: do not let a single motion, presence, or voice event disarm the alarm.
If the household uses Abode, compare the Abode Lock, Mini Door/Window Sensor, and Smart Security Kit. Confirm current lock, Apple Home, alarm-user, and plan support before purchase. The plans page shows current monitoring choices.
Test the guest path before the real visit
- Stand outside the home during the scheduled window.
- Use only the credential the guest will receive.
- Confirm the correct door unlocks and excluded doors remain unavailable.
- Open and close the door, then check alerts, camera framing, and alarm state.
- Repeat the test before and after the allowed window.
- Test a low-battery or internet-offline scenario with the owner present.
Remove access in every system
At the end of the visit, remove the Apple Home guest, retire any lock code, delete alarm users or PINs, remove camera shares, close garage or gate accounts, and check old phones or tablets. Then run one real access test. The HomeKit member-removal checklist covers the full offboarding path, while the smart-lock turnover checklist is useful for rentals and recurring service staff.
Monthly guest-access audit
- List every current resident, guest, code, alarm user, and camera share.
- Remove expired people and schedules.
- Check that names match real people rather than generic roles.
- Test the most-used service entrance.
- Review battery, door alignment, hub status, and recovery access.
- Record who completed the audit and when.
FAQ
What is the difference between a resident and a guest in Apple Home?
Apple says residents can receive broad local and optional remote control of home accessories. Guests can be limited to selected security accessories and a schedule, with local-only access.
Does removing an Apple Home guest delete a smart-lock code?
Not necessarily. A lock code may live in the lock maker’s app or another account. Remove and test every credential separately.
Should a cleaner be added as a resident?
Usually no. Start with scheduled guest access to the minimum doors or accessories. Add resident access only when the person truly needs broad, ongoing control.
What if the guest’s phone or the home internet fails?
Keep an owner-controlled fallback such as a physical key or alternate entry process. Test the lock, hub, network, and battery failure paths before relying on phone access.
Prove the HomeKit guest-access plan before sharing it
Guest access is a small permission system, not a message with a door code. The household needs to prove who can enter, which door works, when access starts and stops, what the person can see, which separate vendor credentials exist, and who removes every path. Build one record for each cleaner, sitter, contractor, relative, or short-term helper.
| Control | Write down | Failure that blocks access |
|---|---|---|
| Person | Real name, purpose, owner, phone, approved dates | A generic “guest” or “cleaner” identity is shared by several people |
| Apple Home role | Guest or resident, selected accessories, schedule, local/remote expectation | The role is broader than the visit needs |
| Door path | Entrance, compatible lock, gate, garage, alarm zone, fallback | The approved door works but another route stays open or unmanaged |
| Other credentials | Lock code, alarm PIN, camera share, intercom, garage app, building access | Removing the Apple Home guest leaves another credential active |
| Privacy | Visible cameras, audio state, rooms, notifications, clip access | The guest can view or control more than the job requires |
| Response | Owner, backup owner, failed-entry contact, alarm rule, emergency path | A failed entry or unexpected alarm has no named responder |
| Removal | End time, remover, verifier, evidence, retest date | Expiry is assumed but never tested |
Separate Apple Home permissions from every other account
Make an access ledger before sending an invitation. Include Apple Home, the lock maker, alarm app, camera app, garage controller, gate or building system, delivery service, property manager, and any shared password. The smart-home guest-access guide helps map these separate systems.
Use one named account or code per person where the product supports it. A named record gives the owner a cleaner event history and a smaller removal target. Do not share the owner Apple Account, lock administrator password, alarm master code, setup code, recovery key, or device passcode.
Test the schedule, time zone, and daylight-saving boundary
A schedule can be correct on paper and wrong at the door. Confirm the property’s time zone, start and stop times, days of the week, overnight behavior, and daylight-saving change. The HomeKit time-zone checklist covers clocks, automations, cameras, and recovery.
- Set a short test window that begins several minutes in the future.
- Try the approved door before the window; access should fail.
- Try it during the window; only the selected route should work.
- Test an excluded lock or accessory without changing its state.
- Wait until the window ends and prove that entry stops.
- Check the event history and write down which account or code appears.
For an overnight worker, test both sides of midnight. For a recurring schedule, test the first allowed day and an excluded day. Do not stretch a narrow service visit into permanent access because the scheduling rule has not been tested.
Define what the guest may see and control
Door control does not grant a need to see indoor cameras, occupancy state, family routines, alarm history, or other rooms. Review the assigned accessories from the guest device, not only from the owner’s phone. Keep cameras out of private spaces and confirm that exterior views match the household’s privacy rules.
