Moving into a home with Apple Home accessories is not the same as plugging in a router and choosing a new Wi-Fi password. A lock, camera, garage controller, alarm bridge, or motion sensor may still belong to somebody else’s Home, account, automation, or cloud plan. The hardware can look ready while ownership and recovery remain unclear.
This HomeKit security move-in checklist is for buyers, tenants, landlords, and property managers taking control of an existing smart home. It focuses on security devices and the questions that matter at handover: Who owns the Home? Which hubs and bridges are required? Are old users and codes gone? Can every device be reset and paired again? What keeps working when internet service fails?
Short answer: inventory first, transfer or reset ownership second, then rebuild access and automations from named accounts. Do not assume a working Home app tile proves that the new resident controls the device.
HomeKit move-in priorities at a glance
| Priority | What to verify | Why it matters |
|---|---|---|
| Ownership | Home owner, administrators, manufacturer accounts, monitoring account | Old users may retain remote control or recovery rights. |
| Physical access | Keys, lock codes, garage remotes, alarm PINs, installer codes | Digital cleanup does not revoke a copied key or remote. |
| Hubs and bridges | Apple TV, HomePod, Thread border router, vendor bridge, alarm hub | Removing one box can break remote control and automations. |
| Setup records | HomeKit QR codes, serial numbers, model numbers, reset steps | You need them after a reset, replacement, or failed migration. |
| Privacy | Camera view, microphone, recording rules, notification recipients | A camera can expose private space even when the lock is secure. |
| Failure behavior | Internet outage, power loss, dead phone, failed hub, low battery | Security must have a usable local fallback. |
Before keys change hands
1. Ask for an accessory and account inventory
Walk the property room by room. Record the brand, exact model, serial number, power source, location, and visible hub or bridge for each security-related accessory. Include door locks, garage controllers, cameras, video doorbells, contact sensors, motion sensors, smoke or CO alert bridges, leak sensors, sirens, keypads, alarm panels, routers, Apple TVs, and HomePods.
Do not label a device simply “HomeKit camera.” The exact model determines its reset procedure, account requirements, recording options, and whether it depends on a bridge. Photograph model labels only after checking that the image will not expose a setup code in a shared folder.
2. Separate Apple Home ownership from vendor ownership
Apple Home can provide a shared interface, but many products also use a manufacturer account. An alarm system may have its own owner, monitoring subscription, installer record, emergency contacts, and user PINs. A camera may use a vendor cloud account as well as Apple Home. A smart lock may hold keypad codes locally even after it disappears from the Home app.
Create four columns for each device: Apple Home, manufacturer account, physical credential, and paid service. Each column needs a named new owner or a documented decision to remove the device.
3. Decide whether to transfer, reset, or replace
A clean reset is often safer than inheriting a configuration nobody can explain. Transfer only when the vendor supports an explicit ownership handoff and the outgoing owner can complete it while both parties are present. Reset when the hardware is supported, the setup code is available, and the reset steps are known. Replace when ownership cannot be proved, the setup code is missing with no supported recovery path, security updates have ended, or the device cannot pass a basic failure test.
For equipment leaving the property, use the HomeKit accessory decommission checklist so recordings, automations, accounts, and physical labels are handled together.
The first 24 hours after move-in
Change physical and local credentials first
- Rekey or replace exterior cylinders when key custody is uncertain.
- Delete all inherited lock and garage codes, then create named codes for current residents.
- Replace generic alarm PINs and confirm duress, installer, and master-code behavior with the alarm provider.
- Collect or erase old key fobs, garage remotes, NFC credentials, and emergency keys.
- Test the mechanical key and manual garage release before relying on an app.
Use unique named credentials instead of one household code. Named access gives you a clean offboarding path and makes event history easier to interpret.
Create the new Apple Home deliberately
The incoming resident should own the Home from a current Apple Account protected by multi-factor authentication. Invite household members individually. Give management rights only to people who need to add accessories, edit automations, or manage users. Apple documents current sharing and permission behavior in Share control of your home.
If the outgoing owner is changing, follow a written sequence rather than passing around a shared login. The HomeKit administrator change checklist covers owners, administrators, hubs, locks, cameras, and recovery.
Rebuild the setup-code record
Record each HomeKit setup code in an encrypted password manager or another access-controlled system. Keep the accessory name, room, exact model, serial number, bridge dependency, reset method, purchase date if known, and last successful re-pair date beside it. Do not leave a spreadsheet of lock and camera setup codes in a public property folder.
Use the HomeKit setup-code inventory checklist to create a record that can survive a failed hub or phone replacement.
Hubs, Thread, Matter, and bridges
A reliable Home app screen can hide a chain of dependencies. A sensor may talk to a vendor bridge; the bridge may use Ethernet; remote access may rely on a HomePod or Apple TV; a Matter accessory may depend on a Thread border router. Removing the seller’s Apple TV or bridge can break remote control even though the accessory remains mounted.
For every device, draw the path from the accessory to the person receiving the alert. Mark the power source and network connection at each step. Then answer:
- Which Apple home hub is expected to stay in the property?
