Skip to content
What the Record Proves

Home / Identity

Why Credentials Get Shared

The six reasons badges and codes get passed around, why most of them are operational rather than dishonest, and how to find out which one you have.

Identity · Reference

Credentials get shared for six reasons and only one of them is theft. A queue at the terminal, a reader that fails, a shift that starts before the door opens, a lateness rule with teeth, a forgotten badge, and somebody genuinely being paid for hours they did not work. The responses to the first five are operational; only the last is a conduct matter.

The identity gap described in “Why Credentials Get Shared” matters when teams assess see the available configuration choices for daily schedule template. The platform may make an activity or timestamp visible, yet a responsible review still distinguishes the device or account from the person, checks another source and records what the evidence does not establish.

Organisations that treat all six as the last spend heavily on controls and are surprised when the behaviour continues in a different form.

Teams reviewing “Why Credentials Get Shared” can cross-check their approach against the U.S. Justice Department computer crime resources. The comparison is most useful when the organisation records which recommendations apply, which do not and why.

The six, and what each looks like

A queue produces clustering at the hour, several badges at one reader, and no gap anywhere else in the day.

A failing reader produces repeated attempts by one person followed by a successful read on a different credential, and it is visible in the error log if anybody looks.

A door that opens later than the shift starts produces a cluster of punches by whoever has a key, on behalf of everyone waiting.

A lateness rule produces punches in the ninety seconds before the hour and almost none after it, which is a distribution no honest process produces by accident.

A forgotten badge produces a single isolated instance with an obvious explanation, usually volunteered.

Genuine absence produces something different: no clustering, no group, and a second record that disagrees.

Telling them apart

  1. Plot punches by minute around shift starts, for a month.
  2. Pull the reader error log for the same period.
  3. Check what time the doors and equipment stores actually open.
  4. Read the lateness policy and ask three people what happens if they are late.
  5. Look for a second record — output, vehicle, system — that disagrees.
  6. Only then consider whether anybody was absent.

Steps one to four take an afternoon between them and resolve most sites. Step five is where a real case begins.

The lateness rule is usually the cause

Where being a minute late has a consequence — a point on a record, a deduction, a conversation — and the terminal is slow, passing a badge forward is the rational response for people who are physically present and on time.

That is worth saying out loud internally, because it reframes the problem. The behaviour is produced by the interaction of a rule and a queue, and either side of that can be changed for very little.

What people say when asked

Surprisingly, they tell you. Asked neutrally and without jeopardy — what happens at shift start, what gets in the way — people describe the arrangement accurately and without embarrassment, because in their view nothing dishonest is happening.

That conversation is more informative than any log and it is the step organisations skip, because asking feels like condoning.

Ask the question before building the case. If the answer is "the terminal takes four minutes and we'd all be marked late", the investigation is over and the fix is a second terminal.

Where it is genuinely theft

It exists, it is a minority, and it has a different shape: one person rather than a group, no clustering, and corroboration that disagrees rather than being absent.

Those cases deserve a proