Blog Total Locker Service

Blog storage solutions

Cash Safe Access Control & Governance UK: Keys, Codes, Dual Control and Staff Permissions

Cash safe security depends on more than the safe, lock and cash rating. A business also needs clear rules defining who may access the safe, who may authorise new users, how keys and codes are issued, what happens when staff change roles or leave, when two-person control is required and how emergency access is handled.

This guide focuses specifically on cash-safe access governance for UK businesses. It covers authorised roles, joiners and leavers, physical keys, electronic credentials, two-person access, emergency overrides, temporary permissions, audit responsibility and regular access reviews.

It does not compare key locks with electronic locks as products. For that specification decision, see Key vs Electronic Cash Safes UK.

Quick Answer: What Is Cash Safe Access Governance?

Cash safe access governance is the set of rules that determines who may access a business safe, who can approve that access, how keys or credentials are issued and withdrawn, when two-person control is required, how emergency access is authorised and how permissions are reviewed over time. The objective is to make access deliberate, current and accountable rather than informal or inherited.

Governance questionWhat the business should define
Who may open the safe?Named roles or authorised individuals
Who approves access?Manager, finance lead, owner or nominated authority
How is access issued?Key handover, code assignment or managed credential
What happens when staff leave?Recover keys and revoke or change credentials
When are two people required?Define dual-control activities
How is emergency access handled?Controlled override procedure
Who reviews permissions?Named governance owner
How often are permissions checked?Periodic and event-driven review
A safe-access policy should define authority, lifecycle and accountability as well as the physical credential.

Access Governance Is Different From Lock Choice

Choosing a key lock, electronic keypad or other access method answers one question: how is the safe opened?

Governance answers a different set of questions:

  • Who is allowed to open it?
  • Why do they need access?
  • Who approved that permission?
  • How long should the permission last?
  • What happens when responsibilities change?
  • Who can override normal access?
  • Who checks whether permissions are still appropriate?

A technically strong lock can still be poorly governed if keys circulate without records, shared codes remain unchanged for years or former staff retain access.

This distinction mirrors the wider access-governance structure already used across controlled storage: access should be based on roles, permissions, onboarding, offboarding and override rules rather than merely on possession of a key or code.


Define Authorised Safe Roles

Safe access should follow business responsibility rather than general seniority or convenience.

A business may define roles such as:

  • safe administrator;
  • finance manager;
  • cash-office user;
  • store manager;
  • duty manager;
  • business owner;
  • authorised auditor;
  • emergency-access holder.

Not every role needs the same permission. A member of staff may need to deposit cash without being able to retrieve it. A manager may need normal opening rights but not authority to add new safe users. A finance director may approve access without using the safe personally.

Avoid vague categories

Terms such as “management”, “office staff” or “senior team” can become too broad unless the organisation defines exactly which roles are included.

Where the value or sensitivity justifies it, record access at named-person level rather than relying only on a broad job category.


Give People Only the Access They Need

Safe permissions should match the task being performed.

For example:

  • a cashier may need deposit access only;
  • a shift manager may need retrieval access;
  • a finance manager may need full reconciliation access;
  • a maintenance contractor may need supervised access to the surrounding area but no access to safe contents;
  • an auditor may need records without needing a permanent safe credential.

This prevents access from expanding merely because giving everyone the same key or code is administratively easier.


Who Should Approve Safe Access?

The organisation should identify who has authority to grant safe access.

Depending on the business, approval might sit with:

  • the owner;
  • finance director;
  • finance manager;
  • site manager;
  • security manager;
  • another formally nominated role.

The person issuing a key or creating a code should not have to guess whether somebody is authorised. Approval should already be clear.

Separate approval from administration where appropriate

In larger organisations, one role may approve access while another physically issues keys or manages credentials.

This creates a useful distinction between:

  • authority to decide who should have access; and
  • administration of the key, code or credential.

Safe Access for New Starters and New Role Holders

Safe access should not be issued automatically because somebody joins a department.

Before granting access, confirm:

  • the person’s role;
  • why they need access;
  • who approved it;
  • which safe or safes they may access;
  • whether they need deposit-only or retrieval rights;
  • whether access is permanent or temporary;
  • which key, code or credential will be assigned;
  • what procedure they need to understand before use.

