Digital Key and Mobile Access: The Data Layer Nobody Is Using
Every guest room door in your hotel is now a timestamped, credentialed sensor, and almost nobody is reading it. Mobile key was sold and bought as a way to skip the front desk. The events it generates are a better arrival forecast than your PMS, a better vacancy signal than your desk agents, and a security feed that catches problems in minutes instead of weeks. Here is what the data can do and what it takes to use it.
The Feature Everyone Shipped and Nobody Mined
Ask a general manager what mobile key does for the property and you will get a clean, rehearsed answer: it lets guests skip the desk, it saves plastic, and the loyalty members like it. All true. All beside the point. The lock on every guest room door is now the most reliable sensor in the building, and almost no hotel treats it as one.
Consider what a modern access system already knows. It knows the moment a guest's key was issued to their phone. It knows the moment the guest first touched the door, and every subsequent time. It knows which elevator floor was requested, which fitness center door opened at 5:40 in the morning, and which service door was held open for four minutes at 11:15 at night. It knows that room 1412 has not been entered in 36 hours despite an in-house guest, and that room 1418 has been entered by three different housekeeping credentials in one morning. Every one of these events is timestamped, credentialed, and stored. Most of it sits in a lock server or a vendor cloud that the PMS, the housekeeping system, and the security team never query.
The scale of the installed base makes this a large, quiet opportunity. Hilton now has Digital Key enabled at more than 80 percent of its US managed rooms, and had already logged 135 million door openings by 2022. Hyatt has committed 1,000 hotels to a cloud access platform and was the first brand to put room keys in Apple Wallet. Marriott's Bonvoy app runs Mobile Key across elevators, fitness centers, and parking at participating hotels. Google Wallet now supports hotel keys natively for Android. The market for the solutions themselves was valued at $1.2 billion in 2024 and projected to reach $5.8 billion by 2033.
All of that investment was justified on the guest-facing story. The data story was never told, because the people who bought the locks (engineering and security) and the people who could use the data (front office, housekeeping, revenue) rarely sit in the same meeting. This article is that meeting.
Your hotel spent six figures installing a sensor on every guest room door, then treated the output as a convenience feature. The lock knows more about your operation in real time than your PMS does.
Why the Data Is Stranded
Three structural reasons explain why access data has stayed locked inside the lock system, and understanding them tells you what has to change.
The lock ecosystem was built for security, not for operations. Audit trails on electronic locks exist so a security director can reconstruct an incident after the fact: who entered, when, with which credential. Systems from ASSA ABLOY's Vingcard and dormakaba's Saflok have logged this for decades. The design assumption was that someone would pull the log after something went wrong. Nobody designed it to push a signal before something goes right.
Legacy architectures are offline or polled. Most installed locks are battery-powered standalone units. Events are stored on the lock itself and read out only when a staff member physically visits with a handheld programmer, or, in online systems, when a gateway polls the lock. If the data reaches a server hours later, it is useless for anything operational. Cloud-native platforms like Vostio, dormakaba's Keyless Go, and Salto's cloud access tier change this by making events available in near real time through an API. That is the difference between a record and a signal.
The PMS integration is one-directional. The standard mobile key integration sends a command from the PMS to the lock system: issue a key for this guest, this room, these dates. Almost no property has built the return path, where the lock system tells the PMS, the housekeeping platform, or an orchestration layer what actually happened at the door. The interface exists for key issuance. The interface for key usage is the missing half, and it is the half worth money. If your integration layer is not yet capable of carrying that return signal, the hotel API strategy guide covers the hub-and-spoke architecture that makes it possible.
