The short answer
Manage vendor access by linking each credential to a verified vendor, property or area, purpose, permitted window, issuer, custodian, return or revocation event, and verification. Prefer the least access needed, keep secrets out of broadly visible notes, and do not close the credential merely because the work order closed.
Key takeaways
- Treat the credential and the work order as linked but separate records.
- Limit location, capability, and time window.
- Verify return, revocation, or rotation rather than relying on a vendor promise.
Inventory the credential without exposing the secret
Use a credential ID or masked reference in the operational record. Record its type, controlled area, capability, vendor and named custodian, issuing authority, purpose, issue time, expiry, return method, and restricted location of any secret or key detail.
NIST account-management and least-privilege concepts support limiting and removing access. They are used here as process analogies; building access, tenancy, labor, and safety requirements need the responsible local policy and qualified advice.
Use a lifecycle that cannot skip retirement
The same work order can involve several credentials, and one credential can outlive a scheduled visit. Track status by credential identity rather than a single “access provided” field.
| State | Required evidence | Next control |
|---|---|---|
| Requested | Work identity, access need, authority | Approve minimum scope |
| Issued | Credential ID, custodian, window | Monitor expiry/return |
| Active exception | Changed visit or lost/unreturned report | Restrict, rotate, or escalate |
| Returned | Physical custody verified | Check copies or related codes |
| Revoked/rotated | System confirmation or code-change evidence | Test retired access where appropriate |
| Closed | All related credentials accounted for | Retain history without active secret |
Handle lost, shared, and stale access as exceptions
If a key is lost or a code was shared beyond the named custodian, record the known exposure window and notify the designated security or property owner. Do not bury the event in a work-order comment or publish codes in an incident packet.
A vendor’s offboarding, insurance lapse, job cancellation, staff change, or changed service area should trigger a credential search. Verify the resulting return, revocation, or rotation separately from changing vendor status.
Treat a vendor staffing change as a cross-credential event
Map departed, reassigned, and incoming vendor staff to physical keys, unique and shared codes, portal accounts, shared folders, open visits, and resident-contact assignments. Verify the roster change through an independently maintained vendor contact.
Retire old access and test replacement scope independently. Changing the work-order assignee does not revoke the former technician’s other access paths.
Operational checklist
Mark your progress, then save a working copy. Selections reset when you leave this page. A checked box is not an approval or evidence of completion.
☐
Vendor and custodian identity confirmed
☐
Purpose and minimum access scope approved
☐
Credential ID recorded without exposed secret
☐
Issue and expiry times retained
☐
Lost/shared/stale exceptions routed
☐
Return, revocation, or rotation verified
☐
Vendor offboarding searched for remaining access
0 of 7 marked
Edge cases
- A master key cannot be technically restricted: shorten the custody window and strengthen issuance/return controls.
- A code is reused across properties: treat rotation scope as broader than the one job.
- A subcontractor receives access from the primary vendor: the unrecorded custodian is an exception, not an automatic transfer.
Sources and references
Follow each source to check the underlying claim. Access checks and professional review are different steps.
1. Primary source · National Institute of Standards and Technology
SP 800-53 Rev. 5, Security and Privacy ControlsAccount management and least-privilege concepts support timely access review and removal. The federal control catalog is used as a process analogy, not a landlord mandate.
Source checked 2026-09-18
Automated source-access check: 2026-09-18.
Continue the workflow
A vendor lifecycle control recordVendor staff-change access reconciliationAfter-hours maintenance closeoutRevision history
2026-09-18
Initial Phase 3 operational article with a distinct decision artifact, failure states, source-scope notes, and AI-assisted technical review.