How should old smart-lock access codes and user accounts be audited?
Revoke carefully and verify delivery
Remove credentials that no longer have a legitimate purpose using the model's documented process. Review integrations separately and preserve your own owner access and recovery information. Check that changes have reached each affected device before concluding the work is complete. If physical keys were issued, account for them separately; do not assume an app change disables a mechanical key.