How Do I Prove Who Accessed a Building? 

by | 2. September 2026 | News

An electronic access control system with logging is what makes this provable. It creates a searchable, time-stamped audit trail showing who used which credential, at which door, and when, something a mechanical key system simply cannot produce. Whether the system actually delivers this in practice depends on how it’s configured and how long the data is kept. 

It’s the question that comes up after the fact, not before. A contractor’s badge goes missing. An item disappears from a stockroom. An insurer asks for evidence following a claim. Someone, somewhere, needs a straight answer to “who was in that area, and when,” and reaching for a paper sign-in sheet or a vague memory of who had keys that week isn’t going to satisfy anyone asking the question formally. One UK university found out the hard way what happens without an answer: a lost master key to a scientific research centre meant the entire system had to be rekeyed, at a cost of £50,000. In SimonsVoss’s own survey of facilities and security professionals, 39% said they couldn’t produce an audit trail showing who accessed specific areas and when. That’s not a small gap. It’s the difference between answering a question and rekeying a building. 

What a Proper Audit Trail Actually Captures 

A mechanical key system can tell you almost nothing after the fact. A key either works or it doesn’t, and once it’s been cut, copied or handed to a contractor, there’s no record of who used it, where, or when. If a key goes missing, the only real fix is rekeying the whole system, which is expensive and disruptive. 

The speed difference shows up the moment something goes wrong. On a properly configured online access control system, blocking a lost card and issuing a replacement typically takes about three clicks. On an offline system covering a larger estate, the same job can mean physically visiting every lock, which on an 80-door site can take around two hours. With a mechanical master key, there’s often no equivalent short version at all, only a full rekey. 

An electronic access control system replaces that with a structured log. Done properly, it captures: 

  • Who. The specific credential (a card, fob, PIN or mobile key) tied to a named individual, not a generic master key shared by a dozen people. 
  • Where. The exact door or zone the credential was used at, down to individual rooms if the system is set up that way. 
  • When. A precise, accurate timestamp for every access event, not just an approximate window. 
  • Whether it was expected. Access outside normal hours or patterns can be flagged, rather than sitting unnoticed in a log nobody checks. 

This is the baseline. Without it, “prove who accessed the building” isn’t really answerable, no matter how good your locks are. 

Why Data Retention Is the Gap Nobody Plans For 

Capturing the data is only half the job. The other half is keeping it long enough to be useful, and this is where SimonsVoss’s survey found a bigger gap: 46% of facilities and security professionals said they cannot search or retain access data for a meaningful period. 

There’s no single fixed retention period set out in UK law for access control logs. What does apply is UK GDPR’s storage limitation principle, which requires organisations to keep personal data only as long as necessary for the purpose it was collected for, and to be able to justify that period if asked. In practice, that means the right retention window depends on what the data is for: a short window might cover routine building management, but investigations, insurance claims and safeguarding reviews often surface weeks or months after the event in question. If the data’s already been overwritten by then, it doesn’t matter how good the system was on day one. 

A searchable archive that only goes back a few days isn’t really an audit trail. It’s a temporary log that happens to be useful if you’re lucky with timing. The storage limitation principle cuts both ways too: once data has served its purpose and the retention period has passed, it should be securely deleted rather than left to accumulate indefinitely. A system that can’t do either, keep data long enough or dispose of it properly, creates risk at both ends. 

Where This Actually Matters 

This isn’t a hypothetical compliance exercise. It shows up in ordinary situations that most estates and facilities teams deal with at some point: 

Security incidents. Theft, vandalism or unauthorised entry all raise the same first question: who had access to that area, and when. Without a searchable log, the answer starts with a shrug. 

Contractor and visitor access. Contractors, cleaners and temporary staff often need short-term access to specific areas. When something goes wrong during that window, being able to pull an exact record of who was where matters far more than remembering who was booked in. 

Staff turnover. People leave, change roles, or lose credentials. A clear log shows exactly when access was revoked and whether it was used after that point, which protects the organisation as much as it protects the departing employee. 

Insurance claims. Insurers increasingly ask for evidence of access control and monitoring after a claim, not just confirmation that a system exists. A documented, searchable audit trail is what turns “we had security measures in place” into something an insurer can actually verify. 

Martyn’s Law readiness. For organisations already reviewing their access control approach ahead of Martyn’s Law, an audit trail is one of the clearest, most concrete things to get right. Under the Act’s Enhanced Tier, premises expecting 800 or more people are expected to carry out formal risk assessments and put in place reasonably practicable physical security measures. A searchable, time-stamped record of who accessed what is direct, demonstrable evidence that those measures actually work, not just that they exist on paper. 

Board and governance reporting. This is often the version of the question that actually gets budget released. Facilities managers are frequently the influencers rather than the final decision-makers, and getting sign-off from senior leadership depends on being able to answer a different, harder set of questions: can you demonstrate that permissions align with defined roles? Can you evidence that access is revoked immediately when it should be? Can you produce a searchable audit trail on demand, in front of a board, a regulator or an auditor? An access control system that only answers “did the door open” doesn’t help here. One that produces a clear, searchable record does. 

