Finance & Strategy

Who Still Has a Key? 5 Moments Every Restaurant Must Change the Locks

Your exit process covers the uniform and the final paycheck. The key, the alarm code and the safe combination are rarely on it.

In this article
  1. 5 moments when access should change
  2. What it actually costs — and what not doing it costs
  3. How exposed are you right now?
  4. How access builds up when nobody revokes it
  5. One page for before it happens
  6. The key is the forgotten step, not the hard one

Someone leaves, and the checklist is clear: uniform back, storeroom key back, final paycheck. Nowhere on that list is the front-door key, the alarm code, the safe combination, or the password to the delivery app — and that isn't because nobody thinks of it. It's because that list never existed.

Of every kind of small business, a restaurant hands out the most keys to the least stable team. A typical venue issues a door key, an alarm code, sometimes a safe combination, a POS login and a login for the delivery tablet to everyone working the evening shift — and the evening shift is exactly the team that turns over fastest.

That isn't a gut feeling. The U.S. Bureau of Labor Statistics tracks how many people voluntarily leave their jobs by sector through its JOLTS survey, and "Accommodation and Food Services" has sat at or near the top for years: in July 2026 the sector's quits rate stood at 3.5%, against 1.9% for the U.S. economy as a whole — nearly double. Across all of 2025, the same BLS data put the sector's full-year turnover rate at 65.5%, and the 2001-to-present average is 75.6%, against 43.4% for the broader economy over the same period.

Europe doesn't publish a single continent-wide figure to match, but the direction is the same: Eurostat records one of the highest job-vacancy rates of any sector for accommodation and food service activities — 3.0% EU-wide, 3.2% in the euro area — the same signal of a sector where roles are constantly being refilled. Translate that into a 20-person team and you get roughly a dozen people a year who once held a key, a code or a login and are no longer on the rota.

This article walks through five concrete moments when that access should change and, in practice, usually doesn't: someone leaving, access quietly building up in people who stay, a break-in or a near-miss, a contractor relationship changing, and a seasonal wave that removes a dozen keyholders inside two weeks. Then it works out what doing it properly actually costs — and what not doing it costs instead.

5 moments when access should change

None of these five is rare. Four of them happen in most venues several times a year. The problem isn't that the moment goes unnoticed — it's that nothing fixed starts happening when it arrives.

1. A keyholder leaves

Fired, resigned, or simply stopped showing up — for this checklist it makes no difference. The moment anyone with access leaves, there's a list that has to close that same evening, not "soon":

The door key — collected, or if that fails, the cylinder replaced. The alarm code — changed outright, not just deleted for that one user. The safe combination — if it's shared rather than individual, it always has to change in full. The POS login — one account per staff member makes this a click instead of a rebuild. The delivery app or tablet — a shared device logged into one account is exactly the leak nobody thinks of. Any shared password — the Wi-Fi, the accounting system, the banking app if it was ever set up on a personal phone.

The pattern behind a missed step is almost always the same: someone leaves on good terms, so nobody feels the urgency. That is exactly why this list shouldn't depend on how the departure went — it's a checklist that runs identically every time, whether someone left with a handshake or with a solicitor's letter.

2. Access quietly builds up in people who stay

IT security has a name for this: privilege creep — rights someone once needed temporarily and that are never taken back, until an account can do far more than the job ever asked for. A restaurant runs through exactly the same mechanism physically. A long-serving server gets a personal key "just in case" while the owner is on holiday. The holiday ends; the key doesn't. A shift lead is trusted with the safe code on one busy night and simply keeps it after.

Nobody ever makes a conscious decision to allow this — it just never gets undone. The result, a few years in, is a team where the number of people with full access has stopped tracking the number of people who actually need it, and where nobody quite remembers who's in the first group any more.

IT security's answer to privilege creep is a periodic access review: on a set schedule, explicitly check who can do what and actively decide whether that's still warranted. The same discipline works just as well here, and it costs no software — just a fixed point on the calendar where someone asks the question instead of assuming last year's answer still holds.

3. After a break-in, even without a loss

An attempt that took nothing feels like nothing happened. For the access that was visible that night, it isn't: any key or code that could have been seen, photographed or copied has to change, whether or not anything was actually taken.

