> ## Documentation Index
> Fetch the complete documentation index at: https://help.rekkeh.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Rekkeh safety, emergency, and access rules

> Set emergency lockdown, incident SLAs, visitor rules, notification compliance, commercial access, contractor authorization, and emergency contacts in Rekkeh.

Safety & emergency settings is where facility administrators configure emergency lockdown, incident SLAs and escalation, visitor rules, notification and compliance options, commercial access, contractor access, and emergency routing contacts. Open it from **Settings > Safety & trust > Safety & emergency**. The page requires a signed-in account and the safety module for your facility; without them you're redirected to the dashboard.

The page is one long surface with six stacked cards, each with its own save action. Estate managers and platform admins can edit all six; other roles can review the first five read-only. Emergency contacts has no frontend role gate, but the backend still requires the right permission to create, edit, or delete contacts.

## Security & Escalation

This card controls emergency lockdown, how long offline keys stay valid, and how quickly incidents escalate. It is where you prepare for and respond to an emergency.

### Emergency lockdown

Lockdown blocks new gate check-ins until it is cleared. Guards can still override a lockdown with a supervisor note. The card shows **Normal operations** when inactive and **LOCKDOWN ACTIVE** with the time it started when active.

<Warning>
  Activating lockdown immediately blocks new gate check-ins for all visitors until you clear it.
</Warning>

<Steps>
  <Step title="Activate lockdown">
    Enter a **Lockdown reason** (5 to 500 characters, for example "Security incident at north gate") and click **Activate lockdown**.
  </Step>

  <Step title="Confirm">
    Confirm in the dialog. New gate check-ins are blocked until you clear it.
  </Step>

  <Step title="Clear lockdown">
    To resume normal access, click **Clear lockdown** and confirm. Gate check-ins resume under normal access rules.
  </Step>
</Steps>

Only roles listed in **Lockdown authorized roles** can activate or clear lockdown. The default roles are Estate Manager, Platform Admin, and Security Officer; Guard is available but not selected by default. At least one role must stay selected, or saving fails with **Select at least one lockdown-authorized role**. If your role isn't authorized, you'll see **Your role cannot trigger lockdown per current policy.**

**Scenario:** A security incident happens at the north gate. A security officer with lockdown authority activates lockdown with a reason. New visitors can't check in at any gate until management clears it, while guards can still let known people out or override with a supervisor note.

### Offline key rotation

**Offline key rotation** sets how often offline access keys expire, either **Daily (expires end of day)** or **Weekly (expires end of week)**. Daily is the default.

### SLA escalation multiplier

**SLA escalation multiplier** escalates an incident after its SLA window times this factor. It accepts 1 to 10 in steps of 0.5 and defaults to 2 (escalate after 2 times the SLA window).

### Incident SLA hours by severity

**Incident SLA hours by severity** sets how long each severity level has before it is considered overdue. These are the defaults; the emergency SLA is five minutes unless you change it.

| Severity  | Default SLA             |
| --------- | ----------------------- |
| Low       | 72 hours                |
| Medium    | 48 hours                |
| High      | 24 hours                |
| Critical  | 4 hours                 |
| Emergency | 5 minutes (0.083 hours) |

### Critical-user promotion rules

Three checkboxes control automatic scrutiny at the gate, all enabled by default:

* Promote watchlist hits to critical scrutiny at the gate
* Auto-watchlist after repeated failed scans
* Auto-flag a host with critical issues when an incident SLA escalates

Click **Save security policies** to apply changes. Lockdown activation and clearing are separate actions with their own confirmations.

## Visitor Rules

Visitor rules set the QR, visit duration, visiting hours, OTP, guest caps, and auto-flag thresholds enforced at the gate. Only estate managers can change them; other roles see the current settings read-only.

| Setting                          | Default                                | Limits             |
| -------------------------------- | -------------------------------------- | ------------------ |
| QR expiry (minutes)              | 30                                     | 10-60              |
| Max visit duration (hours)       | 12                                     | 1-48               |
| Visiting hours end               | 22:00                                  | HH:mm, 00:00-23:59 |
| Two-factor (QR + OTP)            | Mandatory first visit, optional repeat | Four options       |
| Max visitors per invite          | 5                                      | 1-100              |
| Recurring vendor weekly cap      | 3                                      | 1-14               |
| Vendor daily tier-bump threshold | 2                                      | 1-20               |
| Unaccompanied minor min age      | 16                                     | 0-18               |
| Failed-scan auto-flag threshold  | 3                                      | 1-20               |

The **Two-factor (QR + OTP)** options are: mandatory for first-time guests, mandatory first visit and optional on repeat (default), always require QR + OTP, or never require OTP (QR only).

**Scenario:** A delivery driver who scans in every day can pass with a short-lived QR and optional OTP, but a first-time visitor must complete both QR and OTP before the gate opens. If a visitor scans a denied pass three times in 24 hours, they are automatically flagged on the watchlist.

### Overstay detection

Overstay detection flags guests who stay past their expected checkout and escalates notifications. Expected checkout is capped at the visiting hours end when that is enabled.

| Setting                          | Default         | Limits          |
| -------------------------------- | --------------- | --------------- |
| Enable overstay detection        | On              | Toggle          |
| Grace period (minutes)           | 0               | 0-120           |
| After-hours overstay rule        | Off             | Toggle          |
| Escalation thresholds (minutes)  | 15, 30, 60, 120 | Comma-separated |
| Auto-flag at critical escalation | On              | Toggle          |
| Allow supervisor force checkout  | On              | Toggle          |

Click **Save visitor rules** to apply changes. An invalid time shows **Visiting hours end must be HH:mm (e.g. 22:00)**.

