A smart lock is only as controlled as its current user list. Audit every code, app account, key, automation, and recovery path after a guest stay, contractor visit, roommate change, move, lost phone, or household staffing change. The goal is not to delete everything. It is to know who can enter, through which door, during which hours, and how that access will be removed.
Smart-lock access audit at a glance
| Access type | Verify | Action |
|---|---|---|
| Owner/admin account | Named owner, recovery email/phone, MFA, current devices | Remove shared admin logins and stale devices |
| Permanent household code | One named person per code | Replace shared codes with individual codes |
| Guest code | Purpose, start/end time, door scope | Expire after the visit |
| Contractor or cleaner | Scheduled window and work order | Use temporary access; revoke after handover |
| Former resident or employee | Codes, app membership, keys, automations | Remove in a written offboarding sequence |
| Physical key or key box | Holder, copies, storage, return status | Rekey if custody is uncertain |
1. Export or record the current access list
Before changing anything, capture the lock name, door, owner account, admins, members, codes, schedules, linked home platform, bridge or hub, physical keys, and recovery method. Use names such as “Pat — dog walker” instead of “Guest 3.” If the lock cannot label codes, maintain a protected code register that records purpose and expiry without exposing the code itself.
2. Separate admin, household, and temporary access
- Admin: can change users, settings, integrations, and recovery. Keep this group small.
- Household: regular entry without system administration.
- Temporary: guests, cleaners, trades, carers, pet sitters, and deliveries with a defined window.
- Emergency: a tested fallback for an authorized contact, stored and reviewed separately.
Do not reuse an alarm master code as a lock code. Do not give contractors the owner account merely because temporary access is inconvenient.
3. Check every code against a person and purpose
For each code, answer five questions: Who uses it? Which door opens? When should it work? When was it last needed? Who owns revocation? Delete unknown codes only after confirming they are not tied to an emergency plan, accessibility need, property manager, or service agreement.
4. Audit schedules and door scope
A cleaner may need Tuesday access to the side door, not permanent access to every exterior lock. A short-term guest may need entry for a weekend, not until someone remembers to delete the code. Test scheduled access at the beginning, during, and after the permitted window. Confirm the lock uses the correct time zone after daylight-saving, router, hub, or firmware changes.
5. Remove access in the right order
- Preserve any access history required for a dispute, incident, or handover.
- Confirm the person no longer needs legitimate entry.
- Remove the app member and lock code.
- Remove Apple Home, Google Home, Alexa, alarm, camera, garage, and property-management access separately.
- Collect physical keys, fobs, remotes, and key-box details.
- Test the removed code and account at the door.
- Record who completed the offboarding and when.
6. Review event history without over-trusting it
Named code events can help confirm normal access, but a log is not perfect proof of identity. Codes can be shared, doors can be left open, manual keys may not appear, clocks can drift, and offline locks may sync late. Use the log to investigate exceptions, then confirm with the people involved and other lawful evidence.
7. Test batteries, connectivity, and local entry
Run the smart-lock battery and outage checklist. Verify the physical key or approved backup, low-battery warning, keypad, app, bridge, hub, Wi-Fi, local operation, and behavior during internet and power failures. Access control is incomplete if the household cannot enter when the owner’s phone or cloud service is unavailable.
8. Coordinate the lock with the alarm
Decide whether unlocking should disarm the alarm and whether that automation is safe for every user. A temporary lock code should not silently grant permanent alarm, camera, or admin access. Test the door sensor, entry delay, siren, notifications, and monitoring process with the provider’s approved test mode.
9. Protect privacy and recovery
Use individual accounts, strong unique passwords, multi-factor authentication where supported, current recovery details, and named household roles. Review the guest-access guide and installer-access checklist when access also reaches cameras, alarm settings, or network equipment.
10. Set an audit cadence
Review access quarterly and immediately after a resident, employee, cleaner, contractor, carer, guest, property manager, phone, hub, or lock changes. A useful audit ends with zero unknown codes, a named owner for each active credential, a tested fallback, and a date for the next review.
Where Abode fits
For a sensor-led system around smart-lock access, compare the Abode Smart Security Kit, the current Abode plans, and the Abode Lock. Verify current lock fit, code roles, supported integrations, automations, event history, backup entry, and monitoring behavior for the exact setup before buying.
FAQ
How often should smart-lock codes be audited?
Quarterly is a useful baseline, with an immediate audit after any resident, guest, contractor, cleaner, carer, employee, phone, account, hub, or lock change.
Should every person have a separate code?
Yes where the lock supports it. Named codes make access easier to revoke and exceptions easier to investigate without changing every household member’s credential.
Is deleting a lock code enough when someone leaves?
No. Remove app membership, home-platform access, alarm and camera roles, garage access, physical keys, fobs, remotes, and recovery access separately, then test the removed credential.
Can a smart-lock event log prove who entered?
Not by itself. Codes can be shared, clocks can drift, and physical keys or open doors may bypass the recorded event. Treat logs as one source of evidence.