A facilities manager asks for another restricted key, but their name is not on the authority record. Stop the job. A locksmith key control register must prove who approved the request before a key is cut or released.
The record must also show where that key went. A current-holder column is not enough. You need the authority trail, every custody event, and any missing or overdue key still waiting for action.
Decide what the register must answer
Build the register around questions your office and technicians face during real commercial work:
- Which site and key system does this key belong to?
- What is the controlled identifier on the physical key?
- Which access reference applies?
- Who may request or approve another key?
- Who received this key, and who released it?
- Is the key due back?
- Has it been transferred, returned, damaged, lost, or retired?
- Which work order supports the action?
Those questions cover four different things: the key asset, customer authority, custody, and exceptions. Keep them linked, but do not squash them into one editable row.
Pick one register as the current record. A controlled spreadsheet, paper register, or job record can work. Private technician lists cannot. Two live copies will eventually give two different answers.
For ongoing commercial accounts, define approval roles and work-order controls during setup. The property-management locksmith contract guide explains how to assign customer contacts before service calls start.
Set the site and naming rules first
Start with the property. People change jobs. Contractors leave. Departments move. The site remains the anchor for the key records.
Give each property a stable site ID. Put that ID on the work order, key records, service notes, and approved door schedule. For a customer with several properties, create a separate site record for every address.
Add the state and city to the site record. Do not assume one credential check covers an entire property portfolio. A customer account may cross several licensing jurisdictions.
Assign stable identifiers
Use separate identifiers for:
- Customer account
- Site
- Key system or series
- Opening or approved access group
- Individual key
- Controlled key set
- Authority record
- Custody event
- Exception
Do not reuse a retired key ID for a new key. Old keys turn up in desk drawers and former employees’ tool bags. A reused identifier makes the old key look current.
Write down the naming method. The stamp on the key, the key ID in the register, and the key ID on the work order must match. If they do not match, stop the handoff and resolve the conflict.
Keep opening details inside the protected record
A physical identifier should let authorized staff match a key to its record without advertising what the key opens.
Do not put the street address, tenant name, room name, or plain-language opening description on the visible tag. Use the controlled key ID. Keep the usable access description inside the protected commercial key register or approved door schedule.
Track an individual key when individual custody matters. Track a sealed emergency set as one unit only when the customer controls and audits it as one unit. If keys from the set can be handed to different people, give each key its own asset record.
Build the locksmith key control register around four records
One row with a field called “holder” will tell you where the key might be now. It will not tell you who held it last month, who approved the transfer, or why it is overdue.
Build the locksmith key control register from four linked records instead.
Key asset record
The asset record identifies the physical key or controlled set. Record the site ID, key ID, system reference, approved access reference, key type, custody state, lifecycle state, and condition.
Keep those fields separate. Use custody states such as under site control, issued, and unresolved. Record lifecycle as active or retired, and condition as serviceable, damaged, or unknown. A missing key can have unresolved custody while its lifecycle remains active. Keep retired and missing assets in the history. Do not delete them to tidy the screen.
Authority record
The authority record says who may perform a particular action. Record the person, role, site, permitted action, effective dates, and customer approval reference.
Restricted key authority is not the same as possession. A maintenance employee may hold a key without having permission to order another. A property manager may approve the order without receiving the key.
When an authorized contact changes, close the old authority period and add a new record. Do not overwrite the old name. You may need to establish who approved an earlier issue.
Custody event
A custody event is an immutable point-in-time record of movement. Create one for every issue, transfer, and return.
Record the key ID, previous holder, new holder, event date and time, preceding custody event, approver, staff member completing the handoff, acknowledgment reference, return date when needed, and related work order.
Derive the current holder from the latest valid custody event. A transfer adds a new point-in-time event under the same key asset. It does not change or close the earlier event.
Exception record
Open an exception for an overdue return, missing key, damaged key, duplicate ID, blank holder, or conflict between the physical key and the register.
