Home » Smart Lock Rekeying Checklist 2026: Keys, Codes, Cylinders, Accounts, and Handover

Smart Lock Rekeying Checklist 2026: Keys, Codes, Cylinders, Accounts, and Handover

Checked July 31, 2026. Rekeying a smart lock is only one part of an access change. It can change which physical key operates a supported cylinder, but it does not automatically remove keypad codes, app users, Apple Home or other platform members, voice routes, automations, shared links, vendor sessions, alarm permissions, camera access, or account-recovery methods.

The safe objective is a complete, testable new access state: the intended new keys and approved credentials work, every old physical and digital route fails, the door still latches and locks correctly, emergency egress remains simple, alarm and camera links behave as designed, and a second administrator can recover the system.

Decide whether this is maintenance, turnover, loss, or an incident

Trigger Required response Do not assume
Routine tenancy, ownership, staff, or household change Inventory keys, cylinders, codes, accounts, users, platforms, automations, alarms, cameras, responders, bills, support, and recovery; approve the new state before changing it A new code or key removes the old person’s other routes
Lost, stolen, copied, or unreturned key Record the exact key, door, last known holder, time, exposure, other matching cylinders, incident owner, interim control, rekey or replacement route, and digital-access audit The key was never copied or cannot identify the property
Unknown key history Treat every undocumented key and matching cylinder as unresolved; map the property and create a clean issuance record The keys received at move-in are the only copies
Locksmith, contractor, cleaner, agent, carer, or installer exit End physical, code, app, platform, camera, alarm, support, installer, and recovery access at one named time Returning one key ends remote or account access
Forced entry, tampering, unknown user, or suspicious event Preserve evidence, secure the property, follow the approved incident route, inspect the door and frame, and replace damaged hardware where required Rekeying alone repairs physical damage or removes an account compromise

Identify the exact door, lock, cylinder, and keyway

Do not begin with a generic “smart lock” instruction. Save the manufacturer, exact model, serial record, firmware, door, handing, bore, backset, thickness, trim clearance, deadbolt or latch type, cylinder, removable core where present, keyway, current key count, keyed-alike group, inside thumbturn, emergency-power route, physical override, warranty, approved parts, manual, support contact, and locksmith record.

Use the smart-lock retrofit guide to verify the physical fit and permission boundary. If the bolt drags or the door must be pushed or lifted to lock, fix and test the door with the door-alignment guide before blaming a cylinder, motor, app, or battery.

Physical record Why it matters Pass condition
Door, frame, hinges, latch, strike, bolt, weather seal, and egress A rekey does not repair binding, loose hardware, a damaged frame, or unsafe exit The door closes, latches, locks, unlocks, and opens freely without force
Exact cylinder, core, keyway, and supported procedure Rekey methods and replacement parts are model-specific The current manual, manufacturer, or approved locksmith confirms the route
Keyed-alike or master-key relationships One key may operate more than the named smart lock Every affected door and retained access level is listed and approved
Rental, strata, HOA, workplace, insurer, fire, and local rules The owner may not have authority to change a cylinder or master-key group Required written permission and handover terms are saved before work

Build the full access inventory before changing the key

Access layer Record Removal proof
Physical keys Unique key ID, holder, door or keyed group, purpose, issued date, returned date, copies allowed, storage, and destruction owner Every old key is returned or treated as exposed, then rejected at every affected cylinder
Keypad and credentials Named code, PIN, fingerprint, card, fob, phone key, schedule, door, role, start, end, notification, and removal owner The old credential fails locally and remotely while the approved new route passes
Vendor app Owner, administrators, members, guests, shared homes, sessions, trusted devices, integrations, recovery, and support access The removed person cannot sign in, control, view history, invite, or recover access
Smart-home platforms Apple Home or other platform member, role, remote control, scenes, automations, voice, presence, locks, cameras, alarm, and invitations Old membership, invitations, sessions, voice routes, automations, and recovery fail
Alarm and camera systems Panel user, disarm authority, door zone, lock event, camera view, recording, shared link, monitoring contact, installer, and responder Removed users cannot disarm, view, export, share, change settings, or receive protected events
Recovery and support Trusted devices, numbers, emails, backup codes, recovery contacts or keys, second administrator, locksmith, installer, account release, and bills An approved second person can recover control and a removed person cannot