The Lock Ecosystem: What Each Architecture Can and Cannot Give You
Not every lock installation can support the use cases in this article. The table below is the diagnostic. Find your row before you read further, because the return on everything that follows depends on whether events can leave the lock in something close to real time.
| Lock architecture | Typical vendors and products | Event latency | Data available to other systems | Operational use cases supported |
|---|---|---|---|---|
| Offline standalone RFID | Vingcard Classic and Signature, Saflok MT, Onity OnPortal | Hours to days (manual audit pull) | Audit trail only, after the fact | Incident forensics only |
| Online via wireless gateway | Vingcard Essence with Visionline online, Saflok Quantum online, Salto BLUEnet | Seconds to minutes (polled) | Entry events, battery status, door ajar, deadbolt state | Arrival detection, room readiness, security anomaly alerts |
| Cloud access management | Vostio, dormakaba Keyless Go, Salto KS, Openpath and Brivo in select-service | Near real time (event push) | Full event stream via API, key lifecycle, wallet provisioning status | All of the above plus housekeeping routing, predictive arrival, guest journey analytics |
| Wallet-native (Apple and Google) | Hyatt on Vostio, Hilton Digital Key, brands on dormakaba and ASSA ABLOY integrations | Near real time | As above, plus device provisioning and Express Mode usage | Highest activation rates, cleanest arrival signal, shared-key visibility |
| Third-party mobile key overlay | OpenKey, Flexipass, PMS-native keys from Mews and Cloudbeds | Varies by underlying lock | Key issuance and first-use events; door events depend on lock tier | Arrival detection; readiness sequencing if lock is online |
The practical implication is blunt. If you are on the first row, the data play is not available to you until a lock refresh, and the business case for that refresh should include everything in this article rather than just guest convenience and plastic savings. If you are on rows two through four, you already own the data. You are simply not reading it.
Use Case One: Arrival-Time Prediction From Key Activation
The single most disruptive fact in a hotel's day is that guests do not arrive when their reservation says they will. Check-in time is a policy, not a forecast. Flights are early, drives are long, conferences let out at four. Every front office manager runs the afternoon on instinct and radio traffic, and every housekeeping director sequences a floor plan against a guess.
Mobile key changes the information available. When a guest downloads and activates their digital key, they generate a signal about their intent that is hours ahead of their physical arrival. Guests who activate their key at 9:00 in the morning from the airport are very likely to arrive before the standard check-in time. Guests who have not opened the app by 6:00 in the evening are very likely to be late. Layer this on top of digital check-in timestamps, flight data the guest volunteered at booking, and the property's own history for that guest segment, and a model can produce an arrival window for each reservation that is materially better than "after 3 PM." The concept is well enough established that a US patent has been granted on predictive hotel arrival using keyless entry systems, and enterprise vendors now describe integrating PMS and pre-arrival communication data to predict actual arrival timing more accurately than scheduled times alone.
The signals, ranked by how much they should move your forecast:
| Signal | Where it comes from | Lead time before arrival | Predictive weight | Action it should trigger |
|---|---|---|---|---|
| Digital key activated on device | Access platform or brand app | 1 to 6 hours | Very high | Move reservation to priority clean queue; pre-assign room |
| Digital check-in completed with stated arrival time | PMS or guest app | 12 to 48 hours | High | Set room-ready deadline for housekeeping board |
| Flight number or arrival airport captured at booking | Booking engine or pre-arrival message | 24 hours to weeks | Medium to high (rises when flight data is live) | Adjust forecast on day of arrival using live flight status |
| Guest segment history (business, group, leisure, loyalty tier) | CRM and PMS history | At booking | Medium | Default arrival window per segment when no other signal exists |
| Elevator or parking credential first use | Access platform | 0 to 5 minutes | Certain | Trigger room-ready confirmation or alternate-room offer; alert desk for VIPs |
| No key activation by evening | Access platform | Negative signal | High | Deprioritize room in clean sequence; flag potential no-show for revenue team |
This matters commercially as well as operationally. A property that knows which rooms need to be ready by noon and which can wait until five cleans in the right order with the same labor, sells early check-in with confidence instead of anxiety, and stops walking loyalty members to the lobby bar to wait. It also gets an early read on no-shows, which is a revenue management input rather than a housekeeping one.
Use Case Two: Room-Readiness Sequencing
Housekeeping is the largest labor line in most hotels, and the boards that run it are still, at many properties, a printed list sorted by room number. The standard benchmark is 12 to 16 rooms per attendant per eight-hour shift, with a checkout clean taking 20 to 35 minutes and a stayover 15 to 25. The waste is not in the cleaning. It is in the sequence: attendants cleaning rooms that will not be needed until evening while a guest who activated their key at 10:00 is standing in the lobby.
