Access Management gives you control over who can start and use your assets. This reduces unauthorized use or theft, simplifies handoffs, and enables fast revocation when access needs to change.
This guide is for anyone who owns assets and manages access on them. That includes rental companies assigning assets to customers, and contractors or fleet owners managing access across their own assets. The process is the same: you own the device, you control the keys, you manage the lifecycle.
Note on contractor-rented assets:
This guide does not cover the scenario where a contractor rents an asset from a rental company and the rental company delegates day-to-day key management to the contractor.
Before you start
Make sure the following are in place before configuring Access Management on any asset.
Hardware requirements
A TU600 device with a DualID keypad, or a TU700 device with a K300 keypad installed on the asset (for Digital Keys no keypad is required as long as a relay is installed).
A relay installed on the asset’s enable circuit (required for immobilization)
Software & account requirements
Access Management enabled in Trackunit Manager for the relevant assets
At least one user with Admin or Fleet Admin role in Manager
💡 Tip: Missing some of the requirements above? Contact your Trackunit representative for help.
Choosing the right Key Type
Trackunit supports four key types. Each suits a different operational context, and you can mix and match them across your fleet.
Key Type | How It Works | Best For | Phone Required? |
Static PIN | A fixed code entered on the keypad. The code does not change automatically. | Simple shared access, small crews, no individual tracking needed. | No |
Rolling PIN | A daily rotating code delivered via the Trackunit On app, reducing exposure if shared. | Where phones are permitted; accountability with a rotating code. | Yes, the Trackunit On app required |
Key Card | A physical RFID card tapped on the keypad to grant access. | Larger crews, no phone required, easy revocation if a card is lost. | No |
Digital Key | A key delivered to the Trackunit On app. Works offline once loaded. | Where phones are permitted and individual operator tracking is required. | Yes, the Trackunit On app required |
💡 Tip: Recommended setup
A common and effective approach is to assign personal Rolling PINs or Key Cards to daily operators, and configure a single Static PIN per asset as a non-personal backup or emergency key.
This gives you individual accountability without removing a failsafe.
Organizing your account
Before assets go out or are assigned to operators, create a logical structure in Trackunit Manager so access can be assigned and revoked cleanly.
Use Groups to organize by customer or crew
Navigate to Trackunit Manager > Groups
Create one Group per customer, site, or crew - for example: “Acme Construction - Site A” or “Night Shift Crew”
Assign keys at the Group level wherever possible. When assets are added to or removed from the group, access updates automatically.
Sites vs. Groups — which to use?
Both Sites and Groups can be used to organize assets for access management. Here’s the key differences:
| Sites | Groups |
Definition | A geographic boundary (geofence). Assets inside the boundary are automatically included. | A flexible list of assets. No boundary required - you manually assign assets. |
Best for | Fixed physical locations with good GPS signal (yard, depot, job site). | Access Management where assets move between customers, sites, or crews. |
Access follows… | Site inventory - automatically includes assets inside the fence. | Group membership - you control which assets are assigned. |
Monitoring usage
Access Management gives you visibility into how and when assets are being used, not just whether they start and by whom.
Operations Report
Use the Operations Report to review asset usage patterns, after-hours activity, and operator usage frequency. This is your primary tool for spotting anomalies or compliance issues.
Movement-based theft Alerts
Set up a Movement-based theft Alert to receive a notification any time an asset operates outside agreed hours. This is a quick way to catch unauthorized use without running a report manually.
Key Governance - What to have in place
Access Management works best when your team has clear ownership and documented rules. These don’t need to be complex. A few agreed principles go a long way.
Designate a Key Admin: one person per branch or location who is responsible for creating, updating, and revoking keys.
Set expiry dates at the time of key creation: always align to the contract or assignment end date.
Treat a lost key card the same as a lost physical key: revoke it immediately and issue a replacement.
Do a quick audit at return: run a spot-check in the Operations Report to confirm no access events after the end date
Review access at regular intervals for longer assignments: validate that active keys still match the current authorised operators
Access Management Lifecycle checklist
Use this checklist at each stage of every assignment that includes Access Management-enabled assets.
| Before Assets Go Out |
| During the Assignment |
| At the End of the Assignment |
✔ | Access Management is enabled on all assets going out. | ✔ | Review the Operations Report for after-hours use or unusual activity.
| ✔ | Delete all active operator keys (or confirm they have expired). |
✔ | Assets are assigned to the correct group. | ✔ | Validate active keys against the current authorized operator list - remove departed operators promptly. | ✔ | Remove assets from the customer or crew group. |
✔ | Operators are created and keys are assigned.
| ✔ | Handle operator changes: create new operator → assign key → set correct expiry date. | ✔ | Spot-check the Operations Report to confirm no access events after the end date. |
✔ | Key expiry date is set to match the contract or assignment end date. | ✔ | For lost key cards: delete the compromised key and issue a new one. | ✔ | Archive operator records per your data retention policy. |
✔ | Spot-test access on at least one asset per batch before it goes out. |
|
|
|
|
✔ | Operators have what they need: PIN, app access, or physical key card |
|
|
|
|
Key terms
Term | Definition |
Operator | An individual granted permission to start or use specific assets via Access Management.
|
Key | A digital credential that allows an operator to start or operate an asset.
|
Key Admin | A user in Trackunit Manager with permissions to create, update, and revoke operator keys and PINs.
|
Static PIN | A fixed numeric code that does not change automatically. Simple to roll out but requires active management.
|
Rolling PIN | A PIN that changes daily, reducing the exposure window of any single code. Delivered via the Trackunit On app
|
Key Card | A physical RFID card used to authenticate an operator and grant asset access.
|
Digital Key | A key delivered directly to an operator’s Trackunit On mobile app. Works offline.
|
Group | A flexible collection of assets in Trackunit Manager. Used to assign access to a set of assets at once.
|
Site | A geographic boundary (geofence) in Trackuinit Manager. Assets inside the boundary are automatically included. |
Resources & Support
All about Access Management
All about the Trackunit On App
💡 Tip:
Need more help?
Click on the Messenger icon in the lower left corner to get in touch with Customer Support.
