In this article
Someone leaves, and the checklist is clear: uniform back, storeroom key back, final paycheck. Nowhere on that list is the front-door key, the alarm code, the safe combination, or the password to the delivery app — and that isn't because nobody thinks of it. It's because that list never existed.
Of every kind of small business, a restaurant hands out the most keys to the least stable team. A typical venue issues a door key, an alarm code, sometimes a safe combination, a POS login and a login for the delivery tablet to everyone working the evening shift — and the evening shift is exactly the team that turns over fastest.
That isn't a gut feeling. The U.S. Bureau of Labor Statistics tracks how many people voluntarily leave their jobs by sector through its JOLTS survey, and "Accommodation and Food Services" has sat at or near the top for years: in July 2026 the sector's quits rate stood at 3.5%, against 1.9% for the U.S. economy as a whole — nearly double. Across all of 2025, the same BLS data put the sector's full-year turnover rate at 65.5%, and the 2001-to-present average is 75.6%, against 43.4% for the broader economy over the same period.
Europe doesn't publish a single continent-wide figure to match, but the direction is the same: Eurostat records one of the highest job-vacancy rates of any sector for accommodation and food service activities — 3.0% EU-wide, 3.2% in the euro area — the same signal of a sector where roles are constantly being refilled. Translate that into a 20-person team and you get roughly a dozen people a year who once held a key, a code or a login and are no longer on the rota.
This article walks through five concrete moments when that access should change and, in practice, usually doesn't: someone leaving, access quietly building up in people who stay, a break-in or a near-miss, a contractor relationship changing, and a seasonal wave that removes a dozen keyholders inside two weeks. Then it works out what doing it properly actually costs — and what not doing it costs instead.
5 moments when access should change
None of these five is rare. Four of them happen in most venues several times a year. The problem isn't that the moment goes unnoticed — it's that nothing fixed starts happening when it arrives.
1. A keyholder leaves
Fired, resigned, or simply stopped showing up — for this checklist it makes no difference. The moment anyone with access leaves, there's a list that has to close that same evening, not "soon":
The door key — collected, or if that fails, the cylinder replaced. The alarm code — changed outright, not just deleted for that one user. The safe combination — if it's shared rather than individual, it always has to change in full. The POS login — one account per staff member makes this a click instead of a rebuild. The delivery app or tablet — a shared device logged into one account is exactly the leak nobody thinks of. Any shared password — the Wi-Fi, the accounting system, the banking app if it was ever set up on a personal phone.
The pattern behind a missed step is almost always the same: someone leaves on good terms, so nobody feels the urgency. That is exactly why this list shouldn't depend on how the departure went — it's a checklist that runs identically every time, whether someone left with a handshake or with a solicitor's letter.
2. Access quietly builds up in people who stay
IT security has a name for this: privilege creep — rights someone once needed temporarily and that are never taken back, until an account can do far more than the job ever asked for. A restaurant runs through exactly the same mechanism physically. A long-serving server gets a personal key "just in case" while the owner is on holiday. The holiday ends; the key doesn't. A shift lead is trusted with the safe code on one busy night and simply keeps it after.
Nobody ever makes a conscious decision to allow this — it just never gets undone. The result, a few years in, is a team where the number of people with full access has stopped tracking the number of people who actually need it, and where nobody quite remembers who's in the first group any more.
IT security's answer to privilege creep is a periodic access review: on a set schedule, explicitly check who can do what and actively decide whether that's still warranted. The same discipline works just as well here, and it costs no software — just a fixed point on the calendar where someone asks the question instead of assuming last year's answer still holds.
3. After a break-in, even without a loss
An attempt that took nothing feels like nothing happened. For the access that was visible that night, it isn't: any key or code that could have been seen, photographed or copied has to change, whether or not anything was actually taken.
There's also a purely financial reason not to put this off. Commercial burglary and theft policies commonly carry a "reasonable precautions" condition — a duty to take reasonable care of the insured property. QBE's own burglary policy wording states it plainly: the insured must take "all reasonable precautions" for the safety of the property covered. Legal firm Clyde & Co notes the test applied is what "the ordinary reasonable man in the position of the insured would have considered as adequate" — and a claim can be reduced or rejected if that condition wasn't met.
For consumer-facing policies the mechanism is spelled out even more directly: if an intruder gets in using a key and there's no sign of forced entry, a claim can be rejected outright, and some policies make changing the locks after a loss or theft an explicit condition of continued cover (Compare the Market, UK). There's no single EU-wide figure for how many commercial hospitality policies carry a clause like this — check your own policy — but the practice is common enough that it should never be treated as hypothetical.
4. A contractor relationship changes
A cleaning crew, a pest-control technician, a refrigeration maintenance firm — each of them gets a key for outside opening hours at some point, and that relationship changes more often than the key itself does. The contract ends, the regular technician is replaced by a colleague, the company is bought out by another one — and the key handed over three years ago simply stays in circulation.
