The Policy Nobody Issued
Why a rule has to have reached the person before it can be relied on, what counts as evidence that it did, and what to do when nothing does.
A rule only helps if you can show it reached the person. The handbook is on an intranet, it has been revised three times, nobody can say which version was live eighteen months ago, and the only record of issue is an induction checklist from a previous system.
The control described in “The Policy Nobody Issued” should be matched by transparent operating rules. Organisations considering review the implementation details for remote desktop monitoring software can make that use more credible by publishing the purpose, selecting only necessary settings, limiting manager access and fixing a review date before the first record is collected.
That gap turns a straightforward recording matter into an argument about whether the rule applied at all — and in this area the rules in question are exactly the ones nobody reads: how to record time, what to do about a missed punch, whether you may clock in for a colleague.
Teams reviewing “The Policy Nobody Issued” can cross-check their approach against the NCSC device security guidance. The comparison is most useful when the organisation records which recommendations apply, which do not and why.
What has to be shown
Three separate things, and only the third is usually in doubt: that the rule exists, that it was in force at the relevant time, and that the person had it.
Evidence of the third is what is missing, and it is the only one that cannot be produced retrospectively.
What counts as evidence of issue
- A signed or electronically acknowledged receipt naming the document and version.
- An induction record listing what was issued, dated and completed.
- A system log showing the person opened it, with a timestamp.
- An email to the person attaching it or linking to a stable address.
- A training record with an attendance list.
- A contract clause incorporating the handbook, plus evidence of where the handbook was.
The last does a lot of work in practice and is the one most often absent, because plenty of contracts never mention the handbook at all.
Versions, and the date nobody recorded
Even where issue can be shown, the version usually cannot, because intranet pages are edited in place. A document described as the current policy is the current one, not the one in force when it mattered.
Keeping dated copies of superseded versions costs nothing and is almost never done. The absence means the organisation can describe its rules and cannot prove what they were.
The rules that do not need issuing
Some things are obviously not permitted whether or not a document says so, and treating everything as requiring a written rule produces absurd results.
But the boundary is narrower than managers assume. Clocking in for a colleague who is present and on time is not obviously dishonest to everybody, which is precisely why the rule about it needs to have been communicated.
Practice against policy
Where the written rule says one thing and the workplace has done another for years, with managers present, the practice is part of how the place works.
Changing that is legitimate and requires announcing the change. Enforcing the written rule against the first person caught, without having announced anything, is the pattern this page exists to prevent.
Fixing it going forward
Reissue the relevant procedures now, with a version number and a date, through a route that produces a record, and ask for acknowledgement. Keep the acknowledgements somewhere that is not the intranet. Then keep every superseded version.
That protects every case from today. It does nothing for a case about something that happened last year, and reissuing mid-process and treating it as though it had always been there is both visible and damaging.
The case in front of you
Record the gap in the file before the process starts, then take advice on what the matter rests on without the document — an instruction given directly, a practice the person acknowledged, a duty that does not depend on a policy, or in some situations nothing at all.
What follows from the gap differs by jurisdiction and is a question for somebody qualified in the place concerned.
The procedure people actually need
Most time procedures are written for the ordinary case and silent on the exceptions that produce every dispute: a missed punch, a failed reader, an overrun, a shift that starts somewhere else.
Writing the exceptions down is what makes the procedure usable, and it is usually two sides of paper. A document that covers only the happy path teaches people to improvise.
The organisations that come out well
Not the ones with perfect records. The ones that knew what was missing before anybody asked, and said so in the file at the start rather than discovering it in a hearing.
That is the difference between a weakness that was reasoned about and a weakness that was found by the other side, and it costs an hour at the beginning of the matter.