A HomeKit household can have working locks, cameras, alarms, and home hubs yet still be one lost account away from a long outage. The weak point is often not the accessory. It is the owner account, its trusted phone numbers, and an untested recovery route.
This 2026 checklist shows how to set up an Apple Account recovery contact without sharing passwords or giving another person owner-level control of the home. It also separates three roles that are easy to confuse: Apple Account recovery contact, Apple Home resident, and vendor-app administrator.
The short answer
Add a recovery contact for the Apple Account that owns the home, keep at least two current trusted phone numbers where practical, and give a second adult only the Home and vendor-app permissions they actually need. Then test the route on a spare device while the owner is available. A recovery contact can help with account recovery; that role does not automatically unlock the home, disarm an alarm, view cameras, or administer a security vendor account.
Three roles, three different powers
| Role | What it is for | What it should not imply |
|---|---|---|
| Apple Account recovery contact | Helps the account owner regain access by supplying a recovery code when Apple permits that process | Does not receive the owner’s password or automatic access to Apple Home |
| Apple Home resident | Controls shared accessories under permissions set by the home owner | Does not automatically become an Apple Account recovery contact or vendor-app owner |
| Security vendor administrator | Manages the alarm, lock, camera, monitoring, or device account under that vendor’s rules | Does not automatically gain Apple Account recovery authority |
Write these roles as separate rows in the household access register. Do not use one shared Apple Account to avoid role setup. Shared credentials make revocation, alerts, device removal, and event history harder to attribute.
Apple’s current requirements to verify
Apple’s account recovery contact instructions explain current eligibility and how a contact supplies a recovery code. Apple’s Apple Home sharing guide covers resident roles and permissions. The home hub guide explains that only home owners can add an Apple TV or HomePod as a home hub.
Read the current pages before changing the account. Software versions, role labels, and recovery requirements can change. Record the date you checked them, but do not copy passwords, device passcodes, recovery codes, or security-key details into the household sheet.
Inventory the owner account before changing anything
- Open Apple Home and confirm which person is shown as the home owner.
- List every iPhone, iPad, Mac, Apple Watch, Apple TV, and HomePod signed in under the owner’s account.
- List current trusted phone numbers and identify who controls each number.
- Confirm which home hub is connected and which hubs are on standby.
- List residents and the permissions each person has.
- List security vendor apps that use the same email address, plus their recovery and multi-factor methods.
- Confirm there is a local way to enter, lock, arm, and disarm if cloud account access is unavailable.
If the owner recently changed a password, use the Apple Account password-change checklist before adding another variable.
Choose the recovery contact deliberately
The contact should be reachable during an emergency, understand the limits of the role, and use a protected Apple Account of their own. A nearby adult may be more useful than a distant relative, but geography is only one factor.
- Availability: can the person respond if the owner is traveling or locked out?
- Device hygiene: does the person use a passcode, current software, and account protection?
- Boundary discipline: will the person refuse requests that do not follow the agreed verification call?
- Continuity: is the relationship likely to remain appropriate over time?
- Independence: does the person control a different phone number and device from the owner?
A recovery contact is not a substitute for a trusted phone number the owner can reach, a local key, or a second authorized alarm user.
Use a verification call, not a text-only request
Account recovery creates an opening for impersonation. Agree on a simple verification process before anyone needs it:
- The owner starts the request from an Apple device or Apple’s documented recovery path.
- The owner calls the contact using a known number or a pre-agreed alternate channel.
- The contact asks two non-secret context questions that an attacker is unlikely to know.
- The contact generates the recovery code only after the call is verified.
- The code is given directly to the owner and is not stored in chat history.
- Both people note the date and whether recovery succeeded, without recording the code.
Do not ask the contact to send screenshots of account settings, passwords, one-time sign-in codes, or device passcodes.
Check trusted phone numbers separately
A recovery contact and a trusted phone number solve different problems. Review each trusted number and remove numbers that were recycled, transferred, or belong to a former employee, former partner, or old family plan.
- Confirm the owner can receive a call or message at the number.
- Confirm the carrier account has its own PIN or transfer protection.
- Keep a second trusted number when the household can do so safely.
- Record the number owner and review date, not the verification codes.
- Repeat the check after changing carriers or phone numbers.
Map Apple Home permissions
Apple Home access should be assigned to people, not devices left signed in under the owner’s account. Review the current resident list in Home Settings. Remove old residents and confirm whether each remaining person needs remote access, camera access, accessory control, or the ability to add and edit accessories.