- Who owns and can update each vendor bridge?
- Which devices use Wi-Fi, Ethernet, Bluetooth, Thread, or a proprietary radio?
- Does the alarm continue locally when Apple Home or internet service is unavailable?
- Where are backup power and network equipment located?
If an accessory shows “No Response,” use the HomeKit No Response checklist to isolate accessory, bridge, hub, Thread, and network faults in order.
Locks, doors, garages, and life-safety exits
Smart-home convenience must not make an exit harder to use. Confirm that every lock turns smoothly by hand, the latch aligns without pulling the door, the mechanical key works, and residents know how to unlock it during power or network loss. For garages and gates, test the physical release and keep it protected from exterior reach.
List each access point with its normal state, auto-lock rule, code owners, battery type, low-battery warning path, and fallback. Do not enable a new auto-lock automation until residents have tested it while carrying groceries, using mobility aids, and returning after dark.
Cameras, microphones, and recording privacy
Camera handover needs a view-by-view review. Stand in each bedroom, bathroom approach, neighboring property line, shared corridor, and garden area that appears in frame. Adjust placement, zones, or recording rules before inviting more users. Check local laws and lease terms for audio and shared-space recording.
Apple’s current guide explains how supported cameras are added and managed in the Home app: Set up security cameras in Home on iPhone. The vendor may still control firmware, account access, or cloud retention, so review both systems.
For each camera, record:
- exact model, power source, Wi-Fi band or wired path;
- who can view live video, recordings, and microphone audio;
- when it streams, records, or turns off based on occupancy;
- retention location and subscription owner;
- how to export a clip and preserve the timestamp;
- what happens during internet, hub, or power failure.
Alarm system and Apple Home: define the boundary
A Home app scene is not automatically an alarm response plan. Identify which system owns arming, entry delay, siren activation, professional monitoring, panic functions, smoke or CO response, and emergency contacts. Confirm those functions in the alarm provider’s own documentation and app.
If you want a DIY system that can work without a long contract, compare the operating model in our no-subscription systems guide for new homeowners. Abode’s Smart Security Kit and current plan options are examples of a security platform that should be evaluated separately from its Apple Home integration.
Automations and scenes to rebuild, not inherit
Delete automations tied to old people, phones, schedules, or rooms. Recreate only those with a named purpose and a safe failure state. High-risk examples include unlocking on arrival, opening a garage, disabling cameras, and changing alarm modes.
For every security automation, document the trigger, conditions, action, fallback, owner, and test date. Test with the triggering phone offline, location access disabled, and the home hub unavailable. If the automation fails, the door should remain secure and the resident should still have a manual route inside.
60-minute HomeKit security move-in acceptance test
- Minutes 0–10 — accounts: confirm the Home owner, administrators, household members, vendor-account owners, monitoring contacts, and recovery methods.
- Minutes 10–20 — access: test every exterior key, resident code, garage remote, manual release, alarm PIN, and code deletion.
- Minutes 20–30 — sensors and alarm: open each protected door and window, walk each motion area, verify device names, and confirm the intended alarm response path.
- Minutes 30–40 — cameras: test live view, notifications, recording, microphone settings, privacy zones, timestamp, and clip export from an invited user’s phone.
- Minutes 40–50 — failures: disconnect internet service, then test a planned hub or bridge outage. Confirm local lock operation, alarm behavior, and the messages users receive.
- Minutes 50–60 — recovery: restore service, confirm every device returns, review event history, and record failures with an owner and deadline.
Pass only when the new resident can operate and recover the system without the previous owner. A screenshot of a working dashboard is not a handover record.
Move-in record to keep
- Property, handover date, and person responsible for the test
- Accessory inventory and exact models
- Account owners and recovery methods
- Home hubs, bridges, router, and backup-power map
- Physical keys, codes, remotes, and offboarding status
- Camera views, recording rules, and retention owner
- Alarm modes, delays, contacts, and monitoring plan
- Failed tests, temporary controls, owner, and retest date
HomeKit security move-in FAQ
Can a seller transfer an Apple Home to a buyer?
Treat this as an ownership and device-by-device handover, not a promise that every setting will move cleanly. Follow Apple’s current sharing guidance, transfer supported vendor accounts explicitly, and reset accessories when ownership cannot be proved.
Should I reset every HomeKit accessory after moving in?
Reset security-sensitive devices when account history, setup codes, old users, or recovery rights are unclear. A documented supported transfer may be reasonable, but it still needs access, outage, and recovery tests.
Does removing somebody from Apple Home remove their lock code?
Not necessarily. Locks, alarm panels, garages, and vendor apps may store separate users or local credentials. Remove access in every system and test the deleted credential.
Will HomeKit security devices work without internet?
Behavior varies by exact accessory, bridge, hub, and vendor service. Test local lock and alarm functions during a controlled outage. Do not assume remote alerts or cloud recording will continue.
What if a setup code is missing?
Check the device label, packaging, vendor app, and manufacturer support path. Do not use an unofficial bypass. If there is no supported recovery method and ownership cannot be proved, replacement may be the safer choice.