Home » Smart Lock House Cleaner Access Checklist 2026: Named Codes, Schedules, Privacy, and Offboarding

Smart Lock House Cleaner Access Checklist 2026: Named Codes, Schedules, Privacy, and Offboarding

A house cleaner needs reliable entry during an agreed service window, but usually does not need permanent household access. A smart lock can make that boundary visible: one named code, one approved door, one schedule, one backup contact, and one person responsible for removal. The lock does not create the policy. The household must decide it before the first visit and test it at the door.

This checklist is for owner-occupied homes, apartments, condos, and small rental properties where a cleaner enters without a resident opening the door. It is not a product ranking. Door fit, fire and egress rules, landlord or association approval, local privacy law, insurance requirements, and the exact lock manual take priority.

House-cleaner smart-lock plan at a glance

Control Decision to record Proof before service starts
Person Name the cleaner or assigned company worker. Do not label a code only “Cleaner.” The person and company contact are written in the access register.
Door Choose one service entrance that can be locked, observed, and recovered. The exact door, latch, deadbolt, sensor, and inside release pass a physical test.
Time Set the earliest entry, latest exit, service days, start date, and review date. An allowed attempt works and an outside-window attempt fails safely.
Credential Use an individual code or invitation where the lock supports it. No resident, contractor, or former worker shares the credential.
Privacy State which camera views, audio, rooms, and records exist. The camera boundary is lawful, disclosed where required, and limited to the entry purpose.
Alerts Choose who receives entry, failed-attempt, held-open, low-battery, and offline alerts. Each alert reaches a named person who knows what to do.
Failure Define backup entry, lockout help, power recovery, and an unavailable owner. The backup path works without disclosing a resident master code.
Removal Name the person who disables access after the final visit or staffing change. Revocation is tested from outside and the result is logged.

Start with the door, not the app

A valid code is useless if the deadbolt binds, the strike is shallow, the door must be pulled to lock, or the battery cover is loose. Inspect the door closed and open. Record door material, thickness, backset, bore size, handing, deadbolt throw, strike attachment, frame condition, weather exposure, hinges, seals, and inside release. The bolt should extend without a person pushing or lifting the door.

Use the smart-lock physical security audit to separate mechanical strength from app features. If installation or recalibration changes the fit, complete the door handing and calibration checklist before issuing a service code.

Choose an entrance that reduces travel through private rooms. A side or garage personnel door may be a better service route than the main entry, but only if it has safe lighting, a reliable network path, a tested door sensor, and a clear emergency exit. Do not direct a worker through a hazardous storage area merely to keep the front door private.

Give one person one named credential

Individual credentials make entry and removal easier to understand. Record the cleaner’s name, employer, purpose, issue date, approved door, allowed days, allowed hours, expiry or review date, issuer, and removal owner. If a company rotates workers, ask how assignments are confirmed. Do not assume the person who arrived last week will arrive next week.

A shared company code hides who used it and can remain active after staffing changes. A resident master code is worse because it often works at every hour and may control settings. If the lock cannot issue a separate worker credential, document that limit and decide whether resident-opened entry, a supervised key handoff, or a different lock is safer.

The smart-lock access-code audit provides a register for guests, contractors, workers, and former residents. For a short engagement, use the temporary access code checklist to create, test, expire, and remove the code.

Build the schedule around real cleaning work

A narrow schedule can fail if parking, key pickup, a late customer, traffic, or a longer service shifts arrival. An all-day schedule may expose more access than the job needs. Agree on a practical window with a small arrival buffer and a defined overrun rule. The household should know whether an entry at the edge of the window is expected, denied, or escalated.

Schedule field Example decision Failure to test
Service days Only the confirmed weekday or one-time date Attempt on an unapproved day
Entry window Agreed arrival range plus a written buffer Attempt just before the opening time
Exit window Enough time to finish, check doors, and report departure Attempt after the closing time
Start date First booked visit, not the day the code was created Attempt before the first visit
End or review date Final visit or a short review interval for ongoing service Attempt after revocation or expiry
Holiday handling Confirm each moved or skipped visit Test the original day after rescheduling

Do not rely on the app label alone. Stand outside, let the schedule change take effect, and test both an allowed and denied attempt. Record the lock’s local time, phone time, time zone, daylight-saving behavior, and the result. A schedule that looks right in the app but behaves differently at the door is not ready.

Keep alarm access separate from door access

Opening the door and disarming an alarm are different permissions. Decide whether the cleaner needs an alarm user, a limited PIN, a monitored-system verbal passcode, or no alarm access because a resident changes the state remotely. Do not reuse the door code for the alarm merely because it is easy to remember.

Write the arrival order: identify the assigned worker, unlock the approved door, disarm only if authorized, confirm the correct area, and report an unexpected alarm state. Write the departure order too: check specified windows and doors, remove any temporary bypass, arm the agreed mode, lock the service door, verify the door state, and send a completion message.

