Authorisation
Who is allowed through?
Define who may enter each boundary. Entry to a home, office or shared building should not automatically grant entry to the collection room, cabinets or safe.
Physical security chapter
Locks do not secure a collection by themselves. They regulate who may cross a boundary, under what conditions, and with what evidence afterward. Their real value depends on the strength of the surrounding door, frame, cabinet, safe or room, the control of keys and credentials, and the behaviour of everyone who uses them.
For a collector, the practical question is not simply whether something is locked. It is whether the complete arrangement delays the relevant attacker, restricts legitimate access to the smallest necessary area, reveals misuse, supports a credible response, and remains safe during fire, power failure or emergency salvage.
Foundation
A useful access-control system performs several functions at once. Focusing on the lock alone misses the human and administrative controls that determine whether the boundary works in practice.
Authorisation
Define who may enter each boundary. Entry to a home, office or shared building should not automatically grant entry to the collection room, cabinets or safe.
Authentication
A key, card, code, phone, biometric or human check must establish that the person requesting access is the authorised person, not merely someone claiming the role.
Restriction
Access should stop at the smallest appropriate zone. A cleaner may enter a hallway, a photographer a prepared work area, and an emergency contact the building without receiving safe access.
Accountability
The system should show, as far as proportionate, who held a key or credential, when access occurred, and whether permissions were changed, shared or revoked.
Delay
A lock matters when it increases the effort required to reach the collection and gives alarms, occupants, neighbours, guards or police time to notice and respond.
Control
Many losses begin with a person who was legitimately admitted. Good control limits freedom, information, handling and unsupervised time even when the initial visit is genuine.
Layered defence
The aim is not to fit a lock to everything. It is to create several proportionate boundaries so that one lost key, weak cabinet or open door does not expose the whole collection.
Layer 1
Gates, communal entrances, garages and property boundaries discourage casual approach and create the first opportunity for observation or detection.
Layer 2
External doors, windows and accessible openings protect the premises. A strong front door does not compensate for a weak side door, garage, roof route or adjacent glazing.
Layer 3
A dedicated room separates collection activity from ordinary household, office or visitor circulation and conceals where the most valuable objects are kept.
Layer 4
Cabinets, drawers, safes and vaults provide category-level or object-level protection and can segment risk within the collection area.
Layer 5
Case locks, concealed fixings, security screws, mounts and restraints can slow individual removal or make it more conspicuous, provided they do not damage the object.
Hardware judgement
Lock categories describe mechanisms or formats. They do not, by themselves, establish resistance, installation quality, key control or suitability for a particular collection boundary.
Useful for keeping a door closed, but not necessarily for resisting forced entry. A door that merely clicks shut should not be treated as securely locked.
Potentially meaningful delay when the bolt, keep, frame, cylinder protection and installation are all strong enough. Bolt depth alone is not a complete measure.
The lock body is recessed into the door. This construction can support substantial hardware, but the word mortice is a format, not a security grade.
Common in modern and multipoint doors. Security depends on resistance to snapping, pulling, drilling, manipulation and unauthorised duplication, plus correct sizing and protective furniture.
Several locking points can resist spreading and levering, but only when the door, frame, cylinder and mechanism remain aligned, maintained and fully engaged.
Common on display cases and drawers. Many low-cost examples control casual opening only because the surrounding material, cam, retaining nut and keying are weak.
Judge the shackle, body, exposed length, corrosion resistance, key control, hasp, staple and anchor as one assembly. A premium padlock on a thin screwed latch is an unbalanced system.
Avoids a removable key but creates risks from predictable codes, observation, sharing, written records, wear patterns and weak emergency override keys.
Can provide individual permissions, rapid revocation, time limits and logs, but adds dependencies on power, software, administration, network security and emergency release design.
Threat model
Collectors do not need operational knowledge of defeating locks, but they do need to recognise the main categories of failure so that purchasing and procedures address the real risk.
Physical
Force may be applied to the lock, cylinder, handle, bolt, frame, glazing, hinges, cabinet, wall, floor anchorage or container itself. The attacker may ignore the lock entirely.
Technical
A mechanism may be operated without the authorised key, while keys, cards, codes, phone credentials or registration data may be copied, photographed, cloned or shared.
Behavioural
A controlled door provides no protection when an unauthorised person follows a legitimate user or when the door is held open for convenience.