Access data solves the two halves of the sequencing problem at once. On the departure side, a checkout guest's last exit event tells housekeeping the room is actually vacant, not merely scheduled to vacate. Properties that rely on the front desk to mark departures lose an average of 30 to 90 minutes between physical departure and system status, because guests leave without stopping at the desk and the system only updates when someone notices. A lock event with no re-entry for a defined window, combined with a folio settled on the app, is a far better vacancy signal. On the arrival side, the key activation events from the previous section tell you which vacant rooms need to be first.
An AI orchestration layer that ingests both streams can replace the static list with dynamic, real-time routing, resequencing attendants as departures and activations arrive through the morning. Vendors and early adopters report that AI-assisted scheduling delivers 10 to 15 percent productivity gains from better assignment sequences alone. At a 300-room hotel with 20 attendants, a 10 percent productivity gain is two full-time positions, or the same headcount absorbing occupancy growth without new hires. For a deeper treatment of the forecasting side, see AI labor scheduling for hotels.
The workflow, once built, looks like this:
| Stage | Data input | System action | Human action | Measured outcome |
|---|---|---|---|---|
| Overnight (11 PM to 6 AM) | Reservations, segment history, stated arrival times | Generate baseline clean sequence with predicted arrival windows | Housekeeping manager reviews and locks exceptions (VIP, out of order) | Board ready before first shift, no morning huddle rebuild |
| Departure window (7 AM to 12 PM) | Last exit events, app folio settlement, deadbolt state | Mark rooms vacant on exit plus no re-entry for 20 minutes; promote in queue | Attendant receives next room on device, no radio call | Vacant-to-clean-start gap cut from 60 plus minutes to under 15 |
| Arrival signal window (9 AM to 3 PM) | Key activations, live flight status, elevator credential use | Reprioritize queue so activated guests' rooms clean first | Front desk sees room-ready ETA per arriving guest | Early check-in requests met without upgrade or wait |
| Inspection and release | Attendant credential exit event, inspector entry event | Auto-release room to PMS when inspector exits; push key to guest device | Inspector confirms or flags on device | Room released within 2 minutes of inspection, not at next desk update |
| Evening (3 PM onward) | Rooms with in-house guest but no entry in 24 hours | Flag for welfare check and skip-clean confirmation | Supervisor or security performs check per SOP | Safety compliance without blanket daily knocking |
The last row deserves a note. A room with an in-house guest and no door activity for 24 hours is, in most hotels, invisible until the third day when housekeeping finally insists. It is also, occasionally, a medical emergency. Access data makes this a query rather than an accident.
Use Case Three: Security Anomaly Detection
The security case for mining access data is the one that should be easiest to fund, because the downside it protects against is severe and the pattern-matching is simple. Most hotel incidents, as one security practitioner's guide puts it, begin or end at a doorway. The lock knows about every one of them. It is just not telling anyone until asked.
The 2024 Unsaflok disclosure made the stakes concrete. Researchers showed that a single pair of forged keycards could open every room at an affected property, with three million doors at 13,000 hotels in scope and roughly 64 percent still unpatched a year and a half after private disclosure. Two lessons follow. First, mobile keys on modern BLE and NFC credentials are meaningfully harder to clone than legacy MIFARE Classic cards, which is a security argument for the migration that rarely makes the business case. Second, and more important here: an attacker using forged cards leaves an anomalous pattern in the audit trail, such as a master-level credential opening rooms out of sequence or a credential with no matching issuance record. A property that reviews its logs weekly finds this after the theft. A property that streams events to a rules engine finds it in minutes.
