| Effective Date: |
December 16, 2021
|
|---|---|
| Last Revised Date: |
October 6, 2026
|
| Applies To: |
Classified Staff, Appointed Personnel, University Staff, Students
|
| Responsible Unit(s): | |
| Responsible Unit Email(s): | |
| Status: |
Active
|
Purpose and Summary
This Policy establishes oversight of Keys, Access Devices, and Access Control for University of Arizona (University) Property to promote a safe and secure environment, and to avoid potentially significant costs due to theft, vandalism, or excessive rekeying of locks.
Scope
This Policy applies to all Units and all Authorized Individuals in relation to Keys, Access Devices, and Access Control for University Property.
Definitions
Access Control means methods, systems, and infrastructure used to regulate entry to and use of University Property.
Access Device means any item, credential, or technology used to secure or provide entry to a restricted area. This includes, but is not limited to, metal keys, combination locks, keypad codes or PINs, CatCards, magnetic or proximity cards, biometric identifiers, RFID (radio frequency identification) devices, digital keys, or any combination of these methods used to control access to a restricted area.
Authorized Individual means anyone who is qualified for or issued an Access Device to access secured University Property based on the individual’s status-specific or role-specific needs, including, but not limited to, Employees, Students, Designated Campus Colleagues, and third parties, including contractors, vendors, and volunteers.
CatCard means the official University of Arizona physical or digital identification card.
Department Access Coordinator (DAC) means an Employee designated by a Senior Leader, Vice President, Director, or Department Head to be responsible for authorizing and processing all Access Control transactions for a specific Unit.
Designated Campus Colleagues (DCCs) means affiliates, associates, volunteers, and interns who are granted DCC status by the University, who contribute their time, services, and expertise to help the University accomplish its mission of teaching, research, and service.
Employee means all University employees, including faculty, staff, graduate assistants/associates, and student workers, whether their employment is full-time, part-time, permanent, or temporary.
Key means a metal key, and it refers to a specific type of Access Device.
Student means any person enrolled in one or more credits at the University, including enrolled Employees.
Unit means any University college, school, department, program, or other operating unit.
University Property means, for the purpose of this Policy, all buildings, facilities, and enclosed land owned, leased, operated, or controlled by the University.
Policy
- University Property
- All University Property must be appropriately secured utilizing University-approved Access Device(s).
- All Access Devices, including Keys, are the property of the University.
- Authorized Individuals
- Only Authorized Individuals may access secured University Property.
- Authorization for access is determined by the business purpose of the space, any mandatory access or security requirements, the status of the individual in relation to the space, and the role of the individual within their Unit.
University-issued Access Devices become the Authorized Individual’s responsibility until their status- or role-specific need has ended.
Authorized Individuals must not duplicate, loan, or share Access Devices.
Authorized Individuals must report immediately any loss, theft, or suspected misuse of Access Devices. Employees and DCCs must make such reports to their Unit’s Department Access Coordinator (DAC). Authorized Individuals must also immediately report theft of Access Devices to the University of Arizona Police Department (UAPD).
For Authorized Individuals who are Employees or DCCs, University Facilities Services – Facilities Management (UFS-FM) will review any reported loss, theft, or suspected misuse of Access Devices and update records as needed.
Authorized Individuals must follow instructions for a lost or stolen CatCard.
Authorized Individuals are responsible for returning Access Devices when their status- or role-specific need has ended, including, but not limited to, termination of employment, separation from the University, or the granted access is no longer needed.
Formerly Authorized Individuals may retain their CatCards after their access permissions have been deactivated, as their CatCard may be needed for other uses.
Authorized Individuals must follow the Electronic Access Guidelines, Facilities Management Key Issuance and Return Guidelines, and Secure Facility Access Control Policy.
Department Access Coordinators (DACs)
Every Unit must have an identified primary and secondary DAC. DACs may be specific to the Unit or can be shared between Units.
Unit leaders, including Senior Leaders, Vice Presidents, Directors, or Department Heads, are responsible for appointing or identifying their Unit’s primary and secondary DACs.
Unit leaders may delegate responsibility for approving Authorized Individual access to DACs.
Upon receiving annual reports from UFS-FM of Authorized Individuals and their Access Devices, Unit leaders are responsible for reviewing the information, addressing any inaccuracies, and responding to UFS-FM. Unit leaders may delegate this responsibility to DACs.
Unit leaders must notify UFS-FM immediately of any changes involving a DAC.
DACs will serve as the primary contacts between their Units, UFS-FM, Office of Public Safety, and third-party security vendors regarding maintaining the Unit’s Access Control.
DACs must remove access permissions and/or instruct Authorized Individuals to return Access Devices when the individual’s status- or role-specific needs have ended, including, but not limited to, termination of employment, separation from the University, or the granted access is no longer needed
Formerly Authorized Individuals may retain their CatCards after their access permissions have been deactivated, as their CatCard may be needed for other uses.
New Construction and Modifications
Units must ensure that all new construction, remodeling projects, facility expansions, modular building projects, and any other major modification to University Property ensures Access Control as outlined in the most recent University Design and Specification Standards (DSS) for all exterior entrances and high security areas.
Responsibilities
The Chief Safety Officer has authority over Access Control and is responsible for the oversight and evaluation of Access Control of University Property.
The Executive Director, University Facility Services is responsible for implementing Access Control on University Property.
UFS-FM is responsible for inventory tracking of Access Devices for access to University Property under UFS-FM management, including sending an annual report to Unit leaders with information about Authorized Individuals and their Access Devices to review and address any inaccuracies.
The Chief Safety Officer or their designee may grant reasonable exceptions to this Policy or related guidelines.
All exceptions must be supported by a standardized risk assessment for each exception and documented by the Office of Public Safety in a centralized tracking log that includes a start and end date.
The Chief Safety Officer may rescind any exceptions to this Policy or guidelines at any time.
Unit Policies and Procedures
Units must ensure that their policies, procedures, or guidelines align with University-wide safety, security, and compliance policies, procedures, and guidelines, and may not adopt conflicting or more permissive Access Control policies, procedures, or guidelines without prior approval.
Any Unit that develops or maintains policies, procedures, or guidelines related to this Policy must obtain approval from the Chief Safety Officer and the Executive Director, University Facility Services prior to implementation.
All approved Unit policies, procedures, and guidelines must undergo review and approval at lease every three years.
Policy Violations
Failure to follow this Policy may result in disciplinary action in accordance with Arizona Board of Regents and University policies. Violations of this Policy may result in an individual losing access to University Property, a restriction on receiving additional Access Devices, and/or additional cost to the individual or Unit, including paying for the rekeying of University Property.