There's also a purely financial reason not to put this off. Commercial burglary and theft policies commonly carry a "reasonable precautions" condition — a duty to take reasonable care of the insured property. QBE's own burglary policy wording states it plainly: the insured must take "all reasonable precautions" for the safety of the property covered. Legal firm Clyde & Co notes the test applied is what "the ordinary reasonable man in the position of the insured would have considered as adequate" — and a claim can be reduced or rejected if that condition wasn't met.

For consumer-facing policies the mechanism is spelled out even more directly: if an intruder gets in using a key and there's no sign of forced entry, a claim can be rejected outright, and some policies make changing the locks after a loss or theft an explicit condition of continued cover (Compare the Market, UK). There's no single EU-wide figure for how many commercial hospitality policies carry a clause like this — check your own policy — but the practice is common enough that it should never be treated as hypothetical.

4. A contractor relationship changes

A cleaning crew, a pest-control technician, a refrigeration maintenance firm — each of them gets a key for outside opening hours at some point, and that relationship changes more often than the key itself does. The contract ends, the regular technician is replaced by a colleague, the company is bought out by another one — and the key handed over three years ago simply stays in circulation.

One case specific to this decade: a delivery driver issued a back-door key during a busy delivery period so cold deliveries could be made outside normal hours, and that key never collected back once the arrangement ended or moved to a different platform. It's exactly the kind of access that shows up on no paperwork at all, because it was granted outside the normal staffing cycle.

The rule of thumb is simple: every time a contract ends, changes hands or changes provider is the moment to ask who still holds a key for it — not the day someone happens to remember.

5. A seasonal wave sweeps through the team

Where the first four moments touch one person at a time, this one touches a dozen at once. At the end of a terrace season or a student summer, seasonal and flexi-job staff often leave within two weeks of each other, and that's exactly when it becomes clear how much access was handed out in that short window: alarm codes given to everyone because it was faster than setting up individual ones, a shared POS login for the extra weekend team, a storeroom key handed to three students at once.

That very peak is why a delayed review is the most expensive kind: a dozen people leaving at the same time means a dozen repeats of the same question, "does this person still hold anything?" — and in practice that question usually never gets asked at all, because attention has already moved to the next rota rather than the last one.

Anyone who wants to fix this structurally schedules the access check as part of the seasonal plan itself — the same date the off-season rota gets drawn up is the natural moment to close out peak-season access. In Belgium, where flexi-job staff are common, that moment comes round several times a year as a matter of course.

What it actually costs — and what not doing it costs

The resistance to any of this is almost never principle — it's the assumption that changing locks is expensive and slow. For most of the steps above, that isn't true.

Changing an alarm code or a POS login costs nothing and takes a few minutes at most: it's software, not hardware. Even a physical lock isn't a large expense. UK locksmith network Keytek's own 2026 price guide puts changing one standard lock at £125–£185 and a high-security lock at £150–£185; changing every lock on a property starts, per the same guide, "from £350", typically two to four hours of work. Those are UK prices — most EU countries land in a broadly similar range, a few hundred euros for a whole venue, so ask your own locksmith for the exact figure.

The ladder: from free to €8,659

Five points on the same scale — from changing a code to the bill for a single break-in.

Change the alarm codesoftware, not hardware
free
Change the safe combinationfive minutes, no cost
free
Replace one lockKeytek UK: £125–£185 per lock
€155
Every lock on the venueKeytek UK: from £350, 2–4 hours
€410
One break-in, all incash · drink stock & equipment · repairs · spoilage · lost revenue — plus the risk a claim is reduced or refused
€8,659

The break-in bill (€8,659) is the worked example from the cost of a break-in on this site: cash, drink stock and equipment, repairs, spoilage and revenue lost over a day and a half. The calculator there lets you repeat that same breakdown with your own numbers. The lock prices come from Keytek (UK, 2026 price guide); ask your own locksmith for the local figure.

How exposed are you right now?

No exact number — that would fake a precision this subject doesn't have. Three questions instead, that together give an honest read on how urgent this is for your venue.

Exposure check

Three questions, no account, nothing sent or stored.

This is an honest-enough rule of thumb, not a security audit. Your own insurer, your own policy and your own premises remain the final word.

