Updated August 2026.
A small-business smart lock needs a scheduled access audit. The owner should be able to match every active PIN, app user, key, card, fob, schedule, administrator, signed-in device, recovery method, and emergency entry route to one current person, role, door, approval, and review date. Former, shared, expired, or unexplained access should not survive because nobody reconciled the records.
This checklist is not a lock-picking or bypass guide. Use only maker-approved entry, recovery, reset, and service procedures. Confirm fire, egress, accessibility, lease, insurer, employment, privacy, and local code duties with the responsible professionals before changing door hardware or access rules.
Start with one door, access, and ownership register
Record each exterior, staff, delivery, stockroom, records, server, utility, garage, gate, and other restricted door. For each, save door and frame, handing, latch, closer, fire or egress duty, lock model, cylinder or emergency method, serial, firmware, local credentials, bridge or hub, radio, network, battery, direct alarm zone, lawful camera view, daily users, emergency users, service, warranty, owner, and recovery method.
Use the small-business smart-lock guide for product and door-fit records. Use the temporary-code removal checklist for cleaners, contractors, deliveries, and short-term users. Use the opening and closing checklist for daily operations.
For one first-party lock and alarm route, review the Abode Lock, Smart Security Kit, and current plans. Confirm the exact lock, hub, direct sensor, user, service, app, bridge, battery, key or emergency method, compatibility, ownership, and transfer state before purchase.
| Audit job | Exact record | Pass evidence |
|---|---|---|
| Reconcile active people | Named person, sponsor, role, approved doors, schedule, credential types, alarm and camera permissions, and review date | Every active credential has one current accountable owner |
| Find orphan credentials | Unknown, shared, dormant, duplicate, former, never-expiring, or owner-level records across locks, apps, keys, alarm, and cameras | Each orphan is disabled, explained, assigned, or escalated |
| Test least access | Role, business need, doors, hours, administrator rights, remote unlock, user management, history, export, and recovery | Routine users cannot reach unrelated doors or owner functions |
| Audit physical keys | Key identifier, holder, doors, issue, return, duplication rule, storage, last audit, missing-key owner, and cylinder decision | Every controlled key is present or has an approved containment record |
| Prove removal | Former staff, vendor, tenant, installer, device, PIN, app, session, key, card, alarm user, camera access, and recovery method | Former digital access fails and physical risk is closed or assigned |
| Test failure access | Internet, bridge, phone, battery, service, administrator, local credential, key or emergency method, alarm process, and owner | Authorized entry works and failed remote states are clear |
Classify every access method
| Method | Record | Failure to test |
|---|---|---|
| Mechanical key | Identifier, door, cylinder, holder, issue, return, storage, duplication policy, lost-key owner, and audit | Key unavailable, lost, duplicated, damaged, or held by a former person |
| PIN or keypad code | Named user, door, schedule, failed-entry limit, expiry, history, removal, and offline state | Expired, removed, repeated failure, low battery, and clock drift |
| Phone or app credential | Named account, device, role, invitation, Bluetooth or network path, session, recovery, and removal | No internet, no bridge, lost phone, signed-out app, and former session |
| Card, fob, or token | Identifier, holder, door, role, issue, return, lost-token response, removal, and spare custody | Lost, copied where applicable, damaged, offline, or unreturned token |
| Approved emergency power or maker route | Exact model instruction, compatible power or tool, storage, access, owner, inspection, and prohibited actions | Low battery, unavailable item, weather, darkness, and owner absence |
| Remote administrator action | Named admin, account, network, role, audit, verification, service, and unavailable-phone backup | Internet loss, stale state, service end, account lockout, and social-engineering attempt |
Physical key custody audit
- Assign an identifier to each controlled key without labeling it with an obvious public address. Record the exact doors and cylinders it operates.
- Use named issue and return records. Avoid an anonymous communal drawer, an unlogged copied key, or an emergency key whose holder is no longer reachable.
- Protect storage, issue authority, access to blanks, duplication records, spare keys, override tools, and the key register itself.
- Set a lost-key rule before a key is lost: who is told, who decides whether a cylinder or key system changes, which codes and accounts are reviewed, and who signs completion.
- Audit keys against people, roles, doors, business hours, contractor status, tenant status, and emergency duties. Record unreturned and unexplained copies.
- Do not hide a key near the door or publish its location in general staff messages. Use the business’s approved secure custody method.
Keep door, lock, alarm, app, and camera states separate
A mechanical or electronic lock event can show one lock state. A direct contact can show one protected opening state. An app can display a vendor state. A camera can record activity inside one lawful view. None automatically proves physical closure, latch, alarm-zone state, arming, evidence, or response.
Use the zone-naming guide so door labels, lock names, alarm zones, camera views, key registers, opening and closing checklists, and responder instructions describe the same place. Test physical open, physical closed, latched, locked, direct-zone, alarm mode, app state, local credential, camera record, warning, and response separately.
Review temporary and former access
- Record the outgoing person’s last authorized date and time, sponsor, role, doors, schedules, lock credentials, keys, app accounts, alarm users, camera access, shared links, service contacts, signed-in devices, and recovery methods.
