NovAsia

Who Should Hold the Keys and Access Rights to an Investment Apartment?

A key appears to be a minor operational detail until there is a leak, burglary, tenancy change or emergency. The owner then discovers that one copy remains with a former manager, reception has another without a register, a cleaner knows a permanent smart-lock code and the owner does not control the administrator account.

The apartment may be physically locked, yet nobody can identify every person who is able to enter.

A secure access system does not mean that the only key sits with an owner in another country. It means every key, access card, parking remote, code and digital account has a named holder, a defined purpose, a time limit and a revocation method. Emergency entry remains possible, but it does not become a permanent and informal right for an unknown group of people.

Allocate access by role

Begin with the question of who genuinely needs access, not how many copies are convenient.

Possible participants include:

Each role needs a different level of access.

The owner retains legal and administrative control, even when they rarely use the apartment. The tenant normally receives exclusive everyday possession during the tenancy. A manager may need access for inspections, repairs and emergencies but not an unrestricted right to enter at any time. Building engineers may require access during an actual emergency or work involving common systems. A cleaner or contractor should receive task-specific and time-limited access.

A weak arrangement relies on one universal key or code shared whenever someone “needs to get in”. A stronger arrangement looks like this:

RoleAccess typeDuration
TenantMain key or personal codeTenancy term
Property managerLogged spare keyManagement agreement
ContractorTemporary key or codeOne approved job
Building managementEmergency procedureEvent only

The general principle is least necessary access. A person should receive the minimum permission required for the task.

A tenant needs quiet enjoyment and clear entry rules

A spare key held by the owner or manager does not create a general right to enter the rented home.

The tenancy agreement should state:

“The owner keeps a key” is too vague. The tenant should know whether it is reserved for emergencies or may also be used for pre-arranged inspections.

Where a tenant has a legitimate concern that a key has been copied, there should be a workable route to change the cylinder. A balanced arrangement may allow an approved replacement, with an emergency spare sealed or lodged under a controlled procedure, followed by restoration or formal handover at the end of the tenancy.

Smart-lock records should not be used as a routine surveillance tool to track when a tenant leaves and returns. Access control protects people and property; it should not become covert monitoring.

Keep a register even for one apartment

A simple key register should record:

Use a neutral identifier on the key. A tag showing the building and unit number helps a finder identify the apartment. Keep the table linking internal numbers to the address separately.

At purchase or handover, record how many keys were supplied by the developer or seller. Where the number of historic copies is unknown, the cylinder should be treated as potentially compromised. This is particularly relevant to resale units, former short-term rentals and apartments that have passed through several management companies.

Reception's register does not replace the owner's register. Building management may track access cards but not mechanical keys. The property manager should reconcile both systems.

A short signed or digitally acknowledged handover record protects everyone. A reliable manager may simply forget, months later, that a spare was left with a contractor.

Track building cards separately

A building card may open the entrance, lift, car park, pool or gym but not the apartment door. Losing it creates a different risk from losing a mechanical key.

Record:

At move-out, receiving the plastic card back is not enough. Confirm that building management has disabled or reassigned it. Where technically possible, request the current list of active cards linked to the unit.

Parking remotes, mailbox keys and storage-room keys should have separate register entries. They are often forgotten and delay the deposit settlement.

Building rules may govern access to common facilities. An owner should not promise unrestricted gym, parking or pool rights without checking the current rules and any fees.

If a card is stolen together with identification showing the address, immediate deactivation matters more than deciding who will pay the replacement fee.

Smart locks reduce some risks and create others

A smart lock can provide:

It also creates dependence on:

The owner should remain the primary administrator. A property manager may receive a delegated account, but should not own the only cloud profile or recovery email.

Keep a secure record of:

One permanent code shared by tenant, cleaner, manager and contractors removes the main security benefit. Individual credentials allow the owner to disable one person without disrupting everyone and make logs more meaningful.

A contractor's code should expire automatically after the agreed work period. Do not leave screenshots of access codes in a large group chat.

Digital security is part of property maintenance

A robust door can still be weakened by an administrator password reused on other websites.

Minimum controls should include:

Do not store every access code in an unprotected spreadsheet available to cleaners and contractors. A management company should use a restricted and auditable storage system.

When changing managers, transfer administrative control first. Test owner login, recovery and the mechanical key. Only then disable the previous manager and connected devices.

Receiving a password is not enough if the recovery email still belongs to the former manager.

Select a lock with a clear support and update policy. If the manufacturer discontinues the app or cloud service, the apartment must remain accessible. Technology should simplify management rather than make the unit unusable during an internet or service failure.

Want to compare Phnom Penh projects by real yield and risk? Request a NovAsia selection — no marketing fog.

Contact usor on Telegram

Reception should not become an uncontrolled key cupboard

A spare at reception can be useful during a leak or other urgent event, particularly where the owner is abroad. Informal storage “with security” creates risks:

Where reception holds a key, agree a process:

Building staff may need access to common pipes or systems passing through the apartment. That does not create a right to enter whenever convenient. The basis should be a real need, building rules and the tenancy arrangement.

Where reception does not maintain proper controls, it may be safer for the spare to remain with a professional manager who can respond promptly.

The owner should periodically verify that the spare actually exists and that the release procedure still operates. “There should be a key downstairs” is not an emergency plan.

