How to Keep Track of Company Keys – A Complete Guide
17 juli 2026 · 5 min läsning
To keep track of company keys, you need four things: a register of every key you own, a single checkout point where every handout is recorded with a due date, a routine that surfaces overdue keys, and a permanent history per key. Miss any one of the four and keys will go missing — quietly, and usually the important ones.
This guide walks through building that system step by step. The steps are the same whether you run them on paper, in a spreadsheet, or in key tracking software; where the medium matters, we'll say so.
Step 1: Build a key register
You can't track what you haven't listed. Go through every key box, drawer, and manager's desk once, and record every key the company owns.
For each key, capture:
- A human-readable name. "Master — Warehouse, roller door," not "K-17." Keys outlive the people who named them.
- An identifier, if the key has one stamped on it.
- A category — masters, vehicle keys, tenant keys, cabinet keys. Categories make audits and searches manageable once you're past a few dozen keys.
- Copies. If you hold four identical copies of the front-door key, record it once with a quantity of four, not as four separate entries. Reserve individual entries for keys where the specific physical key matters — masters, restricted keys, anything you'd need to trace.
This distinction — quantity-tracked copies versus individually tracked keys — is the single biggest thing that keeps a key register usable. (In guardable these are bulk and unique items respectively; unique items each carry their own complete history.)
Expect surprises. Most first-time registers turn up keys nobody can identify and copies nobody knew existed. Label the mystery keys, park them in their own category, and retire them deliberately later.
Step 2: Establish one checkout point
Every key transfer goes through one process — a sheet, a spreadsheet, or software — with no exceptions, including managers, including "just for five minutes."
Each checkout records:
- Which key (from the register — never free-typed)
- Who took it — a named person, and the company they represent if external
- Date out
- Due back — always, even if it's "end of day"
The due date is the piece most teams skip and the piece that makes everything downstream work. A key without a due date can't be overdue; a key that can't be overdue never gets chased; a key that never gets chased is gone.
Two rules to enforce culturally:
- No relay handoffs. A key comes back to the checkout point before it goes to the next person. Person-to-person transfers are where custody chains break.
- External holders get shorter windows. Contractors and vendors should have a named individual (not "the electricians") and an explicit return date on every checkout.
Step 3: Make overdue keys surface themselves
Decide, in advance, what happens when a due date passes:
- Day 0–1 overdue: a reminder to the holder. Most overdue keys are honest forgetfulness, and a prompt fixes it.
- Persistent overdue: escalate to the holder's manager or, for externals, the vendor contact.
- Presumed lost: a defined point where you stop chasing and start your lost-key procedure — assess what the key opens, and rekey if it's a master or restricted key. Your key control policy should set this threshold before you ever need it.
On paper, "surfacing" means a mandatory weekly scan of the sheet for return-date blanks — put it in someone's calendar, because unowned routines don't happen. In software, overdue keys flag themselves the moment the date passes and reminders are one click, which is honestly the strongest argument for going digital: the system does the noticing.
Step 4: Keep history you can replay
When a key goes missing — and one eventually will — the question is never just "where is it now?" It's "who has ever held this key, and when?" That determines whether you rekey one cabinet or a whole building, and it's the first thing an insurer asks.
Paper history lives in binders that get thrown out. Spreadsheet history dies with every edit. If keys are genuinely important to your operation, this is the requirement that ends the paper era: you want an append-only, timestamped log per key that nobody can quietly rewrite. (guardable stores every order event immutably — each key's full custody history is replayable years later.)
Step 5: Audit twice a year
A key audit is a physical count reconciled against the register:
- Every key marked "in" is physically present.
- Every key marked "out" has a named holder who confirms they still hold it.
- Every physical key present appears in the register.
Discrepancies get resolved immediately — found keys checked back in, missing keys pushed into the lost-key procedure. Twice a year is right for most organizations; quarterly if you handle restricted keys or high contractor turnover. With software doing the daily bookkeeping, an audit of a few hundred keys is an afternoon, not a week.
Paper, spreadsheet, or software?
- Paper sheet — fine for one site, under ~15 keys, stable staff. Free, zero learning curve, fails silently. Use our key sign-out sheet template if this is you.
- Spreadsheet — searchable and multi-user, but still relies on manual discipline, has no overdue concept, and overwrites its own history.
- Key tracking software — the register, checkout log, overdue flagging, and permanent history in one place, across all sites. Costs money above the free tiers, pays for itself the first time a master key doesn't go missing. Our key management software guide covers the switch.
Frequently asked questions
What's the best way to keep track of keys at work?
A key register plus a single checkout point where every handout is logged with a due date. Small operations can run this on paper; anything with multiple sites, contractors, or audit requirements should use key tracking software so overdue keys flag themselves.
How do you track who has a key?
Record every handout against a named person with a date out and a due date, and record the return. Never allow person-to-person handoffs — every transfer passes back through the checkout point so the record matches reality.
How often should you audit keys?
Twice a year for most organizations: physically count keys, confirm every "out" key with its holder, and reconcile against your register. Audit quarterly if you manage master or restricted keys with high turnover.
What should you do when a company key is lost?
Check the key's custody history to identify the last holder and everything the key opens, then decide on rekeying based on risk — always rekey for masters and restricted keys. This is exactly why permanent per-key history matters more than the current-status list.
Want the register, checkout log, and overdue flags without building them yourself? Try guardable free — 50 items and 100 orders on the free tier, no credit card, no time limit.