One case specific to this decade: a delivery driver issued a back-door key during a busy delivery period so cold deliveries could be made outside normal hours, and that key never collected back once the arrangement ended or moved to a different platform. It's exactly the kind of access that shows up on no paperwork at all, because it was granted outside the normal staffing cycle.
The rule of thumb is simple: every time a contract ends, changes hands or changes provider is the moment to ask who still holds a key for it — not the day someone happens to remember.
5. A seasonal wave sweeps through the team
Where the first four moments touch one person at a time, this one touches a dozen at once. At the end of a terrace season or a student summer, seasonal and flexi-job staff often leave within two weeks of each other, and that's exactly when it becomes clear how much access was handed out in that short window: alarm codes given to everyone because it was faster than setting up individual ones, a shared POS login for the extra weekend team, a storeroom key handed to three students at once.
That very peak is why a delayed review is the most expensive kind: a dozen people leaving at the same time means a dozen repeats of the same question, "does this person still hold anything?" — and in practice that question usually never gets asked at all, because attention has already moved to the next rota rather than the last one.
Anyone who wants to fix this structurally schedules the access check as part of the seasonal plan itself — the same date the off-season rota gets drawn up is the natural moment to close out peak-season access. In Belgium, where flexi-job staff are common, that moment comes round several times a year as a matter of course.
What it actually costs — and what not doing it costs
The resistance to any of this is almost never principle — it's the assumption that changing locks is expensive and slow. For most of the steps above, that isn't true.
Changing an alarm code or a POS login costs nothing and takes a few minutes at most: it's software, not hardware. Even a physical lock isn't a large expense. UK locksmith network Keytek's own 2026 price guide puts changing one standard lock at £125–£185 and a high-security lock at £150–£185; changing every lock on a property starts, per the same guide, "from £350", typically two to four hours of work. Those are UK prices — most EU countries land in a broadly similar range, a few hundred euros for a whole venue, so ask your own locksmith for the exact figure.
Five points on the same scale — from changing a code to the bill for a single break-in.
The break-in bill (€8,659) is the worked example from the cost of a break-in on this site: cash, drink stock and equipment, repairs, spoilage and revenue lost over a day and a half. The calculator there lets you repeat that same breakdown with your own numbers. The lock prices come from Keytek (UK, 2026 price guide); ask your own locksmith for the local figure.
How exposed are you right now?
No exact number — that would fake a precision this subject doesn't have. Three questions instead, that together give an honest read on how urgent this is for your venue.
Exposure check
Three questions, no account, nothing sent or stored.
This is an honest-enough rule of thumb, not a security audit. Your own insurer, your own policy and your own premises remain the final word.
How access builds up when nobody revokes it
For a 20-person team at the annual turnover rate cited above — 65.5% (BLS, 2025) — that's just over thirteen people over a typical year. Anyone who never revokes access simply watches that number pile up, spike included around September when a student season typically winds down.
The same 20-person team, over twelve months. Above: how many people with still-valid access pile up if nobody revokes it. Below: the same departures, closed out the same week every time.
An illustrative example based on a 20-person team at the BLS's own 65.5% annual turnover figure for 2025 in U.S. hospitality — the exact monthly spread varies by venue, the end-of-season spike usually doesn't.
One page for before it happens
Everything above gets easier with one standing document: a key register. No software, no subscription — one page of who holds what, since when, and when it was last checked. Print it and pin it by the safe, or keep it as a shared document reviewed once a month.
The point of the page isn't that it's kept perfectly from day one — it's that there's a fixed place where the question "who still has access to this?" can be answered in five seconds, instead of ten phone calls.
| Who | Access to | Since | Last checked |
|---|---|---|---|
| Owner | Door key · alarm code · safe · bank | Opening | — |
| Head chef | Door key · alarm code | Hire date | — |
| Floor shift lead | Alarm code · POS login | Promotion | — |
| Cleaning crew (contractor) | Door key (back entrance) | Contract start | — |
Four example rows to start from — fill in your own team and update the page on the same day as the seasonal rota, and every time someone leaves.
The key is the forgotten step, not the hard one
Nothing in this article asks for a new system, a subscription or an investment. It asks for five moments that are already happening — a departure, a long tenure, a break-in or a near-miss, a contractor changing hands, a seasonal turnover — to be recognised, each paired with the same short checklist every time.
The reason this gets skipped so often isn't reluctance. It's that there was never a fixed routine for it, while there has always been one for the uniform and the final paycheck. One register and five recognisable moments are enough to close that gap.
Pair this with a level-headed look at burglary deterrents and your own policy's small print, and both sides of the same question are covered: what happens if someone gets in anyway, and who can already just walk in today.