Run the smart-lock access-code audit at the same time. If the change is part of a move or tenancy turnover, use the rental-turnover checklist so physical keys, accounts, codes, cameras, alarms, networks, and bills change together.

Plan a safe controlled work window

  1. Name the change owner, property authority, locksmith or support contact where used, second witness, start time, end time, rollback point, and incident contact.
  2. Keep safe physical entry and emergency egress available throughout the work. Do not leave children, residents, guests, workers, or vulnerable occupants dependent on an untested phone or app.
  3. Place any connected alarm or monitoring service in the approved test state before repeated door, lock, tamper, or entry tests. Record the start, contact, cancellation, restoration, and clean exit.
  4. Export needed incident records and save the current user, code, platform, automation, alarm, camera, and recovery state before changing access.
  5. Prepare the exact approved parts, current instructions, new keys, labels, key log, batteries where due, tools, and rollback hardware. Do not improvise a destructive cylinder or lock procedure.

Rekey or replace through the exact supported route

Follow the current instructions for the exact lock, cylinder, or removable core. If the route is unclear, the cylinder is damaged, the keyway is part of a master system, the lock is under warranty, the property has restricted keys, or a safe rekey cannot be proved, stop and use the manufacturer, property owner, or an approved locksmith. Do not force a key, cylinder, deadbolt, motor, or interior mechanism.

  1. Photograph and label the before state without exposing key cuts, codes, serials, reset data, or private account details in a shared record.
  2. Confirm the door is open and can remain safely controlled during the approved procedure.
  3. Complete only the exact supported rekey, cylinder change, core change, or lock replacement step.
  4. Test the new key gently with the door open, then test the old key rejection without forcing it.
  5. Close the door only after manual latch, bolt, thumbturn, key, emergency egress, alignment, and powered operation pass.
  6. Repeat open, close, latch, lock, unlock, and restore tests from inside and outside. Record every bind, incomplete throw, false locked state, motor retry, delay, and unexpected unlock.

Remove digital access after the physical change

Rekeying is incomplete until digital routes are reconciled. Remove or rotate each exposed code, credential, vendor user, platform member, invitation, voice route, automation, shared link, camera viewer, alarm user, installer route, trusted device, and recovery method. Change one layer at a time and keep a passed baseline for approved current users.

Do not solve an ownership problem by sharing the primary account password. Each approved person should have a named role and their own credential where the system supports it. Record who can unlock, add users, view history, operate cameras, disarm an alarm, change automations, export data, contact support, pay for service, transfer ownership, and recover the account.

Test the lock as a physical device and a security system

  1. Door mechanics: open, close, latch, lock, unlock, and restore 20 times. Test normal weather and pressure without forcing the door.
  2. Physical keys: test each newly approved key and every old or exposed key at every affected cylinder. Record pass or rejection, key ID, door, time, and witness.
  3. Codes and credentials: test every approved current credential once, then prove every removed code, phone key, fob, card, fingerprint, schedule, and guest route fails.
  4. Apps and platforms: verify the correct door state, remote-control boundary, notifications, history, automations, voice controls, invitations, sessions, and removed-member result.
  5. Alarm and camera links: trigger the named door sensor and approved lock events. Confirm the direct physical state, zone name, local warning, app history, camera evidence, purchased monitoring signal, trouble, restoration, and response.
  6. Emergency access: test inside egress, physical fallback, low-battery or emergency-power route where supported, unavailable phone, unavailable internet, unavailable hub, and unavailable owner.

