Restricted Key System Blanks For Commercial Accounts
Why this matters
A restricted-key program is the contract that turns a high-security cylinder into an actual security feature. The locksmith who sells the cylinder without setting up the restricted-key contract has sold the customer a mechanical drill-and-pick deterrent, not a controlled-access system. Commercial accounts (office towers, healthcare, multi-family residential, schools, government) live on the restricted-key program: every key issued is logged, every key cut is authorized by a named signatory, and every rekey is traceable. This article gives the contract structure, the signatory protocol, and the lifecycle reality that makes restricted keys work.
What "restricted" actually means
A restricted blank is distributed only through authorized dealers, under contract, to customers who have signed an end-user agreement. Three combined protections operate together: patent protection prevents legitimate manufacture of duplicate blanks during the patent term; dealer distribution control limits blank flow to dealers under a manufacturer agreement (cross-shipping prohibited); and end-user signatory authorization gates every cut. An unauthorized person must compromise the dealer or the signatory to obtain a duplicate key. The cylinder face resists picking and drilling; the contract resists the more likely attack of someone walking into a shop with the original key.
The contract structure
A typical commercial restricted-key program has four documents: manufacturer-to-dealer authorization (dealer signs a distribution agreement with the manufacturer); dealer-to-end-user authorization (end user names authorized signatories and the keying records assigned to their account); signatory authorization card per signatory (each named signer provides a signature card on file); and the key issue log (every blank cut logged with date, key code, recipient, signatory who authorized, and running serial). The log is the operational deliverable the facility manager checks during audits, after employee terminations, and during compliance reviews.
Selecting signatories
The customer is asked to name signatories at contract setup. Two to four signatories is typical for a single-building customer; more signatories spreads the authorization burden but increases compromise surface. Signatories should be roles ("Director of Facilities," "VP of Operations," "Building Owner") not specific names - when the role changes hands, the customer updates the signature card without restructuring the program. At least one signatory should not be the office manager who handles day-to-day key requests; the intent is to make casual blanket authorization harder. Signatories are named in writing on company letterhead, with signatures on file in the dealer's program binder.
Key code assignment
Each key has a code identifying its bitting and its place in the master-key hierarchy. The Top Master Key (TMK) opens every cylinder in the system. Master keys open subsets defined by the hierarchy (one master per building or per department). Change keys open one cylinder or one small group. A typical program might have one TMK, three masters, and 150 change keys. The keying records map every change-key code to a cylinder location (room, door, equipment ID); the locksmith maintains the records and the customer keeps a copy.
Lifecycle - the year-one through year-ten reality
Year 0 - install. Dealer installs cylinders, cuts the initial key complement, delivers keying records. Signatory contracts in place.
Year 1 to 3 - light maintenance. Lost keys are reissued under signatory authorization. Occasional cylinder rekey for departing employees. Adds for new spaces follow the existing hierarchy.
Year 4 to 7 - personnel turnover. Signatories change as the customer's organization changes. The dealer updates signature cards. A few cylinders are rekeyed each year. Lost masters trigger a partial-system rekey.
Year 7 to 10 - patent expiration approach. The current generation may be approaching expiration. The dealer briefs the customer on migration options.
Year 10+ - migration or accept aftermarket. After patent expiration, blanks become available to unauthorized cutters. The customer either migrates to a new restricted platform or accepts that key control is now contract-based and dealer-monitored only.
Lifecycle cost framing
The customer conversation focuses on lifecycle cost, not per-key cost. A large office may issue 200 keys over five years and rekey 10 cylinders. The restricted program's overhead is a fraction of one rekey cycle on a non-restricted system that turned over because an unauthorized duplicate appeared. The locksmith's role is to surface this math during the spec conversation. A customer who only sees the per-cut difference will reject the program for the wrong reason.
Signatory compromise protocol
When a signatory is terminated, retires, or otherwise leaves: customer notifies dealer in writing; dealer removes signatory authorization immediately; if the departed signatory had personally received keys that grant broad access (master or higher), partial-system rekey is the recommended remediation; new signatory authorization is processed. The remediation rekey is part of the lifecycle expectation. Customers who refuse to rekey after a signatory departure have decided that the financial cost is not justified by the access risk - document the recommendation and the refusal in writing.
A dealer who cuts a blank for an end-user account without verified signatory authorization has voided their distribution agreement and possibly the customer's key-control program in a single transaction. The signatory authorization protocol is the dealer's professional discipline as much as it is the customer's security control. A "we'll get the signature later" cut is the wrong move every time.
Customer onboarding checklist
Customer agreement signed by named signatories; signatory cards on file with the dealer; key issue log initialized; keying records (cylinder location to change-key code map) delivered in printed and digital form; replacement-and-rekey expectations documented; annual signatory verification cadence set.
When to walk away
Three configurations where the program will not work: customer refuses to name signatories or wants "anyone in the front office" to authorize cuts (the program collapses to commodity-blank equivalence); customer is rapid-turnover hospitality or short-term rental (restricted programs assume a stable signatory base); customer's facilities staff includes a person known to authorize informal duplication (the program cannot enforce against insiders). In each case, a high-quality conventional cylinder with documented rekey cycles delivers more practical security than a restricted program the customer will not run.
References
- ALOA Security Professionals Association - Key Control and Restricted Keyway Program Guidance.
- BHMA / ANSI A156.5 - American National Standard for Cylinders for Architectural Door Hardware.
- BHMA / ANSI A156.30 - American National Standard for High Security Cylinders.
- UL 437 - Standard for Key Locks.
- Manufacturer dealer agreements - Medeco, Mul-T-Lock, ASSA Abloy program documentation.