A facilities manager asks for another restricted key. The request sounds routine, but their name is not on the authority record. Stop there. A locksmith key control register should connect approval, cutting, issue and return before another key leaves your shop.
The register is not just a list of key numbers. It is the operating record for the site. It tells you which keys exist, who controls them, who holds them and what needs attention.
Set up the locksmith key control register before issuing another key
Build the record around the site and its key system. Do not start with a loose list of employee names. People move between departments. Contractors finish projects. Locks change. The site stays at the centre of the record.
A spreadsheet, controlled paper log or job record can all work. Pick one record as the current version. If staff keep private copies, you will eventually have two different answers to the same question.
Create one site record and one naming system
Give each customer site a stable identifier. Use that identifier on the register, door schedule, work order and service notes.
Set one naming convention for openings, key groups and holders. Write it down. If the key stamp says one thing, the door schedule says another and the commercial key register uses a third label, the technician cannot make a clean match.
Keep the labels boring. Site ID. Opening reference. Key ID. Holder. Status. Dates. Authority. Plain labels are easier to audit than codes understood by one employee.
For a customer with several properties, keep a separate site record for each address. A portfolio view can show every site, but it should not replace the site-level detail.
Link four records instead of changing one row
Build the register from four linked records: the key asset, authority, custody events and audit exceptions. Give each record its own identifier and connect it to the same site and key ID.
The key asset record identifies the physical key or controlled set. Record its key ID, system, approved access reference, type and current status.
The authority record names who may request, approve, receive or return controlled keys. Add effective dates and preserve old authority records when contacts change.
The custody event records every issue, transfer and return. Add a new event for each handoff instead of replacing the previous holder. Record the recipient or controlled location, approval reference, issuer, dates and acknowledgement.
The audit exception record holds missing keys, overdue returns, conflicting identifiers and other unresolved findings. Record the owner, follow-up date, decision and closure reference without changing the custody history.
Use simple asset statuses: unissued, issued, returned, missing, damaged and retired. An overdue key stays issued until it is returned or confirmed missing. Record the missed due date and follow-up owner as an open audit exception.
Keep sensitive door information off the tag
A key identifier must let authorized staff match the physical key to the record. It should not tell a stranger what the key opens.
Do not put the street address, room name or plain-language access description on a visible tag. Use a controlled identifier. Keep the opening details in the protected register or door schedule.
The physical stamp, tag and register should still match. Test that match at the bench before handing over the key.
Separate restricted key authority from key custody
Authority and custody are different jobs. The person carrying a key does not automatically have permission to order another one.
Write down who may request, approve, receive and return each controlled key type. One person may hold several roles, but do not assume it. The customer decides the authority chain, subject to the controls attached to the key system and any local requirements.
Check authority before cutting or releasing a key
Compare every request with the current restricted key authority record. Check the site, system, requested quantity, access group and approving person.
If the requester is not listed, stop the order. Ask the customer’s authorized contact to confirm or update the authority record. Do not accept a familiar voice, old email chain or job title as a replacement for current approval.
Record the request reference and the approval used. That gives the next technician a direct trail from authority to cutting and release.
A property manager may authorize work while a building employee receives the key. Record both people in their proper roles. Do not put the recipient in the approval field merely because they were standing at the counter.
For broader commercial service controls, use the property-management locksmith contract guide to define contacts, approval limits and site records before calls start arriving.
Stop when the records disagree
A technician arrives to issue a restricted key. The facilities manager making the request is missing from the current authority record. The job does not move forward until the authorized customer contact resolves the mismatch.
Record the stopped request. Note who was contacted and what must change. Do not cut the key and promise to clean up the paperwork later.
This protects the customer and your crew. It also prevents an informal request from becoming the new authority process without anyone making that decision.
Give every key and controlled set a traceable identifier
Track individual keys when individual custody matters. Track a sealed or controlled set as one unit only when the customer actually handles it that way.
If a department receives several keys for different staff, separate records are cleaner. If a lockbox holds a controlled emergency set, identify the set and record the lockbox as the controlled location.
Record every kind of holder
The holder does not have to be a person. Use a holder type so the record stays clear.
