PIPropertyITBUILDING TECHNOLOGY
Field guide / Access

Access Control Credential Hygiene: Fobs, Codes and Leaver Processes for Buildings

How to keep door credentials accurate across tenants, staff and contractors, and how to audit an access-control system before it becomes a liability.

  • By Ali Sedighi, MBA
  • Reviewed 2026-10-06
  • 5 min read

A door access system is only as good as its credential list. The hardware can be new and the software current, yet if the list contains the cleaner who left in March, the contractor from last year's renovation and every tenant who has ever lived in suite 804, the system is granting access to people who should not have it. Credential hygiene is the unglamorous process of keeping that list true, and it is the single most valuable security task in most buildings.

Where credentials go stale

Credentials accumulate because adding is easy and removing is nobody's job. A tenant moves out and the move-out checklist covers keys but not the fob database. A contractor is issued a card for a three-week project and still has it two years later. A staff member leaves, and their master credential keeps opening the mechanical room.

The pattern is common enough that an audit of almost any building finds credentials that should be inactive. The question is how many, and which doors they open.

Joiner, mover, leaver, applied to a building

Borrow a process from corporate IT. A joiner event is a new lease, a new employee or a new contractor: credentials are issued with the right door groups and an expiry. A mover event is a unit change or a role change: groups are updated. A leaver event is a lease end, a termination or the close of a project: credentials are disabled the same day.

Tie these events to the systems that already know about them. The property software knows when a lease ends. HR knows when an employee leaves. The project manager knows when a contractor's scope finishes. A simple report or integration from those systems to the access platform removes most of the manual effort.

Door groups and least privilege

Most buildings use too few access groups, so people receive more access than they need. A resident should open the lobby, their parkade level, the amenity rooms they have booked and nothing else. A cleaner should have scheduled access to specific floors. A fire-alarm technician needs mechanical and electrical rooms during maintenance windows.

Time-based rules limit exposure. A contractor group that works only on weekdays during daylight hours is far safer than one that opens doors at any time. Review the group definitions annually and after any change in building operations.

Master credentials and the people who hold them

Master credentials open everything, so they deserve special treatment. Keep a written register of every master credential, who holds it and why. Prefer mobile credentials or cards that can be revoked individually over mechanical keys that cannot. Require two-person approval to create a new master credential and review the register every quarter.

If a master credential is lost, treat it as an incident: disable it, review the logs for its recent use and issue a replacement with a new identifier.

Reading the logs

Access systems record door events, but most buildings never read them. A monthly report should highlight doors held open, repeated failed attempts, after-hours entry to sensitive rooms, credentials used at unusual locations and any credential that has not been used for ninety days.

The goal is not surveillance of residents. It is a short list of exceptions that someone can check in thirty minutes, so you notice a problem before an insurer or a lawyer does.

Hardening the controllers and software

Door controllers, readers and servers should be on a dedicated segment, with unique administrative credentials and current firmware. Old controllers running unsupported software are a frequent finding. Cloud-managed platforms help by patching automatically, but they still need strong administrator authentication and limited admin accounts.

Back up the credential database and configuration. A corrupted server with no backup can force every card in the building to be reissued.

An audit you can run this quarter

Export the full credential list. Match it to the current tenant roll, staff list and contractor schedule. Disable anything that cannot be matched. Review group membership, check for credentials never used and count master credentials. Record the results, the actions taken and the date.

Repeat quarterly. The first audit is usually uncomfortable; by the third, the exceptions are few and the whole exercise takes an hour.

Checklist

  • Export the full credential list from every access system
  • Match credentials to the current tenant roll, staff list and contractor schedule
  • Disable unmatched credentials and record the action
  • Tie lease-end and termination events to a same-day deactivation
  • Give contractor credentials a fixed expiry
  • Keep a written register of master credentials and review it quarterly
  • Update controller and reader firmware on a schedule
  • Back up the credential database and test the restore

Where this lands by property type

Building Owners

Small-portfolio owners run lean. A single failed controller, a camera system nobody understands or a lapsed carrier contract can occupy an owner for days. Typical exposure: no one responsible for building technology.

Strata & Condo Managers

Strata managers serve volunteer councils, answer to owners and keep records the law expects them to keep. The work is document-heavy, deadline-driven and full of personal information. Typical exposure: council records spread across personal email accounts.

Student Housing

Student buildings fill up in a single week each September and pull heavy streaming and gaming loads every evening. Networks need capacity and fast support. Typical exposure: peak-hour congestion at move-in and exam periods.

Next step: a building technology survey

PropertyIT is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery for property teams. If this article describes a situation in your buildings, book a free 30-minute consultation: call (604) 632-4959 or email [email protected]. We will give you a plain-language view of your options, and a fixed-price scope if you want one. No lock-in, no pressure and no obligation.

Frequently asked questions

How often should we audit access credentials?

Quarterly is a good rhythm for most buildings. High-turnover properties such as student housing may need monthly checks.

Are mobile credentials safer than fobs?

They are easier to revoke and harder to copy, though they depend on resident phones and on a well-run cloud platform. Many buildings run both during a transition.

Who is responsible for deactivating a fob when a tenant leaves?

The property manager, as part of the move-out process. The most reliable method is to trigger deactivation automatically from the lease-end date.

Can PropertyIT audit a system installed by another vendor?

Yes. We can review the controllers, credential lists and logs with the installer's cooperation and give you a ranked list of findings.

Call (604) 632-4959Email [email protected]Book a consultation