Office · Risk and compliance research
Security Protocols for After-Hours Office Cleaning
The security protocols that should sit behind any after-hours office cleaning contract in Melbourne, from access control to close-down checks, and how to hold a contractor to them.
5 min read
Handing a set of keys and an alarm code to an outside crew that works while your building is empty is a genuine security decision, not an administrative one. For most Melbourne offices, after-hours cleaning is the sensible choice because it keeps disruption away from the working day. The trade-off is that the people cleaning your floors are often the only people in the building for several hours, with access to desks, meeting rooms, and server cupboards. The way to manage that is not to avoid after-hours cleaning; it is to insist on documented security protocols and to hold your contractor to them.
This guide sets out the protocols a serious after-hours cleaning arrangement should include, and how to check they are working rather than taking them on trust.
Start with the risk you are actually managing
Before writing a single procedure, be clear about what you are protecting. For most offices the risks fall into a few groups: physical security of the premises, protection of equipment and assets, confidentiality of documents and data, and safety of the cleaning staff themselves. Each of these points to different controls. Losing sight of any one of them tends to produce a lopsided arrangement — a building that is well locked but leaves sensitive paperwork exposed, or a confidentiality policy that ignores the fact that a lone worker at 2am needs a way to raise the alarm.
A short written risk summary for your site is worth the effort. It gives you a checklist to measure any contractor against, and it makes the conversation about protocols concrete rather than generic.
Access control: who gets in, and how
Access is the foundation of every other control. The core principle is that access should be named, limited, and revocable. In practice that means:
- Only specific, identified individuals are authorised for your site, not "whoever the contractor sends".
- Access credentials — keys, fobs, or codes — are issued to named people and logged.
- Credentials can be withdrawn quickly when someone leaves the contractor's roster.
- Access is limited to the areas that need cleaning, with sensitive zones treated separately.
The weakest arrangements rely on a shared code that never changes and a key that has been copied more times than anyone can count. The strongest use individually attributable access so that any entry can be traced to a person and a time. Where your building uses electronic access, insist that cleaning staff use their own credentials rather than a generic "cleaner" card.
Alarm and monitoring procedures
If cleaners arm and disarm the alarm, that process needs to be documented and rehearsed. A good procedure covers the sequence for disarming on entry, what to do if the alarm activates unexpectedly, who the monitoring company should contact, and the arming sequence on exit. Cleaners should know the difference between a genuine activation and a false one, and they should never simply ignore an alarm because it "always goes off".
Alarm event logs are one of the most useful verification tools you have. They record arm and disarm times, which you can compare against the hours the clean was supposed to take. A pattern of very short visits, or disarming without a matching re-arm, is a signal worth investigating.
Staff identity, vetting, and continuity
Protocols only work if the people applying them are known and stable. Ask who will actually be on your site, whether they have been through police checks and reference verification, and how continuity is maintained. A revolving door of unfamiliar casuals undermines every other control, because no one on your side ever learns who is meant to be in the building. A stable, vetted crew is a security control in its own right — familiar faces make an unfamiliar face obvious.
A practical protocol checklist
The table below summarises the core protocols and how to verify each one. Treat it as a starting point to adapt to your building.
| Protocol area | What good looks like | How to verify |
|---|---|---|
| Access control | Named, individual credentials; limited zones | Access logs; credential register |
| Alarm management | Documented arm/disarm; monitoring contacts | Alarm event reports |
| Sign-in / sign-out | Every visit recorded with times | Sign-in sheets or app records |
| Close-down | Doors, windows, lights, alarm confirmed on exit | Close-down checklist per visit |
| Incident reporting | Clear who to call and how fast | Reporting log; response times |
| Staff vetting | Police checks and references on file | Contractor documentation |
Close-down: the most overlooked step
The end of a clean is where security most often slips. Tired staff at the end of a shift can leave a fire door propped, a light on, or the alarm unset. A written close-down checklist — completed and recorded every visit — reduces this to a routine. It should confirm that all cleaned areas are secured, external doors are locked, windows are closed, and the alarm is set before the last person leaves. Where possible, tie the checklist to the alarm arming event so there is a timestamped record that the building was secured.
Reporting and escalation
Even with strong protocols, things will occasionally go wrong: a door found unlocked on arrival, a light left on by staff, a suspicious person outside the building. What matters is that cleaners know exactly what to do and who to call. Agree an escalation path in advance — a first point of contact, an after-hours number, and a rule for when to call emergency services. Then ask for incidents to be reported to you promptly, not buried in a monthly summary. Prompt reporting is not a sign that the arrangement is failing; it is evidence that the protocols are being used.
Building the protocols into the contract
Verbal assurances are difficult to enforce. The protocols above should appear in the written scope and service agreement, alongside the cleaning specification itself. That gives both sides a shared reference and makes reviews straightforward: you are checking performance against a document, not a memory. It also protects the contractor, because it defines what they have committed to rather than leaving them exposed to shifting expectations.
Good protocols do not guarantee that nothing will ever go wrong — no arrangement can promise that. What they do is reduce the likelihood of avoidable incidents, make any incident traceable, and give you a clear, evidence-based way to hold the arrangement to account.
If you are reviewing your arrangements, AfterFive builds these controls into every after-hours office cleaning engagement and works across Melbourne CBD towers and metro sites. To scope a security-aware clean for your building, talk to our team and we will walk the site with you.
FAQs
What security protocols should an after-hours cleaning contractor follow?
At a minimum, a contractor should follow documented access control, named and vetted staff, a sign-in and sign-out record, alarm arm and disarm procedures, and a close-down checklist confirming doors, lights, and alarms are set on exit. These should be written into the contract, not left to memory.
Who is responsible if a security breach happens during a clean?
Responsibility depends on the contract and the facts. A well-drafted agreement sets out the contractor's obligations, insurance, and reporting duties, but shared protocols and a clear escalation path reduce ambiguity for everyone. Confirm these details before work begins rather than after an incident.
How do we verify that protocols are actually being followed?
Use access logs, alarm event reports, sign-in sheets, and periodic spot checks. Ask the contractor for regular reporting so you can compare what was agreed against what happened on site.