Security & Escalation
This card controls emergency lockdown, how long offline keys stay valid, and how quickly incidents escalate. It is where you prepare for and respond to an emergency.Emergency lockdown
Lockdown blocks new gate check-ins until it is cleared. Guards can still override a lockdown with a supervisor note. The card shows Normal operations when inactive and LOCKDOWN ACTIVE with the time it started when active.1
Activate lockdown
Enter a Lockdown reason (5 to 500 characters, for example “Security incident at north gate”) and click Activate lockdown.
2
Confirm
Confirm in the dialog. New gate check-ins are blocked until you clear it.
3
Clear lockdown
To resume normal access, click Clear lockdown and confirm. Gate check-ins resume under normal access rules.
Offline key rotation
Offline key rotation sets how often offline access keys expire, either Daily (expires end of day) or Weekly (expires end of week). Daily is the default.SLA escalation multiplier
SLA escalation multiplier escalates an incident after its SLA window times this factor. It accepts 1 to 10 in steps of 0.5 and defaults to 2 (escalate after 2 times the SLA window).Incident SLA hours by severity
Incident SLA hours by severity sets how long each severity level has before it is considered overdue. These are the defaults; the emergency SLA is five minutes unless you change it.Critical-user promotion rules
Three checkboxes control automatic scrutiny at the gate, all enabled by default:- Promote watchlist hits to critical scrutiny at the gate
- Auto-watchlist after repeated failed scans
- Auto-flag a host with critical issues when an incident SLA escalates
Visitor Rules
Visitor rules set the QR, visit duration, visiting hours, OTP, guest caps, and auto-flag thresholds enforced at the gate. Only estate managers can change them; other roles see the current settings read-only.
The Two-factor (QR + OTP) options are: mandatory for first-time guests, mandatory first visit and optional on repeat (default), always require QR + OTP, or never require OTP (QR only).
Scenario: A delivery driver who scans in every day can pass with a short-lived QR and optional OTP, but a first-time visitor must complete both QR and OTP before the gate opens. If a visitor scans a denied pass three times in 24 hours, they are automatically flagged on the watchlist.
Overstay detection
Overstay detection flags guests who stay past their expected checkout and escalates notifications. Expected checkout is capped at the visiting hours end when that is enabled.
Click Save visitor rules to apply changes. An invalid time shows Visiting hours end must be HH:mm (e.g. 22:00).
Notifications & Compliance
This card sets the default notification channel, whether SMS can go to unverified numbers, how long data is kept, and the registration consent text. Only estate managers can edit these settings.SMS to unverified phone numbers
SMS to unverified phone numbers is off by default. Rekkeh only auto-texts numbers verified with a one-time code. Guest invites and guardian pickup codes stay in the app until you turn this on; hosts can still share the pass themselves.Default notification channel
Default notification channel is the suggested default for new residents. The options are Push (in-app) (default), SMS, WhatsApp, and Email. Email is opt-in until each resident enables it in their app preferences.Data retention
Data retention (days) sets how long notifications and access logs are kept before they are purged daily, per NDPR. It defaults to 365 and accepts 30 to 3650 days.Consent
Consent version and Consent text (shown at registration) define the consent residents accept when they register. Bump the version when the consent text changes; residents must accept the new version at registration. The consent text defaults to “I agree to receive security and access notifications,” must be at least 20 characters, and can be up to 2,000 characters. Click Save notification & compliance to apply changes.Commercial access
Commercial access controls how shops and tenants receive visits. Businesses can only use the access modes you allow here. This card also covers gate and kiosk walk-ins, business-issued passes, and who can override a deny.
At least one access mode must stay selected. Gate kiosk mode self-service registration requires the relevant walk-in option. When phone-on-walk-in is off, watchlist phone matching and repeat recognition don’t apply to those walk-ins. Overriding a deny always requires a reason and is audited. On-site exit stays allowed when a pass is expired or revoked.
Click Save commercial settings to apply changes.
Contractor access authorization
Contractor access gives standing contractors entry that expires on a schedule. Their identity stays in the directory after expiry; renew to restore entry.
There is no no-expiry option. Validity is normalized to whole days between the configured minimum and maximum, and reminders are normalized to positive whole days below the default validity. Click Save contractor access settings to apply changes.
Scenario: A maintenance company’s technician gets 60 days of standing access with reminders at 14, 7, and 1 days before expiry. When access expires, the technician stays in the directory but can’t enter until you renew and re-approve.
Emergency Contacts
Emergency contacts are tagged contacts surfaced on panic, duress, and critical incidents. The list shows each contact’s name, phone number, display order, and alert-type badges, and marks inactive contacts with an Inactive badge.1
Add or edit a contact
Click Add contact to open the add modal, or Edit on an existing contact.
2
Enter details
Enter the contact Name (required) and Phone (E.164) (required). The phone defaults to Nigeria (+234) and is normalized to E.164 before saving.
3
Set order and alert types
Set the Display order and choose at least one Alert type: Security, Fire, Medical, Police, or Management. New contacts default to Security.
4
Save
Keep Active (visible to residents and alert routing) checked to route alerts to this contact, then click Save.
Permissions and validation
Access to the page and to each action is controlled by the safety module and your role, not by your subscription plan. The first five cards are editable by estate managers and platform admins; other roles see them read-only. Emergency contacts render editable for anyone who reaches the page, but the backend still requires the right permission to create, edit, or delete a contact, so a role without it sees a save or delete failure. Key validation to remember:- Lockdown reason must be 5 to 500 characters, and at least one lockdown-authorized role must stay selected.
- Visiting hours end must be in HH:mm format.
- Consent version is required, and consent text must be at least 20 characters.
- Emergency contact phone numbers must be valid for the selected country.