A key is handed out in seconds — and is remarkably hard to track down again. Anyone working in an organisation with 50, 500 or 5,000 keys knows the situation: a contractor is waiting at the door, a response vehicle needs to leave, an employee has resigned. And the decisive question is the same every time: who has the key — and since when?
This guide sums up what has proven itself in practice. It draws on the working routines of around 70 organisations that manage their keys with Log+Key — from assisted-living alarm services with thousands of client keys to property managers looking after 100 buildings. The best practices apply whether you work with paper, Excel or dedicated key management software. To be honest: beyond a certain size the first two stop working particularly well — more on that below.
What good key management has to deliver
Before the how, briefly the what. Key management worthy of the name answers four questions reliably:
- Where is the key right now? In storage, with a member of staff, with a service provider — answerable at any time, without a round of phone calls.
- Who had it, and when? A complete history of every checkout and return that cannot be altered after the fact.
- Can you prove it? Audits, funding bodies, insurers or a dispute all require documentation with a timestamp, a name and ideally a signature or receipt.
- Will anyone actually follow it? The most important and most underestimated point. A process that is too cumbersome for everyday use gets bypassed — and documentation full of gaps is barely better than none at all.
The lifecycle of a key
Every key in your organisation passes through the same stages. If you have a defined routine for each one, you have the topic under control.
Registration
As soon as a key becomes your responsibility, it gets recorded — created individually or imported from your existing list: label, storage location, the property it belongs to and ideally a photo. It pays to document the moment you take receipt of it, so the history starts on arrival rather than at the first checkout.
Checkout and return
The daily business — and the point at which paper lists fail. Every checkout and every return needs documenting: who, what, when. In practice that means the process has to be done in seconds, otherwise it happens "later" — which is to say never. With NFC tags on the keyring, issuing a key is a scan on a smartphone or terminal, and the history is created automatically.
Swaps and changes
A single key on a ring is swapped, a cylinder is replaced, a bunch is put together differently. Changes like these belong in the same history as checkouts — otherwise you are documenting yesterday's situation.
Stocktaking
Check regularly whether the documented inventory matches reality. It sounds obvious, but without system support it is almost always postponed, because with paper lists it takes days. More on this in best practice 5.
Archiving
Property given up, contract ended, key returned? The key leaves the active inventory but its history remains. In an audit it matters that closed cases are still verifiable too.
Seven best practices from the field
1. One single source of truth
The most common pattern in organisations with key chaos: there are three versions of the truth. A key book at reception, an Excel list in administration, and the memory of the longest-serving colleague. All three contradict each other. Decide that exactly one system counts — and that any movement not documented there is treated as not having happened.
2. Every movement has a name attached
"Key 14 is missing" is not information you can work with. "Key 14, taken by Mr K. on 5 August at 14:12" is. Accountability comes from assigning every checkout to a person — not to find someone to blame, but so the follow-up question is answered in seconds. For handovers to external parties (contractors, service providers, tenants), a signature plus an automatic PDF receipt has proven its worth: both sides hold the same record.
3. The process has to be quicker than the shortcut
The uncomfortable truth about all key management: staff bypass processes that slow them down. If logging the key takes longer than taking it, taking it wins — on the night shift at the latest. That is why the key metric is not how completely the form is filled in, but how long the process takes. One scan, done. Anything beyond that needs a good reason.
4. Not everyone needs to see everything
Who may issue keys? Who may change master data? Who can see the history? In small teams this sorts itself out; from around ten members of staff it no longer does. A roles-and-permissions concept — even if it starts life on a single sheet of paper — prevents both a free-for-all and its opposite: only one person being able to answer questions, so everything stops when they are on holiday.
5. Schedule the stocktake, don't just intend it
"We really should count everything again some time" is the beginning of the end. Set a fixed rhythm — quarterly or half-yearly depending on your inventory — and make the stocktake as easy as possible. With NFC tags, a stocktake means walking through, scanning, noting discrepancies. What used to cost a weekend is done in a morning — and differences surface while they can still be explained.
6. Make overdue returns visible
Most keys are not lost dramatically. They simply stay with someone — in a jacket pocket, in a glovebox, at the end of a shift. Define return times and make sure overdue items surface automatically rather than by chance. Someone reminded after two days returns the key. Someone asked after two months goes looking for it.
7. Settle the loss procedure before the loss
What happens when a key goes missing? Who is informed, when is the cylinder replaced, who bears the cost, what gets documented? These questions are better decided calmly than in an emergency. A clean history helps twice over: it narrows down where the key was last — and it demonstrates to an insurer or client that your processes were sound.
Paper, Excel or software?
The honest answer: it depends on size.
The key book works as long as a handful of keys pass across a single counter. It fails at everything after that: searching means leafing through pages, reporting means retyping, and if the book is full, wet or gone, so is your documentation.
The Excel spreadsheet is the key book with a search function. It fails a little later — typically in three places: several people maintain it in parallel (or fail to), it proves nothing (every cell can be altered afterwards, which is a real problem in an audit), and it notices nothing by itself — no overdue return, no gap. We have written up the limits in detail: Log+Key vs. the Excel key book.
The key safe solves a different problem: it secures keys mechanically instead of documenting their movements. For high-security applications it is the right tool — for the documentation problem it is an expensive answer to the wrong question. The two approaches can coexist; you will find the multi-year cost comparison under Log+Key vs. key safe.
A digital key management system addresses the four requirements from the start: every movement is documented as it is scanned, the history cannot be altered, reports are available at the push of a button — and the process itself takes seconds, so it actually gets done.
Starting is smaller than you think
Best practices sound like a project. In practice, getting started takes three things: record your inventory once, properly; define the checkout and return routine; clarify responsibilities. For the initial capture you do not have to create every key by hand — properties can be imported. Organisations moving to Log+Key are typically up and running within days, and we are happy to handle the initial import for you.
If you would like to tackle the subject: Log+Key is free for up to 10 keys — enough to test the process with your team in everyday use before you migrate your whole inventory.