This turns access issuance into a controlled onboarding step rather than an informal handover from one colleague to another.


What Happens When Someone Changes Role?

A person may remain employed while no longer needing safe access.

Examples include:

  • a duty manager moving to another department;
  • a finance administrator changing responsibilities;
  • a temporary supervisor returning to their normal role;
  • a manager transferring to another site;
  • a contractor finishing a project.

Access should therefore be reviewed when roles change, not only when employment ends.

This is consistent with broader access-governance practice, where permissions need active revocation when the business justification ends.


Safe Access When Employees Leave

Offboarding should include safe access wherever the employee held keys, knew codes or had another recognised credential.

For key-based access

  • recover issued safe keys;
  • confirm spare keys are accounted for;
  • investigate missing keys;
  • assess whether the lock needs changing if a key remains uncontrolled.

For code-based access

  • remove the user’s credential where the lock supports individual users;
  • change shared codes known to the departing employee where appropriate;
  • review administrator and master credentials;
  • update access records.

Do not leave access unchanged simply because the person departed on good terms. Governance should depend on current authority, not personal trust.


Governance of Shared Safe Codes

Some safes use a single operational code shared by several authorised users.

Where shared codes are used, define:

  • who is permitted to know the code;
  • who may disclose it;
  • when it must be changed;
  • how changes are communicated;
  • what happens when a user leaves;
  • how emergency access is separated from ordinary access.

Shared codes reduce individual attribution because several people possess the same credential. Where individual-user functionality exists and accountability matters, separate user credentials may be easier to govern.

The technical difference between lock types is covered separately in Key vs Electronic Cash Safes UK.


Governance of Physical Safe Keys

A physical safe key is itself a security credential and should be governed accordingly.

A key-control record may include:

  • key identifier;
  • safe or location;
  • authorised holder;
  • issue date;
  • return date;
  • spare-key location;
  • lost-key incidents;
  • replacement or lock-change action.

Workplace key-management guidance already treats issue, return, storage, logs and periodic review as a complete control process rather than merely a key cabinet problem. The same principle applies to safe keys.

Avoid informal key transfer

An authorised manager should not simply pass a safe key permanently to another member of staff without updating the access record and approval chain.

Otherwise the organisation can lose track of who actually holds the credential.


What Is Dual Control for a Cash Safe?

Dual control means a defined activity requires two authorised people rather than one person acting alone.

The exact mechanism depends on the organisation and safe system. It may involve two credentials, two authorised people being present or a documented two-person procedure.

The governance question is not simply whether the lock supports two inputs. It is which activities the organisation decides should require two-person control.

Activities that may be considered for dual control

  • opening higher-value cash holdings;
  • removing large amounts of cash;
  • cash reconciliation;
  • accessing emergency override credentials;
  • changing administrator credentials;
  • handling particularly sensitive valuables.

Dual control should be proportionate. Requiring two people for every minor petty-cash transaction can make the system unnecessarily difficult to operate.


Designing a Two-Person Safe Procedure

Where two-person control is required, define exactly what both people are responsible for.

  1. Identify the activity requiring two people.
  2. Define which roles may participate.
  3. Confirm whether both need separate credentials.
  4. Define whether both must remain present throughout the activity.
  5. Record the transaction where required.
  6. Define what happens if one authorised person is unavailable.
  7. Define how emergency exceptions are approved.

A two-person rule that exists only informally is difficult to apply consistently. Write the requirement clearly enough that staff know when it starts and ends.


Emergency Access and Safe Overrides

Businesses need a way to deal with legitimate exceptional situations without turning the emergency route into an everyday shortcut.

Emergency access may be needed when:

  • the normal authorised user is unavailable;
  • a credential has failed;
  • a key has been lost;
  • a code has been forgotten;
  • urgent access is required for operational reasons;
  • a security incident requires controlled inspection.

The override procedure should define:

  • who can authorise emergency access;
  • who physically holds the override credential;
  • whether two-person approval is required;
  • how the event is recorded;
  • whether ordinary credentials must be changed afterwards;
  • how the override credential is returned to secure storage.

Override access is an administrative privilege. It should therefore normally be controlled more tightly than ordinary day-to-day access.


Control Emergency and Override Keys Separately

An emergency override key should not simply sit in an unlocked drawer beside the safe.