## Notifications & Compliance

This card sets the default notification channel, whether SMS can go to unverified numbers, how long data is kept, and the registration consent text. Only estate managers can edit these settings.

### SMS to unverified phone numbers

**SMS to unverified phone numbers** is off by default. Rekkeh only auto-texts numbers verified with a one-time code. Guest invites and guardian pickup codes stay in the app until you turn this on; hosts can still share the pass themselves.

### Default notification channel

**Default notification channel** is the suggested default for new residents. The options are **Push (in-app)** (default), **SMS**, **WhatsApp**, and **Email**. Email is opt-in until each resident enables it in their app preferences.

### Data retention

**Data retention (days)** sets how long notifications and access logs are kept before they are purged daily, per NDPR. It defaults to 365 and accepts 30 to 3650 days.

### Consent

**Consent version** and **Consent text (shown at registration)** define the consent residents accept when they register. Bump the version when the consent text changes; residents must accept the new version at registration. The consent text defaults to "I agree to receive security and access notifications," must be at least 20 characters, and can be up to 2,000 characters.

Click **Save notification & compliance** to apply changes.

## Commercial access

Commercial access controls how shops and tenants receive visits. Businesses can only use the access modes you allow here. This card also covers gate and kiosk walk-ins, business-issued passes, and who can override a deny.

| Setting                                    | Default                                          |
| ------------------------------------------ | ------------------------------------------------ |
| Enable commercial access for this facility | Off                                              |
| Open walk-in                               | On                                               |
| Approval required                          | On                                               |
| Invite only                                | On                                               |
| Allow gate walk-in                         | On (disabled when commercial access is off)      |
| Allow kiosk walk-in                        | Off                                              |
| Allow business-issued passes               | On (disabled when commercial access is off)      |
| Require phone on open walk-in              | On (disabled when commercial access is off)      |
| Incident: force invite-only                | Off                                              |
| Default pass duration (hours)              | 4                                                |
| Max pass duration (hours)                  | 12                                               |
| Roles that may override a deny             | Estate Manager, Platform Admin, Security Officer |

At least one access mode must stay selected. Gate kiosk mode self-service registration requires the relevant walk-in option. When phone-on-walk-in is off, watchlist phone matching and repeat recognition don't apply to those walk-ins. Overriding a deny always requires a reason and is audited. On-site exit stays allowed when a pass is expired or revoked.

Click **Save commercial settings** to apply changes.

## Contractor access authorization

Contractor access gives standing contractors entry that expires on a schedule. Their identity stays in the directory after expiry; renew to restore entry.

| Setting                                        | Default  | Limits                      |
| ---------------------------------------------- | -------- | --------------------------- |
| Enable standing contractor access at this site | On       | Toggle                      |
| Default validity (days)                        | 60       | Between minimum and maximum |
| Minimum (days)                                 | 1        | 1-365                       |
| Maximum (days)                                 | 365      | 1-365                       |
| Require re-approval when renewing access       | On       | Toggle                      |
| Remind (days before expiry)                    | 14, 7, 1 | Comma-separated             |

There is no no-expiry option. Validity is normalized to whole days between the configured minimum and maximum, and reminders are normalized to positive whole days below the default validity. Click **Save contractor access settings** to apply changes.

**Scenario:** A maintenance company's technician gets 60 days of standing access with reminders at 14, 7, and 1 days before expiry. When access expires, the technician stays in the directory but can't enter until you renew and re-approve.

## Emergency Contacts

Emergency contacts are tagged contacts surfaced on panic, duress, and critical incidents. The list shows each contact's name, phone number, display order, and alert-type badges, and marks inactive contacts with an **Inactive** badge.

<Steps>
  <Step title="Add or edit a contact">
    Click **Add contact** to open the add modal, or **Edit** on an existing contact.
  </Step>

  <Step title="Enter details">
    Enter the contact **Name** (required) and **Phone (E.164)** (required). The phone defaults to Nigeria (+234) and is normalized to E.164 before saving.
  </Step>

  <Step title="Set order and alert types">
    Set the **Display order** and choose at least one **Alert type**: Security, Fire, Medical, Police, or Management. New contacts default to Security.
  </Step>

  <Step title="Save">
    Keep **Active (visible to residents and alert routing)** checked to route alerts to this contact, then click **Save**.
  </Step>
</Steps>

Save is disabled when the name is blank, the phone is invalid, or no alert type is selected. To remove a contact, use the delete icon and confirm. The contact is removed from panic, duress, and critical incident routing.

**Scenario:** You add the estate security head with alert types Security and Police, and the estate doctor with Medical. When a resident triggers a duress alert, the matching contacts are surfaced to the responding team based on their alert types.

## Permissions and validation

Access to the page and to each action is controlled by the safety module and your role, not by your subscription plan. The first five cards are editable by estate managers and platform admins; other roles see them read-only. Emergency contacts render editable for anyone who reaches the page, but the backend still requires the right permission to create, edit, or delete a contact, so a role without it sees a save or delete failure.

Key validation to remember:

* Lockdown reason must be 5 to 500 characters, and at least one lockdown-authorized role must stay selected.
* Visiting hours end must be in HH:mm format.
* Consent version is required, and consent text must be at least 20 characters.
* Emergency contact phone numbers must be valid for the selected country.

## Related articles

For how safety signals appear during operations, see [Understand your Rekkeh admin dashboard](/getting-started/admin-dashboard). To set up your facility and issue your first invite, see [Getting started with Rekkeh](/getting-started/quickstart).
