The key inventory register that knows where every key is — and what to do when one isn't
Most small offices can name who has a laptop but not who has a key. The keys came with the lease, they live in drawers and on lanyards and in a partner's other jacket, and the only time anyone counts them is the day one goes missing — which is exactly the day you need the list you never kept. A key inventory register is that list: one row per physical key, a named holder, an issue date, and a return date. It answers two questions on demand: who can open what right now? and when a key doesn't come back, what exactly is exposed? This page is the template and the operating rules: the columns that carry the weight, the numbered-copies and master-key rules, the offboarding ritual where keys actually come back, the rekey economics for when one doesn't, and the quarterly count that keeps the list from rotting into a spreadsheet nobody opens.
1. What the register is for — the two questions it must answer
- Question one: who can open what, right now? Not "roughly who has keys" — a row per physical key: which lock it opens, how many copies exist, who holds each. When the office manager is out and the server room door is locked, the register answers in seconds instead of a group-chat archaeology session. This is the same "produce it on demand" standard the visitor log meets for people and the badge checklist meets for cards — keys are the third list, and the one most likely to be missing.
- Question two: what is exposed when a key is lost? A key is never "lost" in the abstract; it opens named doors. The register turns "Sam lost his keys" into "Sam lost the front door, the supply closet, and cabinet 3 — and cabinet 3 holds check stock." That sentence decides whether you rekey a cylinder or replace a padlock, and it cannot be written on the day of the loss unless the list existed the day before.
- What it is not for: security through paperwork. A register that says "front door — everyone" is not a register; it is an admission you cannot answer either question. If keys are effectively universal, say so honestly (one row: "universal — all staff"), budget for a rekey after any loss, and let the register be the proof you knew the exposure. The lock-up strategy itself belongs to the physical security checklist; the register documents it.
2. The columns that carry the whole weight
- Key ID — a number, not a nickname. "Front door" is ambiguous the moment there are two doors; "K-014" is unambiguous forever. Tag or stamp the number on the key, one register row per copy. Un-numbered keys are the ones that end up in a bowl and are never traced again.
- What it opens — and what is behind it. "K-014 — front door (lobby)"; "K-007 — cabinet 3, server room (check stock)". The value note is what makes section 1's exposure test a lookup instead of a brainstorm, and it becomes the shopping list when a rekey is needed (section 5).
- Holder, role, dates. Full name plus role ("Sam Ortiz — ops"), date issued, and — the column that keeps the register honest — date returned. A returned key keeps its row with status "returned": the history of a copy is part of the record, the same way the visitor log keeps closed rows. No open-ended issues; every row is either active with a holder or closed with a date.
- Signature on issue and on return. Fifteen seconds each. It sounds excessive until the first "I gave that key back months ago" — the row settles it, memory does not. The visitor log's signature discipline, applied to your own team.
- A "master" flag. Any key that opens multiple doors gets flagged and held to stricter rules (section 3): fewer copies, a named custodian, first priority in any loss. The flag stops the consequential keys from being managed like the trivial ones.
3. Numbered copies and the master key rule
- Every copy is a numbered, assigned row. "We cut four copies" is a guess; "K-014 copies 1–4: Sam, Dana, front-desk lockbox, manager safe" is an inventory. New copy means a new row before it leaves the building; broken or retired copies close their rows with a reason. The test is one-to-one: no unassigned numbers, no unregistered metal.
- Masters: two copies, one custodian, one lockbox. One master with a named custodian; the second in a lockbox whose code two named people know — not three, not "whoever needs it." A master key in an unlocked desk drawer is every door in the building on one unlogged ring. If a master is lost, the register says instantly that the exposure is every door — which is what settles the rekey bill without a debate.
- Retire the spare that outlived its purpose. Offices accumulate spares for people who left years ago. The quarterly count (section 7) retires them: re-issue with a signature, return to the lockbox, or let a rekey make them irrelevant. A spare with no holder is a row with no name, and a row with no name gets decided at the count, not deferred another year.
4. Offboarding is where keys go to die — the return ritual
- Keys come back in the same pass as the laptop and the badge. Offboarding that collects the laptop and forgets the keys builds the exact gap the register exists to close. Put "keys returned — numbers verified" on the same line as device and badge collection: the access request & offboarding checklist is the pattern — one list, one owner, everything collected or disabled the same day. The register row gets its return date and signature at the same sitting.
