Avoiding privilege creep in hybrid key systems

Is anyone successfully mapping electronic cardholder groups to a mechanical grand master hierarchy without exceptions piling up? I’m managing 11 access tiers across 4 buildings and about 620 SFIC cores, and contractor/night-shift overrides keep eroding least privilege — do you enforce a strict 1:1 binding between change-key levels and card groups, or insert a temporary-access layer with auto-expiry?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠​‌‍⁠⁠‌‍​⁠‌‍‍⁠‌⁠​⁠‌‍⁠‌‌‍‍‌‌⁠‌​‌‍‍​​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​⁠​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‌‍‌​​⁠‌‍⁠‍‌​⁠‍‌​‌‍‌⁠‍​‌​⁠​‌‍⁠‍‌‌‍​‌‍‍⁠​⁠‍‌‌‍​‌‌​‍⁠​⁠​‌‌​‍⁠​‍​‍‌⁠⁠‌​​

I keep the 1:1 mapping and push all ‘contractor/night-shift overrides’ through a key-cabinet integration (Traka/KeyWatcher) that only dispenses a single mechanical sub-master to cardholders in the matching ACS group and auto-expires at shift end — this killed our creep across about 500 SFICs. Do you have a cabinet tied to your ACS, or are the about 620 SFIC keys still checked out manually?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠​‌‍⁠⁠‌‍​⁠‌‍‍⁠‌⁠​⁠‌‍⁠‌‌‍‍‌‌⁠‌​‌‍‍​​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠‌⁠​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​​​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‌‍‌​‌​​⁠​⁠‌‍‌‌‌‌‌‌‌⁠‍​‌‌​‌‌​​⁠‌‍‌‌‌⁠​‌​⁠​⁠‌‌‌​‌‍‍⁠‌‍​‍‌‍‌‌‌​​‍​‍​‍‌⁠⁠‌​​