Consider:

  • separate secure storage;
  • limited named holders;
  • sealed or controlled emergency access where appropriate;
  • recording each use;
  • periodic confirmation that the key remains present;
  • a clear procedure if the override key is lost.

The broader principle is the same as master-key governance elsewhere: management-level credentials require accurate records, secure storage and clear rules defining who may use them and when.


Temporary Safe Access

Temporary access may be required during holidays, sickness, audits, project work or short-term management cover.

Temporary permission should have:

  • a clear reason;
  • an approving authority;
  • a defined start date;
  • a defined end date or review point;
  • the minimum necessary access level;
  • a revocation step when the need ends.

A temporary user should not quietly become a permanent user because nobody remembered to remove the permission later.


Contractors, Engineers and Third-Party Access

Safe engineers, maintenance contractors or other third parties may occasionally require access to the safe or its immediate installation area.

Before granting access, define:

  • what the contractor needs to access;
  • whether safe contents should be removed first;
  • whether a business representative must remain present;
  • whether any credentials must be disclosed;
  • how temporary credentials are revoked afterwards;
  • what records should be retained.

A contractor repairing a hinge or lock does not automatically need unrestricted access to cash or business valuables.


Who Is Responsible for Auditing Safe Access?

The organisation should assign responsibility for checking that safe permissions remain accurate.

Possible owners include:

  • finance;
  • security;
  • facilities;
  • site management;
  • business owner;
  • another nominated control function.

The important point is that responsibility is explicit.

If everybody assumes somebody else checks access, old keys and permissions can remain active indefinitely.


Maintain a Safe Access Register

A simple safe access register can provide a current view of authorised access.

FieldExample
SafeMain office cash safe
UserNamed authorised person
RoleFinance manager
PermissionFull access
CredentialKey 2 or user credential
Approved byFinance director
Start dateDate permission issued
Review dateNext scheduled check
StatusActive, suspended or revoked
The access register should show who is authorised now, not simply who received access historically.

Review Safe Credentials Regularly

Permissions should be reviewed both periodically and when important events occur.

Periodic review

A scheduled review can confirm:

  • current authorised users;
  • current key holders;
  • active electronic credentials;
  • temporary permissions that should have ended;
  • override-key holders;
  • the continued need for each permission.

Event-driven review

Review access immediately after events such as:

  • employee departure;
  • role change;
  • lost key;
  • suspected code disclosure;
  • security incident;
  • safe replacement;
  • lock replacement;
  • departmental restructuring.

This lifecycle approach is consistent with the wider locker and workplace key-governance structure already used elsewhere on the TLS blog.


What Safe Access Records Should Be Kept?

The amount of record keeping should reflect the value and risk involved.

Useful records may include:

  • authorised-user register;
  • safe key issue records;
  • code or credential changes;
  • access approvals;
  • temporary access;
  • emergency override events;
  • lost-key incidents;
  • leaver revocations;
  • access reviews;
  • dual-control transactions where required.

Not every small office needs a complex security database. The record should be proportionate while still allowing the organisation to answer a basic question: who currently has authority to access this safe?


Electronic Audit Trails and Safe Governance

Some electronic locking systems may provide individual credentials or access-event records. Where available, these can support governance by providing evidence of use.

However, an electronic audit trail does not replace policy.

The organisation still needs to decide:

  • who receives credentials;
  • who reviews access records;
  • what constitutes an unusual event;
  • how long relevant records are retained;
  • what action follows a suspicious access event.

Technical logging is useful only when somebody is responsible for interpreting and acting on it.


Separation of Duties

Where cash values or business risk justify it, consider whether one person should control every stage of the process.

Roles might be separated between:

  • cash collection;
  • safe access;
  • cash counting;
  • reconciliation;
  • banking preparation;
  • access approval;
  • access auditing.

The appropriate level of separation depends on the size of the organisation and the value being managed.

A small owner-managed business may legitimately have one person fulfilling several roles. A larger cash operation may require stronger separation and dual control.


Separate Deposit Permission From Retrieval Permission

Deposit safes provide a clear example of permission separation.

A cashier may need to place money into secure storage without needing authority to remove previous deposits.

This can create different access groups:

  • deposit-only users;
  • retrieval users;
  • reconciliation users;
  • administrators;
  • emergency-access users.