Run the HomeKit notification audit for both the owner and guest path. The owner may need an unlock, open-door, offline, low-battery, or alarm notice. The guest may need only enough feedback to know whether the assigned door worked. Record Focus modes, muted alerts, watch routing, duplicate alerts, and who acts when the owner does not respond.
Build a failed-entry path that does not weaken security
Write the order of recovery before the visit: retry once, check the correct entrance and time, contact the named owner, use an owner-controlled fallback, and stop if the door, alarm, or property condition looks unsafe. Do not leave a permanent code under a mat or send an administrator credential over chat.
If Home reports an accessory as unavailable, use the Accessory No Response checklist. Check lock battery and alignment, bridge or Thread path, Home hub, local network, vendor app, and the exact account. Do not remove and re-pair the lock during a live visit until the owner has setup codes, vendor credentials, physical access, and a rollback plan.
Keep an owner and backup-administrator path
A guest should not become the household’s only way to open a door. Keep a working owner device, physical or approved mechanical fallback, account recovery method, and a second trusted person who can act if the primary owner is unavailable. Run the backup-administrator drill before travel or a long absence.
The backup administrator should know the property, approved doors, guest identity, removal time, alarm rule, and emergency contact. They should not receive every owner secret. Give the least access that lets them recover the planned path, then test it.
Remove the person, codes, sessions, and routines
Removal is a multi-system job. Remove or expire the Apple Home guest, lock code, alarm user or PIN, camera share, garage and gate credential, vendor-app user, shared calendar entry, and any automation created for the visit. Use the temporary smart-lock code removal checklist to prove that both the visible code record and actual door access are gone.
Then sign out or close the guest device, reopen the apps, and retry the same door. Confirm excluded accessories remain excluded, history identifies the failed attempt correctly, owner alerts still arrive, and the regular household access path still works. A deleted name in one app is not proof that every credential stopped.
Record every change and exception
Guest access often changes at the last minute: a delayed arrival, different worker, new phone, alternate entrance, longer visit, failed lock, or emergency repair. Use the system change log to record the request, approver, previous state, new state, test result, expiry, and rollback.
Do not edit the person, schedule, code, lock, alarm user, and camera share in one batch and then guess which change caused a failure. Make one bounded change, test it, and close the record before the next change.
Run the 60-minute HomeKit guest-access acceptance test
- Minute 0-5 — Identity: confirm the real person, purpose, owner, property, visit window, and approved contact.
- Minute 5-10 — Accounts: list Apple Home, lock, alarm, camera, garage, gate, building, and shared credentials.
- Minute 10-15 — Scope: verify the guest role, selected accessories, approved door, excluded doors, privacy, and remote-access expectation.
- Minute 15-20 — Before window: try the approved credential early and confirm it does not work.
- Minute 20-25 — During window: unlock, open, close, relock, and verify the correct event and owner alert.
- Minute 25-30 — Exclusions: check that unassigned doors, cameras, rooms, alarms, and administrator settings remain unavailable.
- Minute 30-35 — Failure: test an approved offline or low-battery scenario with the owner present and use the written fallback.
- Minute 35-40 — Response: contact the primary and backup owner, explain the alarm rule, and record response time.
- Minute 40-45 — End window: wait for expiry or move the test schedule forward, then prove the same credential stops.
- Minute 45-50 — Removal: delete every separate share, code, PIN, session, and visit automation.
- Minute 50-55 — Revocation proof: retry entry and viewing from the guest device; both should fail as planned.
- Minute 55-60 — Owner recovery: verify normal owner access, alerts, lock state, alarm state, and the written change log.
Guest-access launch blockers
- The person is identified only by a generic shared role.
- The guest is a resident or administrator without a documented need.
- The approved door, excluded doors, start, stop, time zone, or overnight rule has not been tested.
- A lock code, alarm PIN, camera share, garage credential, or vendor account is missing from the ledger.
- The guest can see cameras, rooms, history, or controls beyond the visit.
- The owner receives no useful unlock, open-door, offline, low-battery, or alarm signal.
- A failed entry depends on an owner password, hidden permanent code, or unsafe improvised access.
- No backup owner can recover or revoke access.
- Removing the Apple Home guest leaves another credential active.
- There is no end-of-window revocation test, owner recovery test, or change record.
Do not share access until each blocker is closed. The plan passes when one named person can use only the approved route during the approved time, private controls stay private, owners receive useful signals, failure has a safe fallback, and every access path can be removed and proved inactive.