IT and infrastructure oversight. For IT managers increasingly involved in access control decisions, the audit trail itself is data that needs to be handled properly: stored securely, access to the logs restricted and recorded, and the system able to sit alongside existing infrastructure rather than as an isolated island. An audit trail that isn’t itself secure and well-governed undermines the case it’s meant to support. 

How SimonsVoss Systems Support This 

This is exactly what SimonsVoss’s software platforms are built to provide. Access events are logged centrally against named credentials, giving estates and facilities teams a searchable record rather than a scattered set of assumptions. Permissions can be set, changed or revoked instantly when someone leaves or a credential is lost, and that change is itself recorded. Retention settings can be configured to match what the organisation actually needs, rather than defaulting to whatever the system happens to store by default. 

The result is a system that answers “who accessed this building, and when” as a straightforward search, not a project. 

FAQ 

How long should access data be retained? 

There’s no single legal minimum or maximum. UK GDPR requires you to keep data only as long as necessary for a documented, justifiable purpose, which for most organisations means balancing routine storage costs against the realistic time it takes for an incident, claim or investigation to surface. Many organisations retain access logs for several months to a year, but the right period depends on your sector, risk profile and any specific compliance requirements that apply to you. 

Can this data be used as evidence? 

Access control logs can support an investigation or claim, but their evidential weight depends on the integrity of the system: accurate timestamps, credentials tied to named individuals, and a clear record of who can access and edit the logs themselves. A system that’s well configured and consistently used is far more useful as evidence than one bolted on as an afterthought. 

What’s the difference between logging and monitoring? 

Logging is the record itself, the who, where and when of every access event, stored for later review. Monitoring is watching that activity in real time, or setting up alerts for unusual patterns as they happen. A good access control system does both, but logging is the non-negotiable foundation. You can’t monitor effectively, or investigate after the fact, without a complete log to work from. 

 

If you’d like a wider view of how this fits into a broader access control strategy, our digital locking systems for compliance-ready buildings page covers the core capabilities, audit trails included, that estates and facilities teams should expect as standard. And if you’re specifically weighing this up against Martyn’s Law, our piece on whether wireless locking complies with Martyn’s Law covers the tiered requirements and where the common compliance gaps sit. 

Not ready to talk to a person yet? Get the Access Control Readiness Checklist first. It’s a practical, non-technical walkthrough covering access control, monitoring, staff training and audit-trail readiness, built to help you see exactly where your current setup stands before you make any changes. 

Ready to see where your current setup stands? Speak to our UK team about audit-trail capability and what “meaningful retention” should look like for your estate. 

An electronic access control system with logging is what makes this provable. It creates a searchable, time-stamped audit trail showing who used which credential, at which door, and when, something a mechanical key system simply cannot produce. Whether the system actually delivers this in practice depends on how it’s configured and how long the data is kept. 

It’s the question that comes up after the fact, not before. A contractor’s badge goes missing. An item disappears from a stockroom. An insurer asks for evidence following a claim. Someone, somewhere, needs a straight answer to “who was in that area, and when,” and reaching for a paper sign-in sheet or a vague memory of who had keys that week isn’t going to satisfy anyone asking the question formally. One UK university found out the hard way what happens without an answer: a lost master key to a scientific research centre meant the entire system had to be rekeyed, at a cost of £50,000. In SimonsVoss’s own survey of facilities and security professionals, 39% said they couldn’t produce an audit trail showing who accessed specific areas and when. That’s not a small gap. It’s the difference between answering a question and rekeying a building. 

What a Proper Audit Trail Actually Captures 

A mechanical key system can tell you almost nothing after the fact. A key either works or it doesn’t, and once it’s been cut, copied or handed to a contractor, there’s no record of who used it, where, or when. If a key goes missing, the only real fix is rekeying the whole system, which is expensive and disruptive. 

The speed difference shows up the moment something goes wrong. On a properly configured online access control system, blocking a lost card and issuing a replacement typically takes about three clicks. On an offline system covering a larger estate, the same job can mean physically visiting every lock, which on an 80-door site can take around two hours. With a mechanical master key, there’s often no equivalent short version at all, only a full rekey. 

An electronic access control system replaces that with a structured log. Done properly, it captures: 

  • Who. The specific credential (a card, fob, PIN or mobile key) tied to a named individual, not a generic master key shared by a dozen people. 
  • Where. The exact door or zone the credential was used at, down to individual rooms if the system is set up that way. 
  • When. A precise, accurate timestamp for every access event, not just an approximate window. 
  • Whether it was expected. Access outside normal hours or patterns can be flagged, rather than sitting unnoticed in a log nobody checks. 

This is the baseline. Without it, “prove who accessed the building” isn’t really answerable, no matter how good your locks are. 

Why Data Retention Is the Gap Nobody Plans For 

Capturing the data is only half the job. The other half is keeping it long enough to be useful, and this is where SimonsVoss’s survey found a bigger gap: 46% of facilities and security professionals said they cannot search or retain access data for a meaningful period. 