Handle old keys, cylinders, and records safely

Count returned keys and mark unresolved copies as exposed. Store approved spare keys in the documented protected location. Dispose of old keys, cylinders, cores, packaging, QR codes, reset labels, and printed records through the property or manufacturer-approved route. Do not leave a working old cylinder, identifiable key, reset code, account secret, or full address together in ordinary waste or an unlocked drawer.

Keep the handover record separate from secrets. The shared record can name the door, cylinder, key IDs, holders, dates, access roles, administrators, responders, support contacts, and test results. Store actual codes, account passwords, recovery keys, key-cut data, and sensitive incident evidence in the approved protected system.

Test failures, rollback, and second-person recovery

Failure Record Pass condition
New key does not operate smoothly Door state, cylinder, key ID, insertion, rotation, bolt, alignment, old condition, support or locksmith action, and rollback No force is used; safe entry and egress remain available until corrected
App, hub, internet, or platform unavailable Local key, keypad, inside egress, direct sensor, warning, remote loss, history, missed events, reconnect, and restoration Approved local access and life-safety routes remain clear
Primary owner unavailable Second administrator, physical keys, alarm control, support, bills, ownership, recovery, and removal authority An approved second person can secure the property and remove access
Old credential still works Exact route, holder, door, account, platform, session, automation, camera, alarm, recovery path, containment, and retest The route is removed, every linked layer is audited, and current users are rechecked
Lock or cylinder must be rolled back Reason, approved old hardware, current key exposure, digital access state, door safety, alarm test state, responsible person, and retest The rollback creates a known temporary state with a named correction deadline

45-minute smart-lock rekey acceptance test

  1. Reconcile the door, frame, lock, cylinder, keyway, keyed group, keys, codes, users, platforms, automations, alarm, cameras, monitoring, support, bills, responders, and recovery owners.
  2. Open, close, latch, lock, unlock, and restore the door 20 times from inside and outside. Save every bind, incomplete bolt throw, false locked state, retry, delay, and unexpected unlock.
  3. Test every approved new key and credential. Prove every old key, code, app user, platform member, invitation, voice route, automation, shared link, vendor session, alarm user, camera viewer, and recovery route fails.
  4. Run safe low-battery, unavailable-internet, unavailable-hub, unavailable-phone, and unavailable-owner tests. Record local access, egress, warning, history, notifications, remote limits, restart, and recovery.
  5. Give the current key and access register to a second administrator. Have that person identify the physical fallback, remove a user, find the event history, contact support, and recover control without the primary phone.

Use the lockout-recovery checklist if normal access fails and the security handover checklist when the owner, resident, installer, network, or account changes. If directly purchased sensors with optional professional monitoring are part of the door design, compare Abode’s Smart Security Kit and current plans against the same access, alarm, failure, ownership, and recovery tests.

Smart lock rekeying FAQ

Does rekeying a smart lock remove app users and codes?

No. Rekeying changes a supported physical cylinder or keyway. Codes, app users, platform members, automations, shared links, vendor sessions, recovery methods, and alarm or camera access are separate routes that must be removed and tested separately.

Can every smart lock be rekeyed?

Do not assume so. Confirm the exact lock model, cylinder, keyway, door, manufacturer instructions, warranty, approved parts, and locksmith route. Some designs require a cylinder, core, or complete lock replacement rather than an owner rekey.

When should a smart lock be rekeyed?

Common triggers include a lost or unreturned key, move, tenancy or ownership change, contractor exit, unknown key history, locksmith work, damaged cylinder, or access incident. The full response must also cover digital credentials and account ownership.

How do I prove the old key no longer works?

Test every old key at the correct door from a safe controlled state without forcing the cylinder. Record rejection, the new key result, inside egress, latch and bolt travel, app state, code revocation, event history, alarm state, and a second-person handover test.

Have your say!

0 0