For the physical deposit-safe process, see Deposit Safes UK.


Safe Governance Across Multiple Sites

Businesses with several premises should decide which access decisions are local and which are controlled centrally.

A multi-site model may define:

  • central policy;
  • local authorised-user lists;
  • site-level approval limits;
  • central control of emergency credentials;
  • standard joiner and leaver procedures;
  • common review intervals;
  • escalation for lost keys or compromised credentials.

Standardisation can make governance easier, but each site may still need different authorised roles because cash handling differs between locations.


Common Cash Safe Governance Failures

  • Everyone in management knows the code: access becomes broader than the business need.
  • Former employees still know active credentials: leaver access was never revoked.
  • Keys are passed between staff informally: the organisation loses track of the holder.
  • No one owns the access register: permissions become outdated.
  • Override keys are kept beside the safe: emergency access becomes an easy bypass.
  • Temporary users become permanent by accident: no end date or review was set.
  • One person can approve and conceal all activity: separation or dual control may be needed for higher-risk processes.
  • Codes never change: historical users may retain knowledge indefinitely.
  • Two-person control is vaguely defined: staff apply the rule inconsistently.
  • Electronic logs exist but nobody reviews them: technical evidence provides little governance value.

Cash Safe Access Governance Checklist

  1. Identify every business safe covered by the policy.
  2. Define authorised roles for each safe.
  3. Define who approves new access.
  4. Record current authorised users.
  5. Record physical safe keys and their holders.
  6. Define how electronic credentials are issued.
  7. Define joiner access procedures.
  8. Define role-change procedures.
  9. Define leaver revocation procedures.
  10. Define temporary-access rules.
  11. Define contractor access.
  12. Define whether deposit-only access exists.
  13. Define when dual control is required.
  14. Define emergency-access authority.
  15. Secure override keys or administrator credentials.
  16. Assign responsibility for access reviews.
  17. Set a periodic review interval.
  18. Trigger additional reviews after security events.
  19. Record lost keys and compromised credentials.
  20. Document changes to access permissions.

Cash Safe Access Governance FAQs

Who should be allowed to access a business cash safe?

Access should be limited to people whose current role genuinely requires it. The organisation should define authorised roles or named users rather than allowing access simply because somebody is senior or works in the same department.

Should safe access be removed when an employee leaves?

Yes. Recover physical keys and revoke, remove or change electronic credentials as appropriate to the safe and access system.

Should access be reviewed when someone changes role?

Yes. A person may remain employed while no longer needing safe access. Permissions should follow current responsibility rather than employment status alone.

What is dual control for a cash safe?

Dual control means a defined safe activity requires two authorised people rather than one person acting alone. The exact procedure depends on the organisation and safe system.

Should every safe require two-person access?

No. Dual control should be proportionate to the value, risk and business process. It may be appropriate for higher-value retrieval or administrator functions but excessive for ordinary low-value petty-cash access.

Who should hold an emergency override key?

The business should nominate a limited authorised role and store the override credential securely. It should not normally be available as an informal everyday alternative to normal access.

Should safe codes be changed when staff leave?

If a departing employee knows an active shared code, review whether that code should be changed. Individual credentials should be revoked where the system supports them.

Do businesses need a safe access register?

A simple register is useful where several people or credentials are involved because it provides a current record of authorised access, approval and review status.

How often should safe access permissions be reviewed?

Use a periodic review appropriate to the business and also review access after events such as departures, role changes, lost keys, compromised credentials or security incidents.

Can cashiers deposit money without having retrieval access?

Yes, where the safe design supports separate deposit access. This allows staff to place cash into secure storage without giving them authority to retrieve accumulated takings.


Treat Safe Access as a Permission Lifecycle

Cash-safe governance should answer more than who currently has a key or knows the code. It should define why each person has access, who approved it, how long it should last, what happens when responsibilities change and how emergency access is controlled.

Good governance therefore follows a lifecycle: approve access, issue the credential, use it under defined rules, review it periodically and revoke it when the business need ends.

For higher-value or more sensitive cash processes, add dual control, separation of duties and tighter override management where proportionate. The goal is not maximum administrative complexity. It is to ensure that safe access remains deliberate, current and accountable throughout the life of the system.


Discover more from Blog Total Locker Service

Subscribe to get the latest posts sent to your email.