How access builds up when nobody revokes it

For a 20-person team at the annual turnover rate cited above — 65.5% (BLS, 2025) — that's just over thirteen people over a typical year. Anyone who never revokes access simply watches that number pile up, spike included around September when a student season typically winds down.

Thirteen departures, two ways to handle them

The same 20-person team, over twelve months. Above: how many people with still-valid access pile up if nobody revokes it. Below: the same departures, closed out the same week every time.

JanFebMarAprMayJunJulAugSepOctNovDec
Never revoked (running total) Closed out every time

An illustrative example based on a 20-person team at the BLS's own 65.5% annual turnover figure for 2025 in U.S. hospitality — the exact monthly spread varies by venue, the end-of-season spike usually doesn't.

One page for before it happens

Everything above gets easier with one standing document: a key register. No software, no subscription — one page of who holds what, since when, and when it was last checked. Print it and pin it by the safe, or keep it as a shared document reviewed once a month.

The point of the page isn't that it's kept perfectly from day one — it's that there's a fixed place where the question "who still has access to this?" can be answered in five seconds, instead of ten phone calls.

WhoAccess toSinceLast checked
OwnerDoor key · alarm code · safe · bankOpening
Head chefDoor key · alarm codeHire date
Floor shift leadAlarm code · POS loginPromotion
Cleaning crew (contractor)Door key (back entrance)Contract start

Four example rows to start from — fill in your own team and update the page on the same day as the seasonal rota, and every time someone leaves.

The key is the forgotten step, not the hard one

Nothing in this article asks for a new system, a subscription or an investment. It asks for five moments that are already happening — a departure, a long tenure, a break-in or a near-miss, a contractor changing hands, a seasonal turnover — to be recognised, each paired with the same short checklist every time.

The reason this gets skipped so often isn't reluctance. It's that there was never a fixed routine for it, while there has always been one for the uniform and the final paycheck. One register and five recognisable moments are enough to close that gap.

Pair this with a level-headed look at burglary deterrents and your own policy's small print, and both sides of the same question are covered: what happens if someone gets in anyway, and who can already just walk in today.

Frequently asked questions

Is this the same as the article on burglary security?

No, and that's deliberate. That article is about whether an alarm, cameras or better lighting are worth the money as deterrents against someone who isn't supposed to get in. This one is about who can already just walk in today — with a key, a code or a login that was once issued for a good reason and never taken back. One is about hardware against strangers; the other is about access held by people you once trusted yourself.

How often should I actually change my locks and codes?

Not on a fixed calendar — at each of the five moments in this article: someone leaves, access has never been pruned in people who stay, there was a break-in or near-miss, a contractor's relationship changes, or a seasonal team's contract ends. A venue with a lot of staff turnover realistically hits at least one of those several times a year.

Do I really need to re-secure the whole venue every time one person leaves?

Usually not — the door key and, where relevant, the alarm code are typically enough, unless that person also held the safe combination or other shared access. The point isn't that every departure demands an expensive rebuild; it's that the checklist in the first section above gets run every time, even when the answer is usually "nothing to change".

What if I no longer know who has a key at all?

That's already the answer: start by changing the door key and the alarm code — the two that open the rest of the building — and build the register from this article from that point on, so the question can be answered in seconds next time instead of never.

Can my insurer reject a claim if I don't change the locks in time?

Commercial burglary policies commonly carry a 'reasonable precautions' condition — a duty to take reasonable care of the insured property. On a claim with no sign of forced entry, where access happened with a key or code, an insurer can test that condition and reduce or refuse the claim. There's no single EU-wide figure for how often this happens in practice — check the exact wording in your own policy.

Isn't a digital lock with per-user codes simply the solution?

It makes the fix easier — revoking one code is a click, not a locksmith call — but it doesn't remove the underlying problem on its own. Without a fixed point to review those codes, the same privilege creep builds up digitally that builds up physically: people keep access after the reason for it is gone.

Why does hospitality staff turnover matter so much for this topic?

Because it means the number of people who have ever held access grows faster than in most other sectors. U.S. BLS data has put 'Accommodation and Food Services' at or near the top of every industry's quits rate for years (3.5% in July 2026, against 1.9% for the whole economy), and Eurostat records one of the EU's highest job-vacancy rates for the same sector. Every person who leaves is a new point where access should have changed.