Fully licensed & insured · WorkSafeBC coverage · Lower Mainland

Security guide · System Ownership

Security-System Handover Checklist for Strata and Property Managers

The accounts, drawings, backups, licences, tests, privacy records and training a property should receive before accepting a security project.

Light House residential property with access control and CCTV installed by WeTech
A finished installation is not fully handed over until the property controls the records and accounts needed to operate it.

A complete handover makes the system supportable by the property and transferable to a future manager or qualified contractor. Put the deliverables into the proposal before installation begins.

Direct answer

The short answer

Before accepting a security-system project, the property should receive owner-controlled administrator accounts, a final device inventory, as-built records, software and licence details, configuration backups, credential and resident data under an approved process, test results, privacy settings, training records, warranty information and support contacts. Handover is incomplete when only the hardware works but the installer still controls the accounts or documentation.

The owner-control handover matrix

Assign a named property representative to receive and verify each category.

CategoryDeliverableAcceptance check
AccountsOwner-level cloud, software, mobile and recovery accountsProperty can sign in and recover access without a personal installer email
InventoryModel, serial, location and purpose of each deviceCounts match the installed site
DrawingsDoor, camera, panel, cable and network recordsNames match software and physical labels
ConfigurationApproved exports and tested backupsRestore method and version are documented
LicencesKeys, subscriptions, renewals and billing ownerExpiry, cost and transfer process are visible
TestingCommissioning and acceptance resultsCritical functions and failure cases passed
PrivacyUsers, roles, retention and data-flow settingsConfiguration matches approved policy
SupportWarranty, service contacts and escalationCoverage, exclusions and responsible parties are clear

Accounts must belong to the property

Avoid systems owned by an installer’s personal email or one departing council member. Use a controlled organizational address, named individual administrators, least-privilege roles and multi-factor authentication where supported. Record who can authorize recovery and how former managers or vendors are removed.

  • Owner-level account and billing control
  • At least two approved recovery contacts where appropriate
  • Named users instead of a shared administrator
  • Multi-factor authentication where supported
  • Current vendor access and removal process
  • Emergency recovery evidence stored securely

Inventory and as-built records

Final documentation should use the same names people see in software and at the property. A camera called ‘Camera 12’ and a controller door called ‘Reader 4’ are difficult to support if no record maps them to the actual location.

  • Device schedule with model, serial, firmware and location where appropriate
  • Door and elevator permission map
  • Camera purpose, view and retention target
  • Panel, power, battery and network locations
  • Cable labels and retained-infrastructure notes
  • Gate, automatic-door, elevator, electrical and fire-interface responsibilities

Backups, licences and vendor exit

Receive current configuration backups in a protected owner-controlled location and document how they are restored. Record licence ownership, subscription renewal, required internet or telephone services and what remains operational if a contract ends.

Where export is supported, document credential, resident, door, schedule, event and configuration formats. A proprietary platform can still be supportable when transfer and exit terms are understood.

Commissioning and acceptance tests

Test real workflows rather than only device power. The approved results become the baseline for future service.

  • Visitor call, video and door release
  • Every approved resident credential method
  • Lost-credential revocation
  • Door close, latch and configured held/forced events
  • Camera day/night playback, time and export
  • Recording retention target
  • Gate and UHF read zone
  • Elevator-floor permissions with the elevator contractor
  • Automatic-door sequence with locking
  • Power and internet failure behaviour under an approved test

Privacy and cybersecurity records

The handover should identify which personal information the system holds, the approved purpose, administrator roles, service-provider access, storage locations, retention and deletion settings, incident contacts and access-request workflow. Review remote access and remove temporary installation accounts.

  • Named privacy officer and system owner
  • Role and permission matrix
  • Retention settings and evidence they work
  • Administrator and relevant activity logs
  • Current firmware and update responsibility
  • Network requirements
  • Incident and breach contacts
  • Export and deletion procedure

Training and final acceptance

Train the people who will actually add residents, revoke fobs, review footage, update directories and call for service. Record who attended and provide resident-facing instructions for the features the building approved.

  1. Property representative signs into every owner account
  2. Counts, drawings and labels are checked against the site
  3. Acceptance tests are witnessed and recorded
  4. Backups and exports are opened or restored where practical
  5. Administrators complete real tasks
  6. Temporary installer access is reduced or removed
  7. Open deficiencies receive an owner and due date
  8. Council or management records formal acceptance

Frequently asked questions

Questions property teams ask

Should the installer keep the only administrator account?+

No. The property should have owner-controlled access or a documented transferable arrangement. Vendor service access should be limited and removable.

Do we need as-built drawings for a small project?+

The level of detail can scale, but even a small system benefits from a device list, locations, cable or power notes and account ownership.

What is a configuration backup?+

It is an approved export of system settings or database information used for recovery or migration. Availability and restore methods vary by platform.

When is handover complete?+

When required deliverables are received, critical tests pass, administrators can perform their tasks and any open deficiencies are documented.

Sources & further reading

Primary references

Want advice for a specific property?

Share the existing system and the outcome you want to achieve.

Request a Site Assessment