Every credential has a named custodian and a clear reason to exist.
Each fob and mobile credential is recorded against the lot it's authorised for, the person who's responsible for it, and the authority that issued it. When the lot is sold or the tenancy ends, the credential follows, either to the new authorised holder or to deactivation. There's no 'found in a drawer' condition.
This works because every change goes through an audit wrapper that can't be bypassed. The platform is opinionated: if your committee wants to break the chain on a one-off basis, that takes an explicit authorised exception, not a back door.