- Recover physical keys, cards, fobs, phones, tablets, recovery devices, documentation, spare batteries, and vendor-owned equipment. Record anything not returned.
- Remove named credentials and sessions. Change shared codes, shared accounts, recovery methods, or physical cylinders where individual revocation cannot contain the risk.
- Test former PINs, app sessions, invitations, alarm permissions, camera access, shared clips, remote unlock, account recovery, and returned physical credentials from the outgoing person’s prior device where lawful and available.
- Assign every incomplete key, equipment, account, billing, service, or warranty step to a named owner and deadline.
Review current users and permissions
- Match each active identity to a sponsor, current role, permitted doors, business hours, emergency duties, alarm permissions, camera permissions, remote-unlock rights, user-management rights, and recovery authority.
- Reduce access that exceeds the current job. Avoid owner-level control for routine opening, closing, cleaning, delivery, maintenance, or incident notification.
- Review dormant users, never-expiring codes, shared credentials, unrecognized devices, repeated failed entries, unusual hours, unexplained administrator changes, and doors outside the person’s role.
- Have a sample of users complete unassisted allowed, denied, offline, low-battery, owner-unavailable, and emergency-entry tests.
- Sign the reviewed keys, codes, accounts, schedules, roles, devices, services, documentation, and recovery methods, with a next review date.
Network, battery, and service failure matrix
| State | Record | Pass condition |
|---|---|---|
| Internet disconnected | Local credentials, key, app, remote control, history, clocks, direct alarm zone, warning, queued events, and restoration | Required local entry remains honest and remote failures are clear |
| Bridge, hub, or access point unavailable | Lock, local credentials, stale app state, automations, alarm independence, user understanding, and recovery owner | No user mistakes old state for a live lock or door state |
| Battery low or dead | Warning lead time, battery stock, replacement owner, local entry, key, approved emergency method, clock, and history | Authorized entry works and the door relocks correctly |
| Primary phone or admin unavailable | Local controls, second admin, keys, alarm process, evidence, service contacts, and account recovery | Backup person completes the full route |
| Optional service ends | Local credentials, app, remote control, history, users, integrations, support, transfer, reset, deletion, and billing | Dated permanent-state worksheet is acceptable |
| Business network changes | Lock, bridge, hub, discovery, segmentation, firewall, stale state, installer access, documentation, and rollback | Access returns without weakening network boundaries |
Use the network-segmentation guide before moving locks, bridges, alarm devices, cameras, guest Wi-Fi, staff devices, or payment systems between networks.
Ownership, cost, and 60-minute access audit
Record who owns the door hardware, lock, keys, bridge or hub, alarm sensor, camera, network equipment, accounts, codes, services, warranties, installation map, recovery methods, and access history. Price lock and door work, cylinder or key-system changes, bridges, direct sensors, alarm equipment, cameras, network work, backup power, batteries, keys, cards, installation, services, replacement devices, support, transfer, tax, and staff time over 36 months.
- Minutes 0-8: reconcile doors, hardware, locks, zones, cameras, keys, credentials, radios, networks, batteries, users, services, owner, and recovery.
- Minutes 8-20: run 20 close, latch, lock, unlock, open, and relatch cycles; record physical, lock, alarm, app, clock, delay, duplicate, and miss states.
- Minutes 20-32: test allowed, denied, expired, removed, offline, low-battery, key, approved emergency, and failed-entry paths.
- Minutes 32-42: disconnect internet and one approved bridge or hub; compare lock, local credentials, alarm, app, history, stale state, and restoration.
- Minutes 42-52: make the primary owner unavailable and have the second administrator enter, secure, audit, handle the alarm route, and recover control.
- Minutes 52-60: reconcile active, former, shared, and orphan credentials plus physical keys; remove a test user, calculate cost, and sign ownership, egress, service, recovery, and next-review records.
FAQ
How often should a small business audit smart-lock access?
Set a schedule based on staff turnover, contractors, door risk, local duties, and incident history. Audit after every role or ownership change, missing key or phone, service or administrator change, door or lock repair, and suspected access problem.
What should a smart-lock access audit include?
Reconcile each door, active and former user, PIN, app account, key, card, fob, schedule, role, alarm permission, camera permission, administrator, signed-in device, service, recovery method, and emergency entry route. Then test allowed, denied, expired, removed, offline, and owner-unavailable states.
How do you find orphan smart-lock credentials?
Compare the lock, app, alarm, identity, contractor, scheduling, key, and HR or tenancy records. Every credential needs a named current person, role, sponsor, permitted door, schedule, approval, and review date. Disable and investigate records with no accountable owner.
Can a smart-lock app prove the business door is secure?
Not by itself. Test physical closure, latch, lock, direct alarm-zone state, app state, local credentials, warning, camera evidence where lawful, and response as separate records.
Should a small business keep a mechanical key for a smart lock?
Keep the maker-approved emergency entry method required by the exact lock and door. If that method is a key, audit custody, storage, issue, return, duplication, and lost-key response. Do not assume an app or remote unlock will work during every failure.