Guard OperationsAction checklist

Access Control, Visitor, Vendor, Delivery, Key and Badge Checklist

An access-control security checklist helps a site admit authorized people and deliveries while documenting exceptions and protecting emergency egress. This version covers access lists, identity checks, visitor and vendor authorization, escorts, deliveries, keys, badges, after-hours requests, lost credentials and privacy. It does not tell a guard whom to search, detain or physically confront, and it should never be used to collect access codes or identification data on a public webpage. Site policy, post orders, emergency plans and applicable law determine the actual procedure. Train personnel on those approved rules and provide a safe escalation path for uncertain or denied requests.

Why it matters

Use a system view, not a single-control view

Access control is a lifecycle, not a door transaction. Authorization can change, temporary credentials must return, delivery exceptions need resolution and lost keys may require a facility response.

NIST physical-access guidance calls for approved access lists, credential issuance, authorization checks, visitor control, audit logs and secured keys. Those controls are useful planning principles even when a private property is not subject to that NIST publication.

Before you begin

How to use this checklist

  1. Review the approved site policy and post orders before using the checklist; never substitute a generic item for a site rule.
  2. Mark items for the applicable access period or transaction type and keep identity details in the site's approved system, not this public tool.
  3. When authorization is uncertain, pause the entry process and use the approved contact or escalation route from a safe position.
  4. At shift end, reconcile temporary credentials, keys and unresolved exceptions with the next responsible person.
Interactive checklist

Mark each task from current evidence

Use Not applicable only when the item genuinely does not apply, and follow the site’s approved escalation process for any urgent condition.

Section 1 of 5

Authorization and entry points

Make the approved rule and current authorization source clear before processing entry.

01The current access policy, post orders and authorized-entry locations are available to assigned personnel. Priority review item

Evidence to look for: Confirm the current controlled version and revision date; do not display restricted entry information publicly.

02The source used to verify employee, visitor and vendor authorization is current and access-limited. Priority review item

Evidence to look for: Examples include an approved system, roster or named sponsor process with a documented update owner.

03Entry and exit points are operating as intended without defeating emergency egress. Priority review item

Evidence to look for: Observe doors, readers and guard controls within assigned duties; occupied-workplace exit routes must remain available as required.

04After-hours and unusual access requests have a defined authorization process. Priority review item

Evidence to look for: The procedure should identify who may approve exceptions and how the decision is recorded without sharing private contact details.

Section 2 of 5

Visitors and vendors

Apply the same approved process consistently while minimizing unnecessary personal data.

05Visitor identity and authorization are verified using the site's approved method. Priority review item

Evidence to look for: Confirm only the information required by policy and applicable privacy rules; avoid copying identification unless the approved process requires it.

06Visitors receive the required temporary credential and visible instructions for its use.

Evidence to look for: The credential should be time- or area-appropriate and distinguishable from permanent access where the system supports it.

07Escort requirements are known and an authorized escort is present when required. Priority review item

Evidence to look for: Verify the escort's authority and responsibility; never leave an escorted visitor unattended in a controlled area.

08Vendor access matches the approved work order, location and service window. Priority review item

Evidence to look for: Compare the request with the authorized source; do not disclose other tenants, systems or restricted areas.

Section 3 of 5

Deliveries and service activity

Separate routine receiving from exceptions that require client decisions.

09The delivery destination, recipient or approved receiving process is verified.

Evidence to look for: Use the site's current directory or receiving system without confirming sensitive occupancy information to an unverified requester.

10Delivery personnel remain within approved public, receiving or escorted areas. Priority review item

Evidence to look for: Follow site rules for loading docks, service corridors and tenant areas; do not publish those boundaries in this tool.

11Unexpected, damaged, leaking or concerning items are handled under the site's safety and emergency procedure. Priority review item

Evidence to look for: Do not touch, open or move a concerning package merely to complete a security check.

12Completed vendor or delivery access is closed out in the approved record.

Evidence to look for: Record departure, returned credentials and any unresolved facility condition without unnecessary personal information.

