Every building has a list of keys that exists nowhere except in people's heads: the back door, the letterbox, the alarm room, the cupboard with the till. The register replaces that folklore with a table. One row per key, issue and return recorded as two separate events, and the rule that a key never changes hands without changing a row. It is the cheapest security control a small site can run — a notebook beats a $2,000 access system that nobody maintains.
Not "roughly". Name them: the cleaner, the weekend casual, the contractor who did the fit-out two years ago, the ex-manager whose key "was never really returned". If the answer requires walking to the staff room board and squinting at a pegboard, the site doesn't know who can open it — and everything downstream (alarm codes, insurance claims, incident investigations) inherits the guess.
Physical keys are credentials. They just predate the vocabulary. Nobody would let a departing employee keep an active login; the same standard applied to the back door is the whole register.
A notebook, a spreadsheet, or a page in the ops binder — the format matters less than the columns, because the columns are what turn a dispute into a lookup:
| Column | What goes in it | Why |
|---|---|---|
| Key ID | An etched code (K-12), never the door name | "The red one" is not an identifier. Codes survive staff, rebrands, and arguments. |
| What it opens | Door / lock description | Needed when a key comes back and nobody remembers it. |
| Type | Standard / restricted / master / fob / code | Masters and fobs carry different rules (below). |
| Cut / programmed date | When it was made | Old keys on old locks are the audit's raw material. |
| Issued to | Name + role | Roles outlive names; both matter when someone leaves. |
| Issued date + signature | The acknowledgement | A signature at issue time is the whole insurance claim, later. |
| Status | Issued / returned / lost / retired | "Returned" with no date is still issued. |
| Return date + received-by initials | Who took it back | The handover is not done until a second person's initials are on the row. |
One row per physical key. If a cleaner holds a ring of four keys, that is four rows and one ring — or one "ring" row that lists the key IDs inside it. Pick one convention and keep it.
When a key moves from Dana to Priya, the register gets two events: Dana's row closes (returned, dated, received-by initialed) and Priya's row opens (issued, dated, signed). Editing Dana's row to say "Priya" destroys the history — and the history is the point. Six months later the question is never "who has K-12 now"; it is "who had K-12 in the week of the 14th". A register that overwrites itself cannot answer that. A register that appends can.
The same applies at exits: the returning key goes into the cabinet (or the rekey queue), and the departing person signs the close. If a key is genuinely not coming back — lost, kept by agreement, worn out — the row says so with a date and a decision, not a blank.
Electronic fobs follow the register exactly — with one addition: a collected fob still opens the door until the system deactivates it. Handing the fob across the desk is the beginning of the offboarding, not the end; the access-control checklist step is the deactivation, confirmed. Alarm codes are the same: recorded under a person, changed (not "told to the next person") on departure. A code is a key that copies itself for free.
A bakery ran the register: eleven keys on eleven rows, each signed at issue. A cleaner reported her ring lost on a Tuesday. The manager read the register, knew exactly what was on the ring (front, back, storeroom — no master), called the locksmith the same day, had two doors rekeyed for $180, and issued the replacement ring with new rows by Thursday. Total disruption: one morning.
A neighbouring cafe, same incident, no register. Nobody could say what was on the cleaner's ring — or who else held copies of the same cuts, because the last manager had "a few made" and left. The insurer asked. The cafe spent the weekend changing every lock on the premises, didn't sleep, and still couldn't produce a list of who held what. Same lost ring, different month: one cost $180, the other cost a weekend, a premium conversation, and an answer they still don't have.
Once a quarter, one person counts the cabinet against the register: every row marked issued should have a key in a person's pocket, every key in the cabinet should be on a row marked returned or retired. Unexplained key or unexplained row — that's the agenda item, resolved the same week, while the trail is still warm. Five minutes, four times a year, is the entire maintenance cost of never doing the weekend-from-hell rekey.
PHYSICAL KEY REGISTER — [site name] | Key ID | Opens | Type | Cut date | Issued to | Issued date | Signature | Status | Return date | Received by | |--------|------------------|----------|------------|----------------|-------------|-----------|----------|-------------|-------------| | K-01 | Front door | Standard | 2025-03-02 | D. Nguyen | 2025-03-04 | (signed) | Issued | | | | K-02 | Back door | Standard | 2025-03-02 | (cabinet) | | | Returned | 2026-08-14 | MP | | K-07 | Storeroom | Master | 2024-11-20 | MANAGER ONLY | 2024-11-21 | (signed) | Issued | | | KEY RETURN RECEIPT (attach to closed row) Key ID: ______ Returned by: ______________ Date/time: __________ Condition: [ ] OK [ ] Damaged [ ] Not returned (reason + decision) Received by (initials): ______ Next action if lost: REKEY — booked for: ______
---
The Ops Starter Kit ($14) turns exit-day chaos — keys, accounts, badges, code word — into a fillable sequence, and Vol. 2 ($27) adds the DR plan and evidence log for the review after anything worse. The First 30 Minutes checklist is free.