There’s no single fixed retention period set out in UK law for access control logs. What does apply is UK GDPR’s storage limitation principle, which requires organisations to keep personal data only as long as necessary for the purpose it was collected for, and to be able to justify that period if asked. In practice, that means the right retention window depends on what the data is for: a short window might cover routine building management, but investigations, insurance claims and safeguarding reviews often surface weeks or months after the event in question. If the data’s already been overwritten by then, it doesn’t matter how good the system was on day one. 

A searchable archive that only goes back a few days isn’t really an audit trail. It’s a temporary log that happens to be useful if you’re lucky with timing. The storage limitation principle cuts both ways too: once data has served its purpose and the retention period has passed, it should be securely deleted rather than left to accumulate indefinitely. A system that can’t do either, keep data long enough or dispose of it properly, creates risk at both ends. 

Where This Actually Matters 

This isn’t a hypothetical compliance exercise. It shows up in ordinary situations that most estates and facilities teams deal with at some point: 

Security incidents. Theft, vandalism or unauthorised entry all raise the same first question: who had access to that area, and when. Without a searchable log, the answer starts with a shrug. 

Contractor and visitor access. Contractors, cleaners and temporary staff often need short-term access to specific areas. When something goes wrong during that window, being able to pull an exact record of who was where matters far more than remembering who was booked in. 

Staff turnover. People leave, change roles, or lose credentials. A clear log shows exactly when access was revoked and whether it was used after that point, which protects the organisation as much as it protects the departing employee. 

Insurance claims. Insurers increasingly ask for evidence of access control and monitoring after a claim, not just confirmation that a system exists. A documented, searchable audit trail is what turns “we had security measures in place” into something an insurer can actually verify. 

Martyn’s Law readiness. For organisations already reviewing their access control approach ahead of Martyn’s Law, an audit trail is one of the clearest, most concrete things to get right. Under the Act’s Enhanced Tier, premises expecting 800 or more people are expected to carry out formal risk assessments and put in place reasonably practicable physical security measures. A searchable, time-stamped record of who accessed what is direct, demonstrable evidence that those measures actually work, not just that they exist on paper. 

Board and governance reporting. This is often the version of the question that actually gets budget released. Facilities managers are frequently the influencers rather than the final decision-makers, and getting sign-off from senior leadership depends on being able to answer a different, harder set of questions: can you demonstrate that permissions align with defined roles? Can you evidence that access is revoked immediately when it should be? Can you produce a searchable audit trail on demand, in front of a board, a regulator or an auditor? An access control system that only answers “did the door open” doesn’t help here. One that produces a clear, searchable record does. 

IT and infrastructure oversight. For IT managers increasingly involved in access control decisions, the audit trail itself is data that needs to be handled properly: stored securely, access to the logs restricted and recorded, and the system able to sit alongside existing infrastructure rather than as an isolated island. An audit trail that isn’t itself secure and well-governed undermines the case it’s meant to support. 

How SimonsVoss Systems Support This 

This is exactly what SimonsVoss’s software platforms are built to provide. Access events are logged centrally against named credentials, giving estates and facilities teams a searchable record rather than a scattered set of assumptions. Permissions can be set, changed or revoked instantly when someone leaves or a credential is lost, and that change is itself recorded. Retention settings can be configured to match what the organisation actually needs, rather than defaulting to whatever the system happens to store by default. 

The result is a system that answers “who accessed this building, and when” as a straightforward search, not a project. 

FAQ 

How long should access data be retained? 

There’s no single legal minimum or maximum. UK GDPR requires you to keep data only as long as necessary for a documented, justifiable purpose, which for most organisations means balancing routine storage costs against the realistic time it takes for an incident, claim or investigation to surface. Many organisations retain access logs for several months to a year, but the right period depends on your sector, risk profile and any specific compliance requirements that apply to you. 

Can this data be used as evidence? 

Access control logs can support an investigation or claim, but their evidential weight depends on the integrity of the system: accurate timestamps, credentials tied to named individuals, and a clear record of who can access and edit the logs themselves. A system that’s well configured and consistently used is far more useful as evidence than one bolted on as an afterthought. 

What’s the difference between logging and monitoring? 

Logging is the record itself, the who, where and when of every access event, stored for later review. Monitoring is watching that activity in real time, or setting up alerts for unusual patterns as they happen. A good access control system does both, but logging is the non-negotiable foundation. You can’t monitor effectively, or investigate after the fact, without a complete log to work from. 

 

If you’d like a wider view of how this fits into a broader access control strategy, our digital locking systems for compliance-ready buildings page covers the core capabilities, audit trails included, that estates and facilities teams should expect as standard. And if you’re specifically weighing this up against Martyn’s Law, our piece on whether wireless locking complies with Martyn’s Law covers the tiered requirements and where the common compliance gaps sit. 

Not ready to talk to a person yet? Get the Access Control Readiness Checklist first. It’s a practical, non-technical walkthrough covering access control, monitoring, staff training and audit-trail readiness, built to help you see exactly where your current setup stands before you make any changes. 

Ready to see where your current setup stands? Speak to our UK team about audit-trail capability and what “meaningful retention” should look like for your estate.