Do the audit as if you were arriving with no insider knowledge. Start at the sidewalk or parking space, walk to every entrance a real visitor might use, try the instructions on the phone they would actually carry, and keep going through checkout. That exposes problems an administrator rarely sees from inside an app.
This audit is deliberately operational. It is not a cybersecurity certification, a landlord-tenant legal review, or a promise that one device is secure. It is a way to find mismatches between doors, people, credentials, network dependencies and handoff procedures before the next visitor discovers them at night in the rain.
Keep door mechanics in the access audit
Guest access software cannot compensate for a bolt that drags, a door that must be pushed while locking, or a strike plate that has shifted. Test the door manually with the door open and closed before troubleshooting credentials. Repeated motor retries can drain batteries and create false 'access' complaints. If the door, frame, fire-rated assembly or egress hardware needs alteration, use appropriate local help rather than treating it as an app setting.
Know which functions require cloud, hub, Wi-Fi or Bluetooth
The word 'smart' hides several dependencies. Local keypad entry may work with no internet while remote unlock, notifications or guest-code creation may depend on a hub or cloud service. Map the dependency for each feature you actually use. Then test the property with Wi-Fi unavailable. FTC and NIST guidance for connected products both support the broader habit of maintaining updates, secure configuration and data protection rather than assuming connectivity equals security.
Use logs as a troubleshooting tool, not a surveillance hobby
Event history can help answer practical questions: did a code activate, did the lock report a failed attempt, did an administrator revoke access? But collecting more visitor history is not automatically better. Decide who can see logs, how long they are needed, and whether local rental, employment, privacy or tenancy rules affect use. Avoid promising that a consumer log is a legal-grade security record.
Treat this as an observable checkpoint: For use logs as a troubleshooting tool, not a surveillance hobby, For rentals and visitors, the same choice can affect a resident, a cleaner, a contractor and a one-night guest differently. Photograph or note the current condition when that will make a later comparison useful; do not collect personal data merely because the app allows it.
Reduce shared secrets and unused integrations
Long-lived shared PINs, forgotten app invitations and integrations that nobody uses all widen the administrative surface. Prefer individual or role-based credentials where the product supports them, remove access that no longer serves a purpose, keep supported software updated, and use stronger account authentication when available. These are practical applications of the security outcomes emphasized by NIST, FTC and CISA; they are not a guarantee that a particular lock is secure.
Walk through the real sequence and look for the mismatch: For reduce shared secrets and unused integrations, For rentals and visitors, the same choice can affect a resident, a cleaner, a contractor and a one-night guest differently. Mark the result as pass, watch, or fix. That prevents a long checklist from becoming a pile of observations with no owner.
End every stay with an operational handoff
The last step is not merely deleting a code. Record whether the door hardware behaved normally, whether batteries or service warnings appeared, whether the guest needed the fallback method, and whether the instructions were confusing. That small handoff turns repeated guest access into a maintainable process. Patterns become visible: a code format that causes mistakes, a phone workflow that excludes some guests, or a door that only binds in humid weather.
Treat property rules and local law as a separate gate
A device feature does not decide whether a landlord, host or employer may use it in a particular way. Lease terms, building rules, fire and egress requirements, privacy law, short-term-rental rules and notice obligations can all change the answer. Before using remote lockout, cameras, detailed access monitoring or hardware modifications, check the rules that apply to the specific property and relationship.
Walk the entire guest route, not just the front door
Begin where a visitor first receives instructions. Check whether the address, correct entrance and arrival window are unambiguous. At the physical door, look at lighting, weather exposure, keypad visibility, the mechanical feel of the latch and whether a screen or storm door changes the sequence. Continue inside: does the visitor need a second credential for a garage, building lobby, elevator, storage room or interior suite? Every extra controlled point is another place for instructions and revocation to diverge.
Then audit departure. Is checkout time linked to the credential end time? Does the host have a positive confirmation that access ended, or merely an assumption? If a cleaner or co-host needs overlapping access, verify that revoking the guest does not revoke the service role. A door-by-door audit is useful because it catches privileges that grew organically around different apps and hardware.
Create a simple property map with each controlled opening, credential type, administrator, fallback and dependency. Mark whether the opening still functions locally if the internet is unavailable. A one-page map is easier to maintain than several app screenshots.
Red flags that deserve action instead of another setting change
Treat repeated door binding, overheating batteries, damaged wiring, loose hardware, failed egress hardware or an active product recall as stop-and-fix issues. Treat unknown administrators, former residents with access, shared master codes and abandoned integrations as security cleanup issues. Treat remote lockout, monitoring, cameras, occupancy tracking or hardware changes in a rental as issues that may need a separate legal or property-rule review.
The audit should also reveal support problems. If every late-night arrival requires a phone call, the system is not self-service. If only one person can recover the account, administration has a single point of failure. If a guest can enter but cannot explain how to lock the door when leaving, the instruction is incomplete.
Finish with a dated record rather than a vague 'checked'. For each door write: physical condition, normal method, fallback, cloud or hub dependency, active guest classes, last revocation test, administrator, and next review trigger. That record makes the next quarterly audit faster and gives the household a clean baseline after a phone replacement, resident move or property-management change.
Run one no-admin arrival test
Choose a trusted tester who is not an administrator and do not stand beside them. Send the same message a guest would receive. Ask them to arrive, identify the right entrance, wake the lock, enter, lock the door again from inside, leave, and secure it from outside. If the property uses a lobby, garage or second controlled door, include those too.
The tester should note every assumption the instructions made: whether the keypad needed a confirm key, whether a code seemed inactive before the scheduled time, whether the door had to be pulled while the bolt moved, whether the app requested an account step that was never mentioned, and whether locking on departure was obvious. These observations are more valuable than a screenshot showing that a credential exists.
After the test, revoke only that tester's access and verify the exact method is dead. Then confirm one resident or service credential remains active. This catches a dangerous administrative mistake: using one shared credential because it was easier to distribute. The audit passes when a guest can complete the full arrival-and-departure loop and the host can remove that guest without collateral damage.
One final check is administrative continuity. Ask what happens if the property manager changes tomorrow. Can the new responsible person identify the account owner, remove the former manager, find the current product documentation, and verify every active guest role without factory-resetting the system? If not, the property still depends on personal memory rather than a maintainable access process.
A copyable audit sheet
| # | Check | Status | Record |
|---|---|---|---|
| 1 | Keep door mechanics in the access audit | Pass / Watch / Fix | Owner + next action |
| 2 | Know which functions require cloud, hub, Wi-Fi or Bluetooth | Pass / Watch / Fix | Owner + next action |
| 3 | Use logs as a troubleshooting tool, not a surveillance hobby | Pass / Watch / Fix | Owner + next action |
| 4 | Reduce shared secrets and unused integrations | Pass / Watch / Fix | Owner + next action |
| 5 | End every stay with an operational handoff | Pass / Watch / Fix | Owner + next action |
| 6 | Treat property rules and local law as a separate gate | Pass / Watch / Fix | Owner + next action |
Boundary note
This D02-022 guide is operational consumer information, not legal advice, a locksmith inspection, a cybersecurity certification, or a promise that a particular access product is secure. Rental, tenancy, privacy, short-term-rental, fire, egress and building rules vary. Follow current instructions for the exact lock and connected service, and use qualified local help for door, frame, regulated egress, wiring or other work outside ordinary configuration.
Sources
- NIST IR 8425 — Profile of the IoT Core Baseline for Consumer IoT Products — checked 2026-10-05
- FTC — Securing Your Internet-Connected Devices at Home — checked 2026-10-05
- CISA — Secure Our World — checked 2026-10-05