If the alarm cannot support an appropriately limited user, treat that as a design constraint. A code that can change owners, monitoring contacts, billing, camera access, or every alarm setting is too broad for routine cleaning access.

Set a camera and privacy boundary before entry

A doorbell or exterior camera can confirm arrival, departure, a held-open door, or an unknown companion. It should not become a reason to record private work areas without a lawful purpose. Map each camera’s physical view, activity zone, audio setting, recording state, retention, export rights, shared viewers, and behavior after any optional plan ends.

Tell the cleaner what is recorded where disclosure is required or expected. Never place cameras in bathrooms, changing areas, or other spaces where people reasonably expect privacy. Indoor recording rules vary by location; obtain local advice when the boundary is unclear.

Use the camera privacy-zone guide to measure the view rather than trusting an app thumbnail. If the household uses Apple Home, the Apple Home activity-history audit helps define who can see lock and alarm events and how long that history supports the access purpose.

Decide which alerts deserve action

More alerts do not automatically create better response. Every enabled alert needs an owner, a delivery path, an expected time, an action, and a fallback if the first person does not respond. Test on the primary phone and a backup contact where the risk justifies it.

Event First check Escalation
Expected unlock Does the named event match the booked worker and time? Contact the cleaner or company only if the identity or timing is wrong.
Failed attempts Confirm a mistyped or expired code without revealing another code. Use the lockout plan after the agreed attempt limit.
Door held open Check whether equipment is moving through the door. Call if the open period exceeds the agreed work step.
Unexpected relock failure Check door alignment and reported bolt state. Keep a person at the property or send an authorized responder.
Low battery Confirm the exact lock and recent replacement record. Replace and retest before the next unattended visit.
Offline lock or hub Separate a network outage from a dead lock or dead battery. Use the documented local entry and verification path.
Entry outside schedule Confirm time zone, schedule, and company assignment. Treat unexplained access as an incident and preserve records.

Use the alert escalation checklist to set response ownership. If an alert arrives late, silently, or only while the app is open, fix notification permissions and power-saving behavior before depending on it.

Prepare for lockouts without sharing a master code

A lockout plan should answer five questions: who confirms the assigned worker, who can grant or restore access, what local backup exists, who can reach the property, and what happens when the owner is unreachable. The plan should work when the internet is down and should not require texting a permanent resident code.

Keep any mechanical backup key controlled, labeled without the address, and recorded when issued or returned. If the lock has external emergency-power contacts or a supported power port, test the exact method in the manual with the door open first. Emergency power may wake a keypad; it does not necessarily retract a jammed bolt or replace account access.

The smart-lock lockout recovery checklist covers keys, batteries, accounts, locksmiths, and recovery tests. The emergency-power test covers battery contacts, supported ports, backup entry, and a timed drill.

Treat battery and network failures as separate events

A low lock battery, dead phone, failed home hub, internet outage, cloud outage, and failed automation are not the same problem. Record what still works locally in each state. A keypad code may continue when remote control and notifications stop; another model may depend on a hub for schedules or activity history. Verify the exact lock instead of assuming.

Set a battery replacement owner and threshold. Keep the correct battery type on hand if the manufacturer permits. Record replacement date, battery type, terminal condition, calibration result, local code test, remote status, and alert reset. Follow the battery replacement checklist to prove the door still locks without binding after new batteries are installed.

For network failure, test local entry, local locking, door-state reporting, queued history, remote commands, notifications, and recovery order. Do not promise remote rescue until it has worked in a controlled outage.

Control keys, tools, and changes inside the home

Smart-lock access does not decide what a worker may do after entry. Write a short property handoff: approved rooms, doors that must remain closed, pets, alarm sensors, windows, gates, chemicals, fragile areas, thermostat limits, and who may approve a change. Avoid leaving spare keys, master codes, recovery codes, or unlocked account devices in the work route.

If cleaning requires a window, patio door, or balcony door to open, name it and include it in the departure check. If a sensor is bypassed, name who restores it. If furniture or equipment blocks a camera, motion detector, or door, retest after the room is reset.

Do not ask a cleaner to troubleshoot wiring, remove a lock, share account credentials, or make a security decision outside the service agreement. Escalate those tasks to the household owner, property manager, installer, locksmith, or alarm provider.

Use a written arrival and departure sequence

Stage Cleaner action Household proof
Before travel Confirm date, arrival range, assigned worker, and any change. Booking and active credential match.
At the door Use only the named credential at the approved entrance. Expected event arrives with the correct door and time.
After entry Close the door, confirm it latched, and disarm only if authorized. Door state and alarm state are correct.
During work Follow the written room, pet, window, and privacy boundaries. No unexplained door, alarm, or account event appears.
Before departure Check listed windows, doors, gates, sensors, and alarm state. Departure checklist is completed.
At departure Close and lock the service door, verify the bolt, and report completion. Locked state and departure event match.
After final service Do not retain or reuse the credential. Household removes access and proves a denied attempt.