Cleaners and contractors should receive temporary access

A cleaner may attend weekly and a contractor once. Neither normally needs a permanent universal key by default.

Options for a cleaner include:

For a contractor, record:

Do not provide a key to “the company” without identifying the person. Contractors may use subcontractors, so the owner or manager should know who actually entered.

During a multi-day renovation, a temporary construction cylinder can be used and then replaced. This prevents the permanent tenant key from circulating among numerous workers.

If a worker loses a key, respond according to risk rather than waiting for an argument over blame. A key lost with an access card or address may justify immediate cylinder replacement. A neutral unmarked key lost far away may create a lower risk, but the incident still belongs in the register.

Emergency entry should be rapid and tightly limited

A genuine emergency may include:

An owner's curiosity, a routine viewing or convenient contractor scheduling is not an emergency.

The procedure should answer:

  1. Who authorises entry?
  2. Who opens the apartment?
  3. Who attends as witness?
  4. Which areas may be entered?
  5. How are the tenant's belongings protected?
  6. What evidence is created?
  7. How is the apartment secured again?
  8. How and when is the tenant notified?

Where a tenant cannot be contacted, engineering staff and the manager may need to act immediately under the contract, building rules and circumstances. Their actions should be limited to controlling the danger.

A bathroom leak does not justify photographing unrelated personal belongings.

After entry, the owner should receive a chronology, names of participants, reason, relevant photographs and the status of keys or locks. If the door was forced, replacement and new-key handover should be documented.

An emergency code should not be a universal code known to all staff. A sealed key, owner-generated temporary code or controlled administrator action is safer.

Reset everything after a tenant leaves

Move-out is not complete merely because one visible key has been returned.

Use a checklist:

A tenant may honestly not know whether a relative copied a conventional key. Where key control is uncertain, replacing the cylinder can be more sensible than debating intent.

For a smart lock, deleting the visible PIN is insufficient if the tenant had administrator rights or linked a device. A full reset and new owner-controlled profile may be necessary.

Building management should remove the former occupant's name and cards. Returned credentials should not remain active.

Deposit deductions must be evidenced and contractually justified. Routine security upgrading by the owner is different from replacement caused by a documented lost key. The owner should not automatically charge a tenant for an expensive new smart lock when a basic cylinder replacement would have addressed the issue.

Close all access when changing property manager

The handover should include:

The former manager should not keep a spare “just in case”. After the management agreement ends, their authority ends unless a separate new arrangement exists.

Before final settlement, the owner should independently test login, recovery, cards and the mechanical key.

If a former manager reports a lost key, first control the risk by replacing the cylinder where appropriate. The reimbursement dispute can be addressed afterwards.

Sales, inspections and inheritance require added controls

During a sale, agents, valuers, inspectors, buyers and lawyers may need entry. One lockbox code shared among many people is weak if it is not changed and visits are not recorded.

A seller should define:

At completion, the buyer should receive the full access inventory and administrative accounts. The seller and former manager should remove their access unless the new owner enters into a separate agreement.

For death or incapacity, secure recovery instructions should exist. A trusted person should know where to find the access register and how to initiate lawful control. Publishing live codes in a will or broad family chat is poor security.

A power of attorney, management contract and succession authority are different legal instruments. Access to the door does not itself prove authority to manage or dispose of the property.

Review the system at least once a year

An annual check can take less than an hour:

Red flags include:

A secure investment apartment is not one that nobody can enter. It is one where authorised people can enter when genuinely necessary, unnecessary access is limited and every credential can be identified and revoked quickly.

For an overseas owner, that system is part of asset management, not a minor housekeeping matter.

This article is for general information and does not replace individual legal or security advice. Entry rights, notice, emergency action and cost allocation should be checked against the tenancy agreement, building rules and facts of the specific incident.

Ready to look at specific units for your budget? Get a tailored NovAsia Estate shortlist with the full cost, instalment plan and a yield breakdown.

Find a propertyor on Telegram

Sources

  1. Kingdom of Cambodia, Civil Code, relevant lease provisions concerning the tenant's ordinary use, the landlord's non-interference and access required to preserve the property. English translation used for reference; current Khmer text and legal advice should be checked.
  2. Royal Government of Cambodia, Sub-Decree No. 126 on the management and use of co-owned buildings, including internal rules, common systems and management responsibilities.
  3. United States National Institute of Standards and Technology — consumer smart-home security guidance on unique passwords, multi-factor authentication, updates and account control, published 2025.
  4. NIST Internet of Things cybersecurity guidance on device identification, secure configuration, access control, data protection and reliable software updates.

Frequently asked

Should building reception hold a spare key?

Not necessarily. It depends on building rules, security controls and the written agreement of the owner and tenant. Any stored key should be logged and released only to clearly authorised people.

Can a property manager give a key to a contractor?

Only for a specific approved job, with a record of issue, a return deadline and access control. A contractor should not retain a permanent copy without a compelling and documented reason.

What should happen after a tenant moves out?

Collect every key, card and remote, disable old codes and connected devices, review access records and, where control is uncertain, replace the cylinder or fully reset the smart lock under a new administrator.

Is a smart lock safer than a conventional lock?

It can make temporary access and revocation easier, but it also requires a strong unique password, multi-factor authentication, software updates, control of the administrator account and a reliable mechanical backup.