Record who owns the follow-up, what happens next, and when the issue is due for review. Close the exception only with a linked custody event, work order, corrected record, or authorized customer decision.
Confirm authority before cutting the key
Match the request to the current authority record before work starts. Check the site, key system, access reference, quantity, requester, approver, and intended recipient.
For a restricted system, also match the request against the recorded authorization method and the key or access scope that person may approve. A recognized contact can still be outside their permitted scope.
Do not treat a familiar email address, job title, purchase order, or earlier approval as permanent authority. Use the current record agreed with the customer.
If the facilities manager requesting another restricted key is not listed as an approver, stop. Contact the authorized customer representative. Record the stopped request and the answer. Do not cut the key and repair the paperwork later.
The same rule applies when the requested quantity or access group falls outside the approval. A valid approver for one building may have no authority for another site owned by the same customer.
An approved access reference should carry into the quote or work order without exposing sensitive opening details. For larger systems, the master-key quoting guide shows how to connect the approved scope to the openings being serviced.
Run a bench check before release
Put the physical key, work order, and register together. Match the stamp or tag to the key ID. Match the key ID to the approved system and access reference.
If the technician finds that the physical stamp does not match the work order, stop the release. Open an exception. Find whether the error sits on the key, work order, or register before the customer takes custody.
Record the stopped release even if staff resolve it on the same day. The exception shows that the mismatch was caught and corrected rather than ignored.
Complete the key issue record at the handoff
Finish the custody event while the key and recipient are in front of you. Do not leave the office to reconstruct the handoff from memory.
Confirm the recipient using the method agreed with the customer. Record the person or controlled location receiving the key, the staff member releasing it, the date, the approval reference, and the work order.
The holder can be a person, security desk, lockbox, department, or controlled key cabinet. Do not leave the holder blank because the key went into a cabinet. Name the cabinet and record who controls it.
For temporary employee or contractor keys, add an expected return date and the customer contact responsible for recovery. The key stays issued after that date passes. Open an overdue exception rather than marking it returned.
The customer may require a signature, initials, badge check, digital acknowledgment, or another handoff method. Record the method used. Do not assume one acknowledgment method applies to every customer or jurisdiction.
Copy-ready register fields
Keep these as four linked record groups. Join them with the site ID, key ID, work order, and related references.
#### Key asset
| Field | Entry |
|---|---|
| Customer | [Customer name] |
| Site ID | [Controlled site ID] |
| State and city | [Jurisdiction] |
| Key ID or set ID | [Physical identifier] |
| Key system | [Controlled system reference] |
| Access reference | [Protected opening or group reference] |
| Key type | [Standard, controlled, or restricted] |
| Custody state | [Under site control, issued, or unresolved] |
| Lifecycle state | [Active or retired] |
| Condition | [Serviceable, damaged, or unknown] |
| Retirement reference | [Work order or decision reference] |
#### Authority
| Field | Entry |
|---|---|
| Authority record ID | [Identifier] |
| Site ID | [Controlled site ID] |
| Authorized person | [Name and role] |
| Permitted action | [Request, approve, receive, or return] |
| Permitted access reference | [Controlled reference] |
| Authorization method | [Customer-approved method] |
| Effective from | [Date] |
| Effective to | [Date or current] |
| Customer approval reference | [Record or document] |
#### Custody event
| Field | Entry |
|---|---|
| Custody event ID | [Identifier] |
| Key ID or set ID | [Identifier] |
| Event | [Issue, transfer, or return] |
| Previous custody event | [Event ID or first issue] |
| Previous holder | [Person or controlled location] |
| New holder | [Person or controlled location] |
| Approved by | [Authorized person] |
| Handled by | [Technician or office staff] |
| Event date and time | [Date and time] |
| Expected return date | [Date or not required] |
| Acknowledgment | [Method and reference] |
| Work order | [Work order number] |
#### Exception
| Field | Entry |
|---|---|
| Exception ID | [Identifier] |
| Site ID | [Controlled site ID] |
| Key ID or set ID | [Identifier] |
| Type | [Overdue, missing, damaged, duplicate ID, or record conflict] |
| Last known holder | [Person or controlled location] |
| Opened date | [Date] |
| Follow-up owner | [Name or role] |
| Next action | [Action and date] |
| Customer decision | [Approved response] |
| Closure reference | [Custody event, work order, or decision] |
| Closed date | [Date or open] |
Record returns and transfers without deleting history
Match the returned physical key to the register before adding the return event. Inspect the identifier and condition. Record who accepted it and when.