The anomalies worth detecting, roughly in order of how often they occur:
| Anomaly pattern | What the access data shows | Likely cause | Alert routing | Response time target |
|---|---|---|---|---|
| Door held or propped open | Door-ajar state exceeding threshold (60 to 120 seconds guest room, 30 seconds service door) | Housekeeping cart, luggage, deliberate bypass of a controlled door | Security desk; housekeeping supervisor if during shift | Under 5 minutes |
| Staff credential used outside schedule | Entry event from an attendant credential outside assigned floors or shift | Legitimate reassignment, or misuse | Housekeeping manager and security, correlated with schedule system | Same shift |
| Rapid sequential entries by one credential | Multiple rooms opened in short succession, especially with no cleaning-duration dwell | Theft sweep, or a supervisor doing a legitimate walk | Security immediately; auto-correlate with camera timestamps | Under 2 minutes |
| Credential with no issuance record | Successful opening by a key ID not found in the key management system | Cloned card or legacy master not retired | Security director and engineering; lock re-encryption review | Immediate |
| Guest room entered while guest key shows in-room | Staff entry event while deadbolt engaged or guest entered and did not exit | Failure to knock and wait; privacy complaint risk | Housekeeping manager; used in coaching, not discipline, first time | Same day |
| Dormant in-house room | No entry events for 24 or more hours on an occupied room | Guest away, or guest in distress | Front office manager; welfare check per SOP | Within 2 hours of flag |
| Departed guest's credential used after checkout | Entry attempt or success from an expired or checked-out key | Checkout not processed, or a shared key still live | Front desk; verify status and revoke | Under 15 minutes |
None of this requires exotic machine learning. Most of these rules are thresholds and joins between two systems that already have the data. The AI value appears when you want to learn what normal looks like on your property for a given day of week, occupancy level, and staffing pattern, so that alert volume stays low enough for a security team of two to act on every one. The computer vision on property piece covers how camera analytics and access events reinforce each other; the pairing is stronger than either alone.
A hotel that reviews its lock audit logs once a week is doing forensics. A hotel that streams them to a rules engine is doing prevention. The data is identical. The only difference is when someone looks at it.
Use Case Four: Housekeeping Routing and Labor Intelligence
Beyond same-day sequencing, access data is the most accurate labor record most hotels will ever have, and it is collected without a single form or timesheet. Every attendant entry and exit on every room is stamped. Over weeks, that produces a true picture of clean duration by room type, by attendant, by floor, by day of week, and by occupancy level. It shows the real walk time between rooms on a badly designed floor plate. It shows which rooms consistently take 40 minutes against a 28-minute standard, which usually means a maintenance problem or a room type that is mis-credited, not a slow attendant.
This matters for three decisions owners make every year and usually make blind. First, the housekeeping labor standard itself: most properties inherit a rooms-per-shift number from a brand standard or a previous manager and never validate it. Access data validates it in a month. Second, the union or pay-per-room conversation, where the argument turns on actual clean times and both sides currently argue from anecdote. Third, the renovation and room-mix decisions, where knowing that corner suites cost 2.4 times the housekeeping labor of a standard king changes the yield math on whether to keep them as suites at all.
The data also exposes routing waste directly. An attendant whose entry events show a pattern of floor 14, floor 11, floor 14, floor 12 across a morning is being dispatched badly, and the cost is walking time that never shows on any report. Routing optimization that keeps attendants on contiguous rooms, released in arrival-priority order, is a solved problem in logistics. It is unsolved in most hotels only because the position data was never connected to the assignment engine.
What the Guest Sees, and Why Adoption Is the Constraint
Every use case above gets more accurate as more guests use mobile keys, which makes activation rate the constraint on the whole data strategy. The industry numbers are sobering. Even at mature programs, adoption among eligible guests sits at 25 to 40 percent, heavily skewed toward frequent business travelers. Leisure guests, international guests, and anyone who has been burned by a key that failed at the door at midnight default back to plastic.
Intent is not the problem. Oracle Hospitality found 74 percent of travelers would prefer a hotel that offers mobile check-in and digital keys, up from 58 percent three years earlier, and 63 percent told Hilton that the option of a digital key matters to them. J.D. Power's 2025 study recorded a 68-point satisfaction gap between guests who used the hotel app and those who did not. Guests want this. The gap between wanting and using is friction, and the friction is almost entirely the property's to remove.