Human
Couriers, contractors, buyers, household visitors, staff and partners may gain excessive access through persuasion, familiarity, trust or weak verification rather than forced entry.
Administrative
Old credentials, unknown duplicates, default administrator codes, unreviewed logs, unreturned keys and installer access can undermine otherwise strong hardware.
Governance
Every additional key creates another opportunity for loss, theft, copying, lending or forgotten possession. The fewer keys there are, the easier it is to know who can reach the collection.
Credential choice
Different credentials move risk rather than eliminating it. The correct choice depends on who needs access, how quickly it must be revoked, whether evidence is needed and what happens when the primary method fails.
| Credential | Useful strength | Main collector risk | Control priority |
|---|---|---|---|
| Mechanical key | Simple and durable | Loss, copying, unknown duplicates | Register, minimise, audit, rekey |
| PIN or combination | Easy to change | Sharing, observation, predictable codes | Individual codes, change after exposure |
| Card or token | Rapid revocation and zoning | Cloning, lending, forgotten deactivation | Named issue, time limits, prompt revocation |
| Mobile credential | Convenient and configurable | Account compromise, device loss, cloud dependency | Strong accounts, remote revocation, supported apps |
| Biometric | Convenient individual factor | False matches, spoofing, privacy, weak override | Use with another factor; secure fallback |
Electronic systems
Electronic systems are valuable when access changes frequently or when individual accountability matters. Their benefits disappear when users share codes, administrators retain default access, logs are ignored or the networked system is poorly secured.
Use a separate credential for each regular user. A shared PIN may open the door, but it cannot show which person used it and cannot be revoked selectively.
Limit permissions by door, zone, day, time, purpose and duration. Adding access should not preserve old permissions that are no longer required.
Disable access when a role, relationship or visit ends, or when a card, phone or credential may have been compromised.
Record granted and denied entry, forced or held-open doors, overrides, administrator changes and unusual out-of-hours use. Logs must be accurate, protected, retained and reviewed.
Understand backup duration, low-battery alerts, manual override and which doors unlock or remain secure during power or network loss. Life safety takes priority over property protection.
Remove default passwords, control installer accounts, patch supported systems, protect remote access and avoid making the access controller an internet route to the collection.
Collector scenarios
Good security does not require hostility. It requires clear boundaries, limited disclosure, proportionate supervision and prompt withdrawal of access when the reason for it ends.
Household
Residents may need building entry without needing cabinet keys, safe combinations or a full inventory. Children, guests and relatives can disclose or damage objects without malicious intent.
Cleaner or carer
Where possible, schedule work so collection rooms remain locked, keys are not left unattended, and exceptional access is supervised or recorded.
Tradesperson
Verify the appointment, secure loose objects and keys, conceal inventories and shipping labels, restrict the work zone, then check doors, windows, sensors and credentials after the job.
Buyer or researcher
Prepare selected objects in a controlled viewing area. Supervise handling, limit unnecessary photography, control bags and never leave the visitor alone with unrelated stock or security details.
Employee or volunteer
Apply joiner, mover and leaver controls. Issue individual credentials, remove obsolete permissions, recover keys promptly and review recent activity when a role ends.
Event or fair
Define who holds case and stand keys, who opens and closes, where keys remain overnight, how shift handovers work, and what happens if a key or credential is lost.
Secure containers
A safe is not merely a heavy box with a lock, and a lockable display case is not automatically a security case. Rating, construction, anchoring, override arrangements and the surrounding room all affect the result.
Simple and independent of batteries, but the risk transfers to key custody, copying, spare storage, discovery and possible coercive surrender.
Avoids a removable key and can be durable, but security depends on code secrecy, dial discipline, observation control and secure emergency records.
Allows rapid entry, code changes and sometimes multiple users or logs, but low-quality electronics, weak override keys, default codes and battery failures can dominate the real risk.
Incident response
The important fact is not whether the original key later returns. It is whether the key, its pattern or its authority may have been exposed while control was lost.
Assess
Establish what the key opens, whether it is identifiable, whether it is a master, when it was last secure, who knew of the loss, and whether targeted theft is plausible.
Contain
Restrict access, increase monitoring, move portable high-value objects, alter alarm arrangements and disable associated electronic credentials where the risk warrants it.
