Automated check-in means a guest can get into a property without anyone meeting them, at whatever hour they actually arrive, and without you being reachable.
That last clause is the one that matters. A lot of setups described as automated are really just delayed manual work: they function until something goes wrong, and then they need a person.
Here is what the options actually are, what each of them breaks on, and how to pick one.
Why it is worth doing
Arrival times are not negotiable. Flights are late. Trains are cancelled. Guests land at 1am. Any process requiring a human at a specific moment will eventually collide with reality.
Manual handover is your capacity ceiling. If every arrival needs someone available, your portfolio is limited by staff hours, not by demand. This is the constraint that stops small operations growing.
It removes the most expensive failure mode. A guest who cannot get in is not a minor complaint. On most platforms it can trigger a refund regardless of your cancellation policy, because the fault is yours.
Vendors need access too. Cleaners, maintenance, inspections and agents all need entry on schedules that have nothing to do with bookings. A system built only around guest arrival handles this badly.
The four approaches
1. Lockboxes
A mechanical box holding a physical key, opened with a shared code.
Good for: single properties, low turnover, no power or connectivity, and as a backup.
Breaks on: codes that never change and circulate indefinitely; no record of who opened it; mechanical seizing in cold weather; visibility from the street; and, in several European cities, removal by the local authority where the device is attached to public property. Rome, Florence and Milan have all acted on this.
2. Smart locks
A keypad, app or fob-operated lock replacing the cylinder.
Good for: properties you own outright, where you can change the hardware, and where the door is a standard type.
Breaks on: batteries, at the worst moment. Also: leasehold and building restrictions on changing external doors, heritage constraints, non-standard door types, guests whose phones fail, and multi-lock properties where a communal entrance is outside your control. If a guest needs a building fob and a flat code, a smart lock on the flat door has solved half the problem.
3. Meeting the guest
A person hands over the key.
Good for: high-value properties where the greeting is part of the product, and complex arrivals genuinely needing explanation.
Breaks on: cost, availability, late arrivals, and the fact that it does not scale. Worth keeping deliberately for some properties and abandoning for others, rather than defaulting to it.
4. A managed key cabinet
A wall-mounted unit holding the physical keys, with access granted per person for a defined window.
Good for: portfolios, buildings, properties with multiple keys or fobs, anywhere you cannot change the lock, and anywhere you need a record.
Breaks on: it needs a wall you control, power and connectivity. It is also more infrastructure than a single owner-occupier needs.
How to choose
Four questions settle it in most cases.
Can you change the lock? If the answer is no, because of a lease, a freeholder, a heritage constraint or a communal door, smart locks are out for that door regardless of their merits.
Is there more than one thing to hand over? A building fob, a mailbox key, a gate key, a parking remote. Smart locks handle one door. A cabinet handles a bundle.
Do you need to know who entered? If disputes, insurance, building complaints or local reporting obligations are part of your reality, you need per-person credentials and a log. Shared codes cannot provide either.
How many people, changing how often? Two stable key holders is a different problem from three cleaning companies and a rotating trade list.
What good automation actually looks like
Whatever you choose, these are the properties that separate a working system from one that merely usually works.
Access belongs to a person for a period. Not a code attached to a property. A guest holds access for their stay, a cleaner holds a recurring window, a contractor holds two hours. Each expires by itself, so nothing needs cancelling.
Credentials work without an app. A code, a scannable QR or a wallet pass. Nobody arriving off a delayed flight is downloading software, and cleaning crews working across several clients will not either.
Instructions are in the guest's language, and specific. One address, one route from a named landmark or transit stop.
It issues automatically. Credentials generated when the booking confirms, through your existing platform, rather than someone remembering to send a message. Airbnb, Guesty, Hostaway and Res:harmonics connect directly, with an API for anything else.
It works when the infrastructure does not. Battery backup and offline operation are not theoretical requirements. Power cuts, outages and fire-weather shutdowns all happen, and they happen at the same time as arrivals.
It keeps a record. Named, timestamped, exportable. You will want this for a reason you have not anticipated yet.
There is a documented fallback. What happens at 11pm if the primary method fails, and does the person on the other end of the phone know the answer?
Identity, which is now part of the job
Worth flagging separately, because it has changed recently.
Several jurisdictions now require you to identify your guests and report them: Italy within 24 hours through the police portal, Spain within 24 hours, and a growing number of registration schemes across the EU under Regulation 2024/1028.
Italy is instructive on where this is heading. A November 2024 Interior Ministry circular argued that key boxes made guest identification impossible, and pushed toward in-person checks. In May 2025 the Regional Administrative Court of Lazio struck that directive down. What survived is the underlying obligation: identify the guest, which the court accepted can be done remotely and digitally.
So the requirement is not "meet the guest." It is "know who they are." A shared code satisfies neither, because it has no idea who used it. Identity verification at the point of key release does.
A practical setup
For most operators running more than a couple of properties, the arrangement that holds up looks like this:
- A wall-mounted key cabinet at a location you control, near the properties it serves
- Per-person, time-bound credentials issued automatically from your booking platform
- Identity verification where local rules require it
- Multilingual arrival instructions with one clear address
- An exportable access log
- A documented out-of-hours fallback
Capacity starts at 9 key positions and grows through chained expansion modules, so one installation scales with the portfolio rather than needing replacement.
See how it works or talk to our team.
Regulatory details reflect publicly available information at the time of writing and are provided for general guidance only. Guest identification, reporting obligations and rules on key storage devices differ by jurisdiction and change frequently. Confirm current requirements locally before relying on any arrangement described here.



