A policy should explain who may hold a key, which approvals are required, how access is recorded and what happens when a key is lost, returned or no longer needed. It should link physical keys, electronic credentials and permissions to documented risk management. It should cover employees, tenants, contractors, suppliers, cleaners, security officers and emergency personnel.