Key safe and alarm codes
A key safe code typed into a notes field reaches every phone it has ever synced to and sits there for as long as the note does, read by whoever is assigned next with nobody keeping count. Access codes gives it a home of its own: encrypted at rest, shown one tap at a time to whoever is actually meant to see it, and logged every single time.
On this page
A key safe number is usually typed into whichever box happens to be open when somebody thinks of it: the property notes, a message to the team, the top of a paper sheet in a drawer. It travels wherever that field travels, forever, to everyone who is ever assigned there, and nobody can say afterwards who read it or when. Access codes gives a key safe or alarm code somewhere else to live: encrypted where CleanFlo stores it, revealed rather than displayed, and only to an owner or to the cleaner standing at that address on the day they are booked there.
It sits inside Keys & access, the panel on a location's own page that already holds the other half of the same question: the physical keys, fobs and cards you are trusted with for a site, and who is currently carrying each one. That register answers "who has the key"; access codes answers "what is the number for the keypad", and CleanFlo keeps the two apart on purpose, because a key wants to be visible so it comes back, and a code wants the opposite.
Where it sits
Open a location and, above the job history, Keys & access carries an Access codes section of its own, underneath whatever keys and fobs are already on file for the same site. A brand new property, or one with nothing added yet, reads No access codes on file with a line explaining what belongs there rather than in the notes.
Adding or changing a code
Add code opens a short sheet, and there is deliberately no way to load a current value into it: showing a stored code inside an edit form would be a reveal with no log, reachable by anyone who could open the drawer, which is the one thing this feature exists to stop. Rotating a code is the same act as adding the first one, type the new number, so the sheet says so rather than leaving an empty field that looks like a bug.
- What it opens
- Free text, up to 40 characters. Key safe is the default; use Alarm, Side gate or your own words for a second code at the same address. Locked once a code exists: a rotation keeps the same label rather than renaming it.
- The code
- 4 to 12 characters: numbers, letters, # and *. Hidden while you type unless you press Show what I am typing. Encrypted the moment it is saved, and never shown on this screen again, to anyone, including whoever just typed it.
- Hint
- Up to 60 characters, what a cleaner sees before they ask for the code, for example "4 digits, on the back gate". It cannot contain the code itself and cannot contain three digits in a row, so a hint that is really the code cannot be saved.
- Ask me to change it every
- Days, from 7 to 365, defaulting to 90. Saving a code, first entry or rotation alike, resets this clock.
- Remove
- Deletes the code and the record of who was shown it together. What the activity feed already logged about it stays.
Who can see it, and when
A code is never stored anywhere it could simply be read off a page. It is decrypted only for the length of one Show, and the same check decides every one of them, whether it is pressed from the property page or from a job: the rule is enforced once, in one place, not copied into two.
| Who | Can they see the code |
|---|---|
| An owner | Yes. From the property page, any time, logged the same as anyone else's reveal. |
| A supervisor | No. They can see the codes list, the rotation state and the reveal log, but not the code itself. |
| A cleaner booked at this address today, on a job still scheduled or in progress | Yes. From that job, in the app, for sixty seconds. |
| A cleaner booked here tomorrow, or on a job already finished | No. |
| A cleaner booked somewhere else today | No, whatever else is on their own schedule. |
What the cleaner sees
On today's job, directly under Getting in, the same free-text access notes a cleaner has always read, sits a row for every code on file at that address: Show the Key safe code. It is only there while the job is still scheduled or running: it does not appear early, and it is gone once the clean is complete.
Tap it and the code sits on screen for sixty seconds with a countdown, then hides itself; Hide now takes it away sooner. Underneath, a line reads plainly, "Every code you are shown is recorded." Nothing keeps a copy on the phone: leave the job and it is gone, and opening it again shows the button, not the number.
Every code you are shown is recorded.
Every reveal is logged
A code is never decrypted before the record that says so exists: who asked, when, and, for a cleaner, which job they asked from. That happens in the same instant as the reveal, so there is no route to a code that leaves no trace, not even an owner's own Show on the panel.
On the property page, a disclosure under the list, Every time a code was shown here, opens onto the last twenty, who and when, in the same ledger style as the rest of the record. A code that has never been shown reads Not shown yet; once the full log runs past what the panel actually loaded, an unshown code reads Not shown recently instead, because silence past that point proves nothing either way.
The activity feed carries its own line too, worded plainly: it "revealed the Key safe code for" the property, or "rotated the [label] code for" it when a code is changed rather than shown. Neither the feed, nor the reveal log, nor anything else in CleanFlo ever carries the code itself. What is recorded is that it happened, never what it was.
Rotation reminders
The panel's Changed column says in words how long a code has been on file, and State reads Rotation due once it passes the window you set for it, in place of the ordinary In date. The badge is not a judgement on the code, it only says a date has passed: nothing here knows who has since written the number down or moved on.
Once a code is due, the company's owners get a push notification and an email, once per company each morning rather than once per code: a company with several key safes due at once gets one message naming all of them, not several. Leave it and it asks again after thirty days; change the code, which resets both Changed and the reminder together, and the asking stops.
The notes field still exists, and CleanFlo watches it
Access notes, the free-text field on Edit Location, still travels to a cleaner exactly as it always has, cached offline and shown as Getting in. CleanFlo does not edit it, block it or scrub digits out of it: it is a field people use for a dozen ordinary things, side gate, dog on site, bins in the alley, and clearing numbers out of it to enforce a rule nobody agreed to would destroy real notes to catch a minority of them.
What it does instead is notice. A note with digits sitting close to the words key, safe, alarm or code, a phone number is never mistaken for one, gets a line on the property page: "That note looks like it has a code in it: everyone assigned here can read it and nothing records who did. Access codes, below, keeps it encrypted and logs every reveal." The Edit Location drawer carries the same steer under the field itself: "Codes belong under Access codes, where they are encrypted and every reveal is logged."
Supervisors
A supervisor sees exactly what an owner sees on this panel, the codes list, the rotation state and the reveal log, and can act on none of it: no Add code, no Show, no Change, no Remove. That is deliberate rather than a gap: a shift lead planning a week needs to know an address has a key safe on file, and to be able to answer who opened it on Tuesday, and neither of those is the code itself or a write.
The Keys & access module
Access codes sits inside Keys & access on Settings → Modules, the same switch the key and fob register shares. Switch it off and the whole panel disappears from the location page for owner and supervisor alike: nothing new can be added, shown, changed or removed, and every code already stored stays exactly where it is, encrypted, waiting for the module to come back on.
A code a cleaner could already see stops working the moment the module is off: the check runs again on every reveal, so it is refused with the same sentence anyone else would get, "Keys & access is switched off for this company," rather than a stored code quietly becoming readable because a switch was missed.
Common questions
Can I see the code I saved after I have typed it in?
What does a cleaner see if they need the code and have no signal?
Does switching Keys & access off delete our codes?
Still stuck?
Open Support in the app and send us a ticket, or email the team. A real person reads every one.