Recover
Rekey or replace affected cylinders when custody cannot be trusted, record the incident and actions, and notify the insurer where policy conditions or likely loss require it.
Operations
Strong hardware is often defeated by routine behaviour. A short written check is more valuable than relying on memory, especially where several people share responsibility.
Myth versus reality
These claims are appealing because they simplify a complex system into one object or feature. Each becomes dangerous when it prevents the collector from examining the whole boundary.
Reality: The door, frame, glazing, hinges, walls, ceiling, floor and operating routine must provide comparable resistance. The easiest bypass defines the boundary.
Reality: Premium hardware can be wasted on a lightweight door, flexible cabinet, exposed hinge or weak fixing. Balance matters more than a single specification.
Reality: Controlled blanks and ordering reduce casual duplication, but no key should be treated as permanently or absolutely copy-proof.
Reality: It replaces some physical-key problems with credential, software, power, installer, cloud and administrative risks.
Reality: Overrides, administrators, sensor limitations and weak fallback locks often determine the practical security of the system.
Reality: Detection can report an event, but the physical boundary must create enough delay for any response to matter.
Proportionality
Not every domestic collector needs commercial access control. The appropriate level depends on value, portability, visibility, occupancy, number of users, previous incidents and the consequences of loss.
Level 1
Prioritise sound external locks, controlled spares, a lockable room or cabinet, rekeying after moving, no visible keys and a simple emergency arrangement.
Level 2
Add a dedicated collection zone, separate household and collection keys, better cabinet or safe locks, a key register, door detection, and written visitor or contractor routines.
Level 3
Add a professional survey, certified boundaries and secure containers, strict master-key limitation, individual credentials, audit logs, formal opening and closing checks, and insurer agreement.
Level 4
Use role-based access, joiner-mover-leaver control, separation of duties, central key custody, after-hours restrictions, visitor management, incident response and cybersecurity for networked systems.
Improvement order
Work from assets and routes toward technology. Buying hardware first often produces a strong lock on the wrong boundary or a sophisticated system that nobody administers correctly.
Record value, portability, visibility, replacement difficulty, sentimental or cultural importance, attractiveness to thieves and preservation sensitivity.
Include household members, employees, cleaners, contractors, buyers, researchers, conservators, insurers, delivery personnel and emergency contacts.
Inspect normal doors, windows, garages, lofts, basements, shared walls, ceiling voids, service penetrations, connecting doors and emergency exits.
Separate visitor space, household or office space, collection work areas, general storage and high-security storage.
Upgrade the complete doorset, cabinet or container rather than concentrating on the visible cylinder or padlock.
Remove unnecessary access before adding technology. Fewer active credentials reduce loss, copying, sharing and audit complexity.
Know who may order duplicates, who holds each credential, what it opens, and who can authorise exceptions.
Monitor important doors, cabinets and safes, then ensure alerts and logs reach someone who will recognise and act on abnormal events.
Decide in advance what happens when a key is missing, power fails, an override is used or responders need urgent access.
Confirm that people actually lock doors, scramble combinations, return keys, disable temporary access and complete opening or closing checks.
Evidence
Good records support maintenance, insurance, incident response, rekeying and succession. They should be protected from casual access and should not be stored only beside the collection they describe.
Review
Use this as a periodic review after moving, changing staff or household access, increasing collection value, buying a safe, suffering an incident or altering the display and storage arrangement.
Specialist threshold
The strongest result comes from describing the collection, building, threat, access pattern and operational constraints - not merely asking for the strongest available lock.
Relevant specialists may include an independent physical-security consultant, a competent security locksmith, alarm and access-control engineers, fire-safety professionals, structural engineers, conservators, insurers and specialist brokers.
Core principles
The strongest collector access-control system is not necessarily the one with the most sophisticated lock. It is the one in which the physical boundary, credentials, people, records and daily behaviour reinforce one another.
Review the structural boundaries that must support any lock or access-control system.
Return to the full physical-security chapter and its connected topics.
Continue to the detection layer that should operate alongside physical delay and controlled access.
Understand how lock type, anchoring, certification and override arrangements affect secure containers.
Control legitimate access without giving visitors or trusted people unnecessary freedom or knowledge.
Record keys, credentials, procedures, maintenance and incidents without exposing sensitive details.
Connect physical arrangements with policy warranties, evidence requirements and claim risk.