Section 4 of 5

Keys, badges and access devices

Maintain an accountable chain from issuance through return or compromise response.

13Keys, badges and temporary access devices are inventoried and stored against unauthorized use. Priority review item

Evidence to look for: The controlled record should identify device, custodian, status and authorized holder without exposing codes or door mappings.

14Each issue and return is recorded with accountable acknowledgment.

Evidence to look for: Record the minimum necessary holder, device, date/time and authorizing role in the approved system.

15Access is removed or credentials are recovered when authorization ends. Priority review item

Evidence to look for: Use a documented HR, tenant, contractor or sponsor offboarding trigger and verify completion.

16Lost, stolen, unreturned or possibly copied credentials trigger the approved compromise process. Priority review item

Evidence to look for: The response may include deactivation, rekey review, notification and incident documentation decided by authorized facility personnel.

Section 5 of 5

Exceptions, records and handoff

Make unresolved access conditions visible to the next responsible role.

17Tailgating, door-prop or access-denial exceptions are documented as observed behavior and condition. Priority review item

Evidence to look for: Record what occurred, where, when, actions and notifications; avoid assumptions based on appearance.

18Access logs and visitor records are available only to authorized users and retained under approved policy.

Evidence to look for: Confirm permissions, secure storage and disposal expectations; collect no more personal data than the approved business purpose requires.

19System outages have a documented manual or backup process that preserves authorization checks. Priority review item

Evidence to look for: The backup should define who approves access, how events are logged and how records are reconciled after restoration.

20Shift handoff includes unresolved visitors, vendors, credentials and access-system conditions.

Evidence to look for: Use the approved handoff record and minimum necessary detail; obtain acknowledgment from the receiving role.

Current result

Complete the checklist to see a summary

Results are informational and do not certify compliance or eliminate risk.

Common mistakes

What can weaken the review

  • Treating a uniform, familiar face or confident explanation as proof of authorization.
  • Collecting or retaining more identification data than the approved process needs.
  • Allowing a temporary badge or vendor escort exception to remain open after the visit.
  • Propping or locking a door in a way that interferes with required emergency egress.
  • Confronting a person when the safer approved response is observation, distance and escalation.
  • Entering access codes, master-key labels or restricted-area details into an online checklist.
Practical questions

Frequently asked questions

What information should a visitor log collect?

Collect only what the site's approved purpose and privacy rules require, commonly identity or name, sponsor, time and credential status. The record owner should define access, retention and secure disposal; a public checklist should not collect visitor data.

What should a guard do when a visitor cannot be verified?

Keep the person in the approved public or waiting area, explain that authorization must be confirmed, and contact the sponsor, supervisor or designated decision-maker. Call 911 for an immediate threat.

Should a lost key always cause a lock change?

Not every key has the same exposure. Report it immediately so the authorized facility or security leader can assess identification, duplication risk, affected areas and compensating controls and decide on deactivation or rekeying.

Can an exit door be locked for security?

Security controls cannot defeat applicable egress requirements. OSHA rules require employees to be able to open exit-route doors from inside without keys, tools or special knowledge, subject to limited approved arrangements. A qualified facility or fire/life-safety professional should resolve conflicts.

Sources and evidence baseline

These references support the general planning baseline. Site-specific decisions still require the responsible organization and appropriate qualified professionals.

  1. NIST SP 800-171 Revision 3: Physical ProtectionNational Institute of Standards and Technology

    Access authorization, credentials, logs, visitors and physical access-device controls.

  2. Security Plan Guidance: Access Control DevicesFederal Select Agent Program

    A regulated high-security example adapted only for general key tracking, return and compromised-key response concepts; it is not presented as a requirement for ordinary commercial properties.

  3. Maintenance, Safeguards, and Operational Features for Exit RoutesOccupational Safety and Health Administration

    Unobstructed exit routes and functioning emergency safeguards.

  4. Physical Security Performance Goals for Faith-Based CommunitiesCybersecurity and Infrastructure Security Agency

    Visitor management and controlled-entry planning principles.

Source links checked: July 19, 2026