Use the HomeKit camera household-access audit for live view, recordings, audio, exports, and revocation. A resident who can turn on a light may not need access to indoor cameras or security recordings.
Keep vendor-app recovery independent
HomeKit may show a lock, camera, or alarm, but the accessory maker’s app may still own firmware, users, event history, subscriptions, and device removal. For every security vendor account, confirm:
- the account owner and recovery email;
- the multi-factor method and a second recovery route;
- which adult can arm, disarm, unlock, export, or delete;
- whether a removed Apple Home resident still has vendor-app access;
- whether a vendor password reset invalidates existing sessions; and
- how to regain control if the owner’s phone is unavailable.
Do not assume removing a person from Apple Home removes them from the lock, alarm, camera, or monitoring account.
Build local entry and alarm fallbacks
Account recovery can take time. The home must remain usable while the owner cannot sign in.
| Job | Primary route | Independent fallback |
|---|---|---|
| Enter the home | Phone key or Home app | Named keypad code or controlled physical key |
| Lock the door | Automation or app | Local keypad, thumb turn, or key |
| Disarm the alarm | Home or vendor app | Named PIN on a local keypad |
| Receive an alarm | Owner’s push notification | Second authorized user or monitoring response path |
| View an event | HomeKit or vendor recording | Second authorized viewer or local storage where supported |
For a dead, lost, or stolen device, follow the lost iPhone HomeKit checklist. For planned hardware changes, use the iPhone replacement checklist.
Run a controlled recovery drill
Do not deliberately lock the owner out. Run the drill while the owner remains signed in on a trusted device and can stop the test.
- Confirm the selected recovery contact appears in the owner’s account settings.
- Have the contact find the recovery-contact controls on their own device.
- Confirm both people know the verification call and the alternate contact channel.
- Power down the owner’s primary iPhone for the rest of the test.
- Use another authorized device to open Apple Home and inspect the home-hub state.
- Have the second adult unlock, enter, disarm, re-arm, and lock using named local credentials.
- Confirm the owner can still access the vendor accounts from a second trusted device.
- Restore the primary phone and confirm alerts, resident permissions, cameras, and automations.
The signed-out behavior should also be checked with the HomeKit signed-out phone test.
What to record
Keep a short control sheet in a protected location. Record:
- home owner name and Apple Account address;
- recovery contact name and review date;
- trusted phone-number owners and last verification date;
- primary and standby home hubs;
- Apple Home residents and their permission level;
- vendor-account administrators;
- local key, keypad, and alarm fallback owners;
- last drill date, failures found, and retest date.
Never record the Apple Account password, device passcode, one-time codes, recovery codes, lock PINs, or physical-key hiding location in that sheet.
When to repeat the audit
- after replacing the owner’s phone;
- after changing an Apple Account password or trusted number;
- after a resident moves in or out;
- after changing carriers or losing a phone;
- after adding a new home hub, lock, alarm, or camera;
- after a relationship or employment change; and
- every six months even if nothing obvious changed.
Do not approve the recovery plan until these blockers are cleared
- No one can identify the Apple Home owner.
- The only trusted number is disconnected or controlled by someone else.
- The proposed recovery contact uses the owner’s shared credentials.
- No second adult can enter and disarm locally.
- Removing a resident from Apple Home does not remove their vendor-app access.
- The household has no tested path for a lost owner phone.
- The recovery sheet contains passwords, PINs, or one-time codes.
Frequently asked questions
Can an Apple Account recovery contact see my HomeKit cameras?
Not because of the recovery-contact role. Camera access depends on Apple Home permissions and any separate vendor account.
Should my Apple Home resident also be my recovery contact?
They can be the same person, but the roles should be approved separately. Give each role only when the person needs it and meets the household’s verification rules.
Does a recovery contact get my password?
No. Apple’s process uses a recovery code. Follow Apple’s current instructions and never send passwords or device passcodes.
Will account recovery keep my alarm working?
The alarm’s local behavior depends on its own hub, keypad, sensors, power, network, and service. Test those jobs independently of Apple Account access.
What is the most important fallback?
A second authorized adult should be able to enter, disarm, re-arm, and lock locally without the owner’s phone.
Bottom line
The safest HomeKit recovery plan does not hand one person every credential. It separates Apple Account recovery, Apple Home control, vendor administration, and local entry. Assign the roles, test them, and keep at least one path that works without the owner’s phone.