Three interventions move activation more than anything else. Wallet-native keys remove the app download step and the "open the app, find the key, hold the phone" ritual; Express Mode on Apple Wallet unlocks the door without waking the phone, which is why Hyatt's Apple Wallet rollout mattered more than another brand-app key. Pre-arrival messaging that offers the key at the right moment (the evening before, not the booking confirmation) roughly doubles opt-in at properties that have tested it. And reliability at the door is non-negotiable: a single failed unlock resets a guest to plastic for years. Lock battery telemetry, which the same access platform provides, is what prevents that failure, and predictive maintenance for hotel engineering covers how to operationalize it.
The plastic argument, incidentally, is real but should stay in the sustainability report rather than the business case. Estimates range from 1,300 tons of keycards and sleeves landfilled annually in the US to far larger global figures, and a 200-room hotel loses roughly 12,000 cards a year. Hilton credited Digital Key with 125 tons of plastic avoided by 2022. Worth reporting. Not what pays for the integration.
Implementation: A 120-Day Sequence
The mistake to avoid is treating this as a lock project. It is a data integration project that happens to start at the lock. The work is in the connection between the access platform and the systems that can act on its events, and in the rules and models that sit between them. Custom integration and orchestration work of this kind is precisely where an experienced partner shortens the path; hotels that want to skip the trial and error often engage a team to build the event pipeline and the first set of rules, and HospitalityOS's custom integrations and automations practice is built for exactly this scope.
| Phase | Days | Work | Owner | Indicative cost |
|---|---|---|---|---|
| 1. Audit and access | 1 to 20 | Confirm lock architecture row (table one); obtain API or event-export access from lock vendor; inventory master and staff credentials; retire orphaned keys | Director of engineering with security | $0 to $5,000 (vendor API enablement fees vary) |
| 2. Event pipeline | 15 to 45 | Stream door, key-lifecycle, and battery events into a data store or integration hub; join to PMS reservation and housekeeping room-status records | Integration partner or IT | $15,000 to $40,000 |
| 3. Security rules first | 30 to 60 | Deploy the seven anomaly rules from table four; tune thresholds for two weeks; route alerts to existing security channels | Security director | Included in pipeline; staff time |
| 4. Readiness sequencing | 45 to 90 | Vacancy-on-exit logic; arrival-priority queue fed to housekeeping app; measure vacant-to-clean gap and early check-in fulfillment | Executive housekeeper and front office manager | $10,000 to $30,000 if housekeeping platform needs a connector |
| 5. Arrival prediction model | 75 to 120 | Train on 60 days of key activation, check-in, and actual first-entry data; publish arrival windows to desk and housekeeping; feed no-show signal to revenue | Revenue and front office, with data partner | $10,000 to $25,000 |
| 6. Labor intelligence review | 90 to 120 | Validate clean-time standards by room type from access data; adjust credits and routing; present findings to ownership | General manager | Staff time |
The reason security rules go first is not that they are the most valuable. It is that they are the easiest to prove, they require no change to any frontline workflow, and a single caught incident buys the political capital for the housekeeping changes, which do require frontline adoption. Sequence for momentum, not for theoretical ROI.
Total cost for a mid-sized hotel already on online locks lands between $35,000 and $100,000 in the first year, depending on how much of the integration exists already and whether the housekeeping platform speaks a modern API. Against two housekeeping FTEs, one prevented theft incident with its associated liability, and a measurable lift in early check-in revenue and loyalty satisfaction, payback inside the first year is the realistic expectation, not the optimistic one. The hotels that fail to get there are almost always the ones that skipped phase one and discovered at day 60 that their locks were offline standalone units all along.
What to Ask Your Lock Vendor Next Week
Owners and GMs do not need to understand lock protocols to drive this. They need five questions, asked in writing, to whoever manages the access contract.
Does our current system make door events available to another system in real time, and if so, through what interface? What is the latency between a door opening and that event being available? Can we receive key issuance, activation, first use, and expiry as distinct events? What does the vendor charge for API access, and is it in our current contract? And if the answer to the first question is no, what is the upgrade path and its cost, and can it be phased floor by floor?