- Contractors get keys like employees — with an end date. A two-week project key becomes a two-year key unless something expires it. Issue with an end date on the row, collect at the end date, review the open ones at the count. The contractor onboarding checklist is where the issue happens; the register is where "does he still have it?" becomes a lookup instead of a favor.
- Cleaning crews and vendors: log it or lock-code it. An outside crew holding a front-door key is an offboarding you never get to run. Prefer door codes or time-boxed access where the lock supports it; where a physical key is unavoidable, issue it like any numbered copy (holder = company, signed by their lead) and end it when the contract ends — the same reflex as the vendor offboarding rule: end of relationship means end of access. Fold the standing list into the annual security review.
5. When a key doesn't come back — the exposure test and the rekey economics
- Run the exposure test before spending money. Lost key + register = a five-minute scoping: which locks were on the ring, what of value sits behind them, who else still holds keys to those locks. House keys lost with nothing sensitive behind the doors may be a note and a watchful quarter; the same ring with a server room and a finance cabinet is a rekey this week. The register converts a panic purchase into a scoped decision.
- Rekey economics: cylinders, not locks. Most commercial door hardware takes a replaceable cylinder — a ten-minute swap and a few dollars per door, not new hardware. Padlocks and cabinet cam locks are usually cheaper to replace outright. The "what it opens" column is the exact work order: rekey the locks the lost key opened, nothing else.
- Three triggers where rekeying is not optional. A master key is lost (exposure is every door); the keys were lost with identifying information (an address on a lanyard or in a lost wallet turns a lock into a written map); or the loss involves a known threat — typically a termination where keys were never collected, which is an offboarding process failure to fix alongside the hardware. Treat the loss as a small incident with a timeline: what was exposed, what changed, who decided — the incident response plan's hour-one discipline, scaled to a door.
- Door codes rotate like keys — because they are keys. A code is a key without metal: it belongs in the register (holder = "known to N people", or a per-person code if the lock supports it) and it rotates on the same triggers — staff change, contractor exit, "we told too many people." If the lock supports per-person codes, that upgrade makes the register's job trivial: disable one code instead of rekeying a cylinder.
6. Where the register lives — and who guards the map
- Pick paper vs digital by where the incident happens. Same call as the visitor log: if the scenario is "power is out, plumber is at the door," the clipboard by reception wins; if the scenario is "audit next month," the spreadsheet with history and search wins. A hybrid works — paper for issue/return signatures at the desk, monthly reconciliation into the digital register — as long as one of them is the truth and the other is a copy.
- The register is itself sensitive — it is a map of every door and every gap. It does not live on the shared drive next to the lunch menu. Digital: a restricted folder, named access, no guest links. Paper: the same locked drawer as the master-key lockbox code — and its custodian is a named row on the register itself.
- One named owner. Not "the office manager" as a role on a good day — a name on the register who adds rows, chases unsigned returns, and runs the count. Every checklist in this series fails the same way: not complexity, just nobody responsible. The physical security checklist assigns the quarterly walk; this register gets the same sentence.
7. The quarterly count — fifteen minutes, next to the badge log
- Count metal against rows, both directions. Every registered key is physically accounted for (issued rows: holder confirms; returned rows: key in the lockbox) and every piece of metal on the ring has a row. The orphan in either direction is the finding: a key nobody can identify, or a row whose holder left in March. Same fifteen-minute habit as the badge reconciliation in the badge checklist and the visitor-log reconciliation — run all three in one sitting and none gets skipped.
- Every orphan gets an outcome at the count. Re-issued to a named holder with a signature, returned to the lockbox as a numbered spare, or the lock is rekeyed and the row closed. The register earns its keep by making this a five-minute decision instead of an annual guilt pile — and the pattern folds into the annual security review so the register itself gets audited yearly.
- After a break-in, the register is the fact witness. "We think they got into the office" becomes "K-014's cabinet was opened; K-002 and K-014 compromised; both cylinders changed the same day at 14:30." That is the sentence the police report, the insurer, and the incident response plan all need — and it is only writable from a list that was true before the night in question.
A key inventory register is one row per physical key: numbered ID, what it opens, holder, role, issued, returned, signature — plus a master flag on the keys that open everything. Number every copy, keep two masters (one custodian, one lockbox), collect keys in the same pass as laptops and badges, run the exposure test before buying a rekey, and count metal against rows quarterly next to the badge and visitor logs. The Ops Starter Kit ($14) includes the fill-in-the-blank register sheet and the quarterly count half-page, and the Automation Starter Pack ($19) schedules the quarterly reconciliation nudge and the offboarding key-return step so nothing quietly walks out the door.