When a contractor finishes work at a commercial property, close their access as part of the job handover: confirm the authorised work has ended, disable temporary passes or app permissions, recover issued keys and badges, and record who checked each step. Review shared entry methods if they were disclosed during the work. The details depend on the site; a working door system alone does not tell you whether old permissions remain active.
For a facilities team managing an office, warehouse or mixed-use building in Watford, this is a useful routine whenever a cleaning, maintenance or fit-out contract ends. It also applies when a worker changes employer or a subcontractor leaves before the main project finishes.
1. Know which access was issued
Keep a simple register of the access given for the job: named passes, physical keys, visitor badges, app accounts, vehicle entry permissions and any approved out-of-hours access. Identify the person who authorised each one and the person responsible for closing it. Avoid giving a whole contractor team one shared identity where individual permissions are practical.
The National Protective Security Authority explains that automatic access control systems manage who can go where and when. That makes the permission list and its owner just as important as the reader at the door.
2. Set an end point before work starts
Agree the work area and the period of access with the contractor and site manager. Where the system allows it, give temporary permissions an end date and review extensions rather than leaving them open indefinitely. If work changes, update the authorisation rather than relying on an informal message to reception or a guard.
Check that the access plan fits operational needs, including deliveries, maintenance and safe exit in an emergency. A restriction that interferes with an escape route or essential service needs site-specific review by the responsible people.
3. Close the job with a recorded handover
At completion, compare the access register with what was actually returned or disabled. Confirm that passes and accounts were deactivated, keys and badges were reconciled, and any outstanding access is assigned to a named person for follow-up. If a shared code was given out, assess whether it should be changed and communicate the change only to people who still need it. Test that authorised users can still enter after the update.
When the contractor has worked across several areas or buildings, do not assume that closing one door group removes every permission. Check the agreed scope in the system and any separate arrangements for keys, gates or shared spaces.
4. Review records and privacy
Access records can identify people and their movements. Limit who can view or export them, explain their use to workers and contractors as appropriate, and set a retention period based on a documented purpose. Do not keep logs indefinitely just because the system permits it.
The Information Commissioner’s Office advises organisations to review access rights regularly and adjust or remove them when people change roles or leave. Its storage limitation guidance also calls for documented retention periods. Your data protection lead should apply those principles to the records and systems at your own site.
Questions for the facilities handover
- Who approved each temporary permission, and who can revoke it?
- Which keys, badges and digital accounts are still outstanding?
- Have all relevant doors, gates and shared areas been checked?
- Who records completion and handles an exception?
- When will the next access-rights review take place?
If you are reviewing controlled entry as part of a broader site security plan, see ZimCos Security’s security services. For a discussion about your premises and the work required, contact the team with the site type and location. The right approach should be agreed against your actual access arrangements and risks.