The answers sort every property into one of two groups: those that can start next month, and those whose next lock refresh needs to be justified on data rather than on guest convenience alone. Either way, the conversation changes. The door stops being a convenience feature and starts being what it already is: the most honest record of what actually happens in the building, hour by hour, guest by guest. Hotels that read it will run tighter, safer, and more profitably than those that keep treating it as a way to skip the desk.
Frequently Asked Questions
Can we use access data for these purposes without violating guest privacy?
Yes, with discipline. Door events are operational data about the property's own rooms and credentials, and hotels have always retained lock audit trails for security. What changes is the purpose and the breadth of use, and that requires three things: a clear statement in your privacy policy that access events are used for security and operational purposes, strict role-based access so that housekeeping sees room status rather than individual guest movement, and retention limits that delete guest-level events after a defined period, typically 30 to 90 days, while keeping anonymized aggregates for labor analysis. In the EU, treat door events as personal data under GDPR and document the legitimate-interest basis. Never use access data for marketing or to profile individual guests' habits across stays. Used for readiness, safety, and labor, it is defensible everywhere. Used to know when a guest goes to the bar, it is not.
We are on offline standalone locks. Is there anything we can do without a full replacement?
Less than you would like, but not nothing. Some offline systems can be upgraded with wireless gateways floor by floor, bringing existing locks online without replacing the hardware; ask your vendor about an online retrofit kit for your specific model. A third-party mobile key overlay can give you the key-activation signal for arrival prediction even if door events stay offline, because the activation happens in software rather than at the lock. And the housekeeping labor analysis can be approximated with periodic audit pulls, which are slow but sufficient to validate clean-time standards once a quarter. What you cannot do without online locks is real-time security alerting or vacancy-on-exit sequencing. If those matter to you, and they should, build the lock refresh case on this article rather than waiting for the batteries to justify it.
Which matters more for the data strategy: brand-app keys or wallet-native keys?
Wallet-native, and the gap is widening. Both generate the same door events once the guest is on property, so the operational data is equivalent. The difference is activation rate, which is the constraint on everything. Wallet keys remove the app download, work without unlocking the phone, update automatically on room change or extension, and can be shared with a travel companion in a way the property can see and control. Properties moving to wallet keys consistently report meaningfully higher activation than app-only programs, and more activated keys means better arrival prediction and better readiness sequencing. If you are choosing an access platform today, wallet support on both Apple and Google should be a requirement, not a nice-to-have. If you are on a brand system, push your brand on the wallet roadmap.
How do we handle staff concerns about being tracked by their credential?
Directly and early, because the concern is legitimate and the data will surface performance differences whether or not you intend it to. Three practices work. First, be explicit that entry and exit events already exist and have for years; what is new is using them to make assignments fairer and to protect staff from false accusations, which the audit trail does routinely. Second, use the data to fix the system before you use it to evaluate people: when a room type consistently runs over standard, adjust the credit rather than coaching the attendant. Third, involve housekeeping leadership and, where applicable, union representatives in setting the thresholds and the review process. Properties that introduce this as a routing and safety tool, and demonstrate the fairness benefits first, get adoption. Properties that introduce it as a productivity monitor get a grievance.
What is a realistic first-year return, and how do we measure it?
For a 200 to 400 room hotel already on online locks, expect first-year benefits in three buckets. Housekeeping productivity of 8 to 12 percent from sequencing and routing, worth one to two FTEs or the equivalent absorbed occupancy growth. Early check-in and room-ready satisfaction gains that show up in loyalty and review scores and in captured early check-in fees where charged. And security value, which is hard to book until an incident is prevented, but which materially reduces liability exposure and often satisfies an insurer's security-controls questionnaire. Measure with four numbers set at day zero: the average gap between physical departure and clean start, the percentage of early check-in requests fulfilled on the guest's arrival, rooms cleaned per attendant shift, and security alerts generated and resolved per month. If those four have not moved by day 120, the pipeline is built but the workflows have not changed, and that is a management issue rather than a technology one.
Peter Mack is a hospitality technology strategist and founder of HospitalityOS, helping independent hotels and resorts implement AI systems that drive revenue and reduce operational costs. With 25 years in hospitality operations and technology, he has worked with properties of all types and in every region as both a General Manager, Founder, Operator, Asset Manager, and Owner.