Badge & door access control for small offices: who can walk in
Every small office has a door story. The server closet that opens with a code four ex-employees still know. The front door that stays propped open in summer because the closer sticks. The badge drawer with "spares" nobody has counted since the office moved. Door access is the layer of security that predates the internet, and it still decides who can walk up to the machines you spent the rest of this site hardening. None of it is expensive. It is mostly decisions made on the day someone joins, and a fifteen-minute walk once a quarter. This checklist is the pass that keeps the doors honest.
1. Count the doors that matter before you count the badges
- Make the short list of doors that guard real loss. The server or comms closet, the finance cabinet, the room where backups live, and the front door itself — that is usually the whole kingdom for a small office. The broader perimeter work (cameras, alarms, the unattended desk) already lives in the physical security checklist; this page is the layer under it: what opens those doors.
- Write down how each door on the list is opened today. Badge reader, keypad code, physical key, or "it has been unlocked since 2019" — one line per door, plus who currently knows the code or holds the key. The honest list is usually shorter than feared but weirder: the fire escape that never latches and the cleaning crew with a master key both belong on it.
- Assign every door one named owner. Not a department — a person. When the keypad battery dies or a badge goes missing, the door owner is who gets the call. A door owned by everyone is a door owned by no one, and that is exactly how a shared code outlives four employees.
2. Issue badges like you issue accounts
- Every badge has a named holder, a purpose, and a revocable owner. The same rule that governs SSO accounts applies to plastic: nobody gets "a badge for the office" — they get badge #14 issued to Dana, for the front door and the server closet, logged where the access request and offboarding checklist already records their accounts. If the badge log cannot answer "whose is this?" in one minute, it is a drawer, not a log.
- Provision door access on the same ticket as everything else. When someone joins, the onboarding ticket that creates their email and repository access adds their badge in the same pass — one place to look when you audit. The onboarding checklist template is where the line belongs; add "badge issued, which doors" as a checkbox, not a hallway conversation.
- Default to least doors. Marketing does not need the server closet; the bookkeeper does not need the roof. Grant the front door by default and everything else by request. Every extra door is an attack surface you have to remember to close at 5pm on someone's last day — and last days are exactly when nobody remembers.
3. Revocation happens the same day, and door codes are not grandfathered
- Offboarding includes the badge and every door code the person knew. Deactivate the badge the same hour the email account dies — the offboarding checklist should treat "badge returned & deactivated" as a gate, not a footnote. A badge that still opens the server closet after HR says someone left is the physical version of an orphaned admin account.
- Rotate the keypad code when anyone who knew it leaves. Codes are the one credential every small office shares badly. The rule is simple: if a leaver knew the code, the code changes that week. It takes five minutes and a message to everyone with a reason attached — "rotating after departures, new code is in the usual place."
- Collect keys like credentials, or accept they are credentials. A physical key on a lanyard is an access token that never expires. Offboarding collects laptop, badge, and keys in the same bag; if the key is "lost," the lock or cylinder changes on the doors it opened. For the doors that matter most, this is the same reflex as the secrets rotation checklist — a credential that left your control gets rotated, no debate.
4. Shared codes and spare keys: name them or retire them
- No anonymous codes. If the server room code is "1111 because everyone needs in," it is not access control, it is a welcome mat with a rhythm. Either assign per-person codes (most keypads support this) so the log names who entered, or accept one shared code — written down in the password manager, rotated on departures, and never spoken across the room at a demo.
- The spare-key drawer gets an inventory or an eviction notice. Count the spares. Each one gets a label, a holder, and a row in the same log as badges. Spares nobody can account for are why "we changed the locks" eventually happens anyway — on the day something walks out the door. Two hours of labeling beats one lock replacement and one incident report.
- Master keys are named, few, and stored like production secrets. The cleaner's master key and the director's master key are both real production access. Record who holds them, review the list quarterly, and never let "the landlord has one too" stay vague — write it down with a date, and put the master on the same audit rhythm as the rest of the office physical layer.
5. Visitors, contractors, and the escort rule
- Contractor badges expire by default. The installer who needs the comms closet for two days gets a badge that dies on day three — physically or in the reader. Permanent access for temporary people is how a six-week project leaves a working badge behind forever. The contractor onboarding checklist should carry the same expiry line as it does for accounts.
- Visitors log in, wear the badge, and get escorted past the short list. The ten-line visitor book from the physical checklist is the floor; the escort rule is the ceiling: beyond the reception line, visitors walk with a host. The rule is one sentence in the onboarding pack and one sign at the door — it does not need a policy document to work, it needs to be said out loud once.
- Temps, cleaners, and building staff get the same revocation day as everyone else. The people with after-hours access to every room are the easiest to forget because they were never in HR. Keep a one-page list of non-employee access with the date it was granted and the date it should end — then actually end it.
6. The badge log is an audit trail, not a receipt printer
- Export the badge report quarterly and reconcile it against people. Badge system, meet the HR list: every active badge matches a current person; every current person's badge matches their granted doors. The mismatches are the whole point of the exercise — badges for people who left in spring, doors granted "temporarily" during the fit-out two years ago. Twenty minutes, once a quarter.
- Read the after-hours entries before an incident reads them for you. The badge log is the quietest detective on staff: 2am entries to the finance room, a badge used in the office the same week it was "returned." When something is wrong, this log is what the incident response plan will ask for — pull it habitually and it stays meaningful; ignore it and it decays into a CSV nobody can interpret.
- Keep one paper fallback that is itself controlled. If the reader dies, the fallback cannot be "the door stays open." A physical log sheet and a known-good override key, both inventoried, both owned — the failure mode is planned the same way you plan the backup restore test: rehearse the broken state once so it is boring on the day.
7. The fifteen-minute quarterly door walk
- Walk every door on the short list with the checklist in hand. Does it close and latch? Is the propped-open wedge gone? Does the badge reader show the right door name? Does the server closet code open it — and did it change when it should have? Fifteen minutes, four times a year, catches what memos never do.
- Test revocation, not just issuance. Grab the most recently deactivated badge from the offboarding bag and try it on every door it used to open. If it beeps green anywhere, you have found this quarter's finding, and it costs one screwdriver to fix. Revocation you have not tested is a rumor.
- Write the walk into the same quarterly folder as the rest. The door walk slots next to the WiFi walk test and the DNS filter re-check, so the whole "things that silently rot" layer gets reviewed in one sitting — and the finding (even "all clear") goes in the folder with a date and a name.
Door access for a small office is one short list and one habit: count the doors that guard real loss, issue badges like accounts with named holders and least doors, revoke badges and rotate codes the same day people leave, name or retire the shared codes and spare keys, expire contractor badges and escort visitors past reception, reconcile the badge log against the people list each quarter, and walk the doors for fifteen minutes with the deactivation badge in your pocket. The Ops Starter Kit ($14) puts the issue/revoke passes on fill-in-the-blank sheets, and the Automation Starter Pack ($19) schedules the quarterly walk and the badge-log reconciliation so both happen without anyone having to remember.