Offboard access after staffing or service changes

Remove access when a cleaner stops working at the property, a company changes the assigned person, the service pauses, a phone is lost, a credential is shared, or the purpose changes. Do not wait for the next annual audit. Disable the named credential, remove any alarm user, close any app invitation, recover physical keys, remove trusted sessions, and verify that resident access still works.

Then test from outside. A code that disappeared from the owner screen but still unlocks locally has not been removed. Check both scheduled and unscheduled periods if the platform stores multiple rules. Review the event history for unexplained use and record the final removal time.

The HomeKit member-removal checklist covers locks, cameras, codes, and access tests. Use it even when the worker was never a full Apple Home member; it helps confirm that no invitation, shared view, automation, or trusted device remains.

Run a 75-minute house-cleaner access acceptance test

  1. Minutes 0–10 — authority and scope: confirm the assigned person, company contact, service dates, approved door, rooms, privacy boundary, pets, alarm plan, and removal owner.
  2. Minutes 10–20 — physical door: test latch, deadbolt, strike, hinges, inside release, door sensor, manual key, and locking without pushing or pulling.
  3. Minutes 20–30 — credential: create one named code or invitation, verify the start and end rule, make an allowed attempt, and confirm the event identifies the right credential.
  4. Minutes 30–40 — denial: test before or after the allowed window, a wrong code, the attempt limit, and the recovery path without exposing a resident code.
  5. Minutes 40–50 — alarm and alerts: test expected unlock, failed attempt, open door, relock, and the agreed alarm transition on the primary and backup response paths.
  6. Minutes 50–60 — privacy and outage: confirm camera view and audio boundary, disconnect the network path, and prove the promised local entry and locking behavior.
  7. Minutes 60–70 — departure: follow the room, window, gate, sensor, alarm, door, and completion-message checklist in the real order.
  8. Minutes 70–75 — removal: disable the worker credential, attempt entry from outside, confirm denial, restore approved access if service is continuing, and save the test record.

House-cleaner access scorecard

Area Pass condition Fail condition
Identity Credential maps to a named assigned person and company contact. Shared or unexplained “Cleaner” code.
Door Deadbolt moves freely and the reported state matches the door. Binding, shallow strike, or false locked state.
Schedule Allowed and denied tests match the recorded window. Entry works outside the approved period.
Alarm Worker has only the required alarm action. Door code doubles as broad alarm or account control.
Privacy Views, audio, records, and viewers have a stated purpose and lawful boundary. Hidden, excessive, or unexplained recording.
Alerts Named responders receive and understand tested events. Alerts are late, silent, duplicated, or ownerless.
Recovery Backup entry works during network, battery, or owner-unavailable cases. Recovery requires sharing a resident master code.
Removal Revoked access fails at the door and is logged. Credential remains usable or cannot be attributed.

Do not approve unattended cleaner entry until these blockers are cleared

  • The door binds, the bolt does not fully extend, or the app reports locked while the door is open or unlatched.
  • The household cannot identify the assigned worker or confirm a staffing change.
  • The only available credential is a resident master code, shared company code, or full-owner account.
  • The schedule has not been tested at the door on both sides of the allowed window.
  • The cleaner needs alarm access, but the available role grants unrelated account or monitoring control.
  • The camera or audio boundary is hidden, unlawful, or broader than the stated entry purpose.
  • No one owns failed attempts, held-open doors, low batteries, offline states, or unexpected entry alerts.
  • Backup entry depends on internet service, one unavailable phone, or texting a permanent household code.
  • No named person will remove access after a final visit, service pause, phone loss, or staffing change.
  • Revocation has not been proved with a denied attempt from outside.

Related smart-lock access guides

Frequently asked questions

Should a house cleaner receive a permanent smart-lock code?

Usually the safer default is an individual credential limited by purpose and reviewed on a short schedule. Ongoing service may justify a recurring window, but it should still have a named owner, a review date, and a tested removal path.

Can the cleaner use the same code as the family?

No. A shared resident code removes attribution and makes offboarding harder. Use a separate code or invitation where the lock supports it.

What if the cleaning company sends different workers?

Require assignment confirmation before entry. If the lock cannot issue distinct credentials quickly, use resident-opened access or another controlled handoff rather than one indefinite code shared across unknown workers.

Should the cleaner have camera access?

Door entry does not automatically require live video, recordings, audio, or camera settings. Grant only the permission needed for the service and keep recording within local law and the stated purpose.

What happens if the smart lock is offline?

That depends on the exact lock, credential type, hub, and schedule design. Test local entry, local locking, notifications, remote commands, and recovery during a controlled outage before promising unattended access.

How should access be removed?

Disable the named lock credential, remove related alarm or app access, recover keys, close trusted sessions, and then attempt entry from outside. Record the denied result and confirm resident access still works.

Have your say!

0 0