Common holder types include:
- Employee
- External contractor
- Site department
- Security desk
- Lockbox
- Key cabinet
- Unissued shop stock
For a person, record the name and organization. For a location, record its controlled identifier and the person responsible for that location.
A lockbox is not an empty holder field. It is a custody location. Count its keys during the audit and record who controls access to the box.
Preserve the history when custody changes
Do not overwrite the previous holder and lose the trail. Close the old custody event, then add the new custody event under the same key asset.
Keep missing, damaged and retired keys in the history. Changing a missing key to returned just to clear an exception makes the register wrong. Deleting a retired key hides which old identifiers may still turn up later.
When a key is damaged, record whether it was surrendered. When it is retired after a rekey, connect it to the work order that changed the cylinder or access group.
Complete the key issue record at the handoff
The handoff is where custody changes. Finish the key issue record while the key, recipient and approved request are together.
First, match the physical identifier to the register. Then check the recipient against the approved request. Record who released the key and when.
Add the purpose and expected return date when the key is temporary. A contractor key issued for one project should not drift into permanent custody because nobody entered a return point.
Record proof without inventing a universal rule
Customer policy, key-system controls and local requirements can differ. Agree with the customer on what acknowledgement or proof the handoff needs.
The record may include a recipient signature, initials, a digital acknowledgement or another customer-approved confirmation. Record the method used. Do not claim that one form of signature works for every site or every key system.
Keep the custody record easy to find. You can attach the request, work order and service notes, but do not bury the key issue record inside a long technician description.
Copy-ready linked register template
Use this as a blank starting point. Keep each table as a separate record and join them with the site ID, key ID and related references.
#### Key asset record
| Field | Entry |
|---|---|
| Customer | [Customer name] |
| Site ID | [Controlled site identifier] |
| Key ID or set ID | [Identifier] |
| Key system or series | [System reference] |
| Approved access reference | [Controlled opening or group reference] |
| Key type | [Standard, controlled or restricted] |
| Current status | [Unissued, issued, returned, missing, damaged or retired] |
| Rekey or retirement reference | [Job or decision reference] |
#### Authority record
| Field | Entry |
|---|---|
| Authority record ID | [Identifier] |
| Site ID | [Controlled site identifier] |
| Authorized person | [Name and role] |
| Permitted action | [Request, approve, receive or return] |
| Effective from | [Date] |
| Effective to | [Date or current] |
| Approval reference | [Customer record] |
#### Custody event record
| Field | Entry |
|---|---|
| Custody event ID | [Identifier] |
| Key ID or set ID | [Identifier] |
| Event type | [Issue, transfer or return] |
| Holder name or location | [Person or controlled location] |
| Approved by | [Authorized person] |
| Issued or received by | [Technician or staff member] |
| Event date | [Date] |
| Expected return date | [Date or not required] |
| Acknowledgement | [Method and reference] |
| Related work order | [Work order number] |
#### Audit exception record
| Field | Entry |
|---|---|
| Exception ID | [Identifier] |
| Site ID | [Controlled site identifier] |
| Key ID or set ID | [Identifier] |
| Exception type | [Overdue, missing, damaged, duplicate ID or record conflict] |
| Opened date | [Date] |
| Follow-up owner | [Name or role] |
| Next action date | [Date] |
| Authorized decision | [Recover, monitor, rekey, replace or correct record] |
| Closure reference | [Custody event, work order or approval] |
| Closed date | [Date or open] |
Process returns, missing keys and staff changes
Do not close custody from an email that says a key was returned. Match the physical key to its identifier first. Inspect it. Then record the return date and receiving person.
If the key is damaged, record the condition before moving it out of issued status. If the wrong key comes back, leave the expected key open and investigate the mismatch.
When a return date passes, keep the key status as issued and open an overdue exception. Assign the follow-up to a named person, record each contact attempt and leave the exception open until the key is physically returned or confirmed missing.
Escalate the overdue key to the authorized site contact when the holder does not produce it through the agreed follow-up process. Record the contact’s decision and the person responsible for the next action.
Reconcile departing workers against the issue record
A departing employee returns one key. The key issue record shows two were issued. Do not mark the account complete.
