A family stays in a villa for a few days, staff enter on certain mornings, and a maintenance contractor has a specific appointment. This is an illustrative scenario: giving everyone the same key or code makes the permissions hard to distinguish. Temporary access defines who may enter, through which entrance and for how long, where the installed system supports those controls.
Every permission should answer four questions
Before opening the management dashboard, write down the recipient, entrances, validity period and person approving the permission. “Staff” is too broad: someone looking after the garden may have no reason to enter bedrooms. A reservation should not automatically grant access to every part of a property.
A simple operational list might look like this:
- Guest: the agreed route from the entrance to the accommodation, for the authorised period.
- Cleaning staff: the necessary entrances within agreed working windows.
- Maintenance contractor: the entrance relevant to the job, for the appointment's duration.
- Manager: individually assigned administrative functions, with an identified deputy.
These are roles to discuss, not a configuration suitable for every property. Account for shared routes, actual schedules and exit arrangements when deciding them.
Credentials, invitations and validity are different
A code received to activate an app may be an invitation, rather than a code to enter at the door. Nuki's user-management guidance, for example, distinguishes redeeming an invitation from subsequently managing permissions. The deadline for redeeming an invitation is not the same as the duration of the resulting access.
Confirm which method the person will use: app, keypad or card, depending on the system. Explain where it works and how to obtain help. Send credentials to the agreed recipient, avoiding large groups or messages reused between bookings. If someone forwards a shareable code, the device does not necessarily establish who physically used it.
Time windows: check the clock too
Some systems provide weekly schedules and restrictions on individual functions. The 2N Access Unit time-profile manual, for example, describes restrictions on codes and cards and stresses correct date and time settings. Do not assume every product offers these functions.
During acceptance testing, check the start and end of permission, the time zone and the system's daylight-saving arrangements. Test entry before, during and after the agreed window. For shifts crossing midnight, establish exactly which days and intervals apply. A correct-looking calendar on screen needs to produce the intended behaviour at the entrance.
Revoked in the dashboard or received by the lock?
An administrative change and its application on the device are separate steps to verify. Nuki's API documentation states that an offline device cannot be reached through that API. This illustrates why immediate remote changes should not be promised without checking connectivity and the selected system's synchronisation mechanism.
An expiry already stored locally may behave differently from a revocation just requested through the cloud. Do not infer the behaviour from the word “smart”. Ask what is stored on the device, what needs connectivity, and how an update is confirmed. If urgent action is needed while the connection is down, agree on a procedure with the person responsible on site.
The acceptance test
Use test credentials and authorised participants, keeping a safe alternative access method available. Record at least these results:
- The permission covers only the intended entrances, excluding other entrances controlled by the installation.
- The credential works within its assigned period and is rejected outside it, as configured.
- Revocation is confirmed as applied to the device, and a further entry attempt has the expected result.
- Internet loss has documented consequences for existing permissions and new changes.
- A lost phone, missing card or changed shift can be handled without sharing the administrator account.
Complete the process after each stay or visit
Assign the final check to one person: review permissions still active, remove those no longer needed and record authorised exceptions. Access logs may help with administration, but they do not automatically turn a code into proof of identity. For accommodation arrivals, the procedure described in our guide to check-in in Italy in 2026 remains a separate task.
Our smart access service starts with actual roles and entrances. On a vessel, smart yacht solutions need a dedicated assessment of the environment, power, connectivity and onboard systems. A solution suited to a villa is not automatically suited to marine use.
Contextual image: the marina does not represent an R3D LINK customer or installation.