If the wrong key comes back, keep the expected key issued. Open an exception for the mismatch. Do not add a return event because the holder returned something that looked similar.
For a transfer, append a new event that names the previous holder and the next holder. Link it to the preceding custody event and record the approval behind the transfer. The history should show both handoffs without editing either event.
Keep damaged keys in the record. Note whether the physical key was surrendered, destroyed under the customer’s process, or left outstanding. Link a retired key to the work order or customer decision that retired it.
Act on overdue, missing, and unreturned keys
An overdue key is still issued. The missed return date is the exception, not a reason to change custody without the key.
Assign the follow-up to a named person. Record each contact attempt and the next review date. If the holder reports the key missing, preserve the last known holder and move custody to unresolved through the customer’s approved process.
A departing employee may return one key while the key issue record shows two open custody events. Add the return event for that key only. Keep the other issued until the authorized customer contact confirms it missing, then move its custody state to unresolved and keep the missing-key exception open.
A missing-key record should identify the affected access reference without putting sensitive details in general notes. Link the customer’s approved response, whether that is continued recovery, monitoring, a rekey, or hardware work. Do not make the security decision for the customer by silently editing a status.
When the approved response becomes billable work, attach the authority and exception references to the work order. Carry those references into the invoice-writing guide so the customer can connect the completed work to the approved action.
Audit from the physical key back to authority
Count the keys physically under site control, including controlled stock, cabinets, lockboxes, and security-desk holdings. Do not expect to count keys held by employees or outside contractors during the site check.
Reconcile issued keys through their latest custody events, recipient acknowledgments, open exceptions, and authorized missing-key decisions. Every issued or unresolved key needs a traceable record even when the physical key is away from the site.
Then test the record in both directions. Pick a physical key and trace it to the site, access reference, current custody event, authority record, and work order. Pick an open custody event and trace it back to a physical asset or documented missing-key decision.
Search for duplicate IDs, blank holders, expired authority, overdue dates, open exceptions, and assets with no custody history. When you correct an entry, append the original value, corrected value, reason, author, date, and linked exception. Do not overwrite the original entry.
Treat a key cabinet, lockbox, or security desk as a holder during the count. Record who controls that location. “On site” is not a usable custody answer.
Set the next audit point using the customer’s policy and the risk attached to the site. Do not invent one universal schedule. Record who will complete the check and which keys, sets, or locations it covers.
Add a U.S. credential checkpoint for every site
Customer authority answers whether a person may request a key. Licensing answers whether your business or technician may perform the contracted scope. Keep those records separate.
Use the USA.gov official directory of state governments (opens in a new tab) to find the state, county, or city authority that handles locksmith licensing questions for the job location. Ask that authority which license, if any, covers the proposed work.
If the job includes access-control wiring, use the same official directory to find the state or city electrical licensing office. Ask that office which trade license covers the wiring. Do not treat authority to cut a key as authority to perform electrical work.
Record each result in a separate compliance record linked by site ID. Include the jurisdiction, work scope, credential question, authority checked, check date, and recorded answer. Do not put licensing results inside the key register or assume one check covers every property.
Keep emergency-entry verification outside the locksmith key control register. A person may show a valid connection to a building without having restricted key authority. Use the lockout customer verification guide for the entry decision, then use the authority record for any key order or release.
Take one active commercial site today. Assign its site ID, separate authority from custody, and reconcile one physical key from the stamp through to the current holder before issuing anything else.