Record the returned key. Keep the second key issued with an overdue exception unless the loss is confirmed. If it is confirmed lost, change its status to missing and keep the exception open for an authorized decision.
The decision may be to recover the key, monitor the exception, change authority, rekey affected cylinders or replace hardware. Record the customer’s approved action. Do not make a security decision by silently changing a status field.
Keep emergency entry checks separate
Lockout customer verification answers whether the person requesting emergency access has a valid connection to the property. It does not give that person authority to order, duplicate or keep a commercial key.
Use the Canadian locksmith ID and emergency-entry checks for the lockout decision. Then use the customer’s authority record for any key that may be cut or issued afterward.
Escalate a lost key as an access problem
Record when the loss was reported, which key is missing, its access group and its last known holder. Notify the authorized site contact through the agreed channel.
Do not mark the key returned. Do not delete it. Keep the exception open until the customer records a decision and the required work is complete.
If the decision is a rekey, list every affected opening, cylinder and active key before pricing. The locksmith rekey quote guide shows how to count the physical scope instead of quoting from a vague request.
Reconcile the commercial key register after locksmith work
A rekey changes which keys operate the affected cylinders. Update the cylinders, active keys and retired keys together. If you update only the door schedule, the custody record still tells staff that dead keys are active.
Tie each register change to the work order. Record the affected opening references, new key identifiers, retired identifiers and authorization used. Set old keys to retired only when the work justifies that status.
Separate remedial work from register correction
Correcting a holder name or closing a matched return is register work. Rekeying cylinders, replacing hardware or cutting controlled keys is remedial locksmith work.
Scope that work before pricing it. List the affected openings, cylinders and keys. Add the labour for site work, bench work and closeout. Add materials at cost, then apply your markup to build the quoted price.
State which closeout records the customer receives. These may include the corrected commercial key register, changed opening references, retired key IDs and new custody records.
Keep the register correction and remedial work attached to the correct job for cost tracking. That lets you see which visit handled the audit, key cutting, cylinder work or record correction without treating the register itself as an invoice.
Audit the locksmith key control register against the site
An audit compares the record with the physical keys, current holders, controlled storage and current authority. Reading the spreadsheet without counting anything is not an audit.
Choose a cut-off time. Pause non-urgent issues and returns while the count is underway, or record each movement separately so the audit does not chase a changing total.
Count by holder and controlled location
Require each named holder to present every assigned key for physical inspection. Match each physical identifier to the key asset and open custody event at the audit cut-off.
Count keys in cabinets, lockboxes, security desks and department stores. Record any assigned key that is not physically presented as an unresolved audit exception, even if the holder says they still have it.
Match every physical identifier to the commercial key register. Record keys found without an entry and entries with no key. Do not create a guessed match because two descriptions sound similar.
Check these exceptions:
- Duplicate key IDs
- Blank holder fields
- Issued keys with no issue date
- Returned keys still shown as issued
- Missing keys shown as closed
- Retired keys stored with active keys
- Lockbox contents that have not been counted
- Authority names that no longer match current staff
Assign each exception to a person and a next action. A long exception list with no owner is just another stale record.
Approve the corrected record
Send the corrected register to the customer’s authorized contact. Ask them to approve the current authority list, unresolved exceptions and any proposed security work.
Record the approval reference and audit date. Set the next audit point based on the customer’s operating needs, staff changes and access risk. Do not invent one schedule for every commercial site.
Turn unresolved access risk into a scoped job
Do not quote “fix key system.” Inspect and list the affected work first.
Record the openings, cylinders, key groups, controlled keys and authority records that need to change. Separate labour, materials and controlled-key work. State which records you will return at closeout.
If the audit uncovers a wider hierarchy problem, use the master-key quote guide to map the doors and access groups before pricing the change.
When approved remedial work sits outside the existing service scope, issue a new quote or get an approved change order before work starts. Use the corrected locksmith key control register to define the affected keys and closeout records in that document.
Locksmith licensing does not sit under one regulator model across Canada. Check the official locksmith, security-services or other statutory regulator for the province or territory where the work will happen. For example, contractors working in Alberta can check the Government of Alberta security service worker licence page (opens in a new tab); contractors elsewhere should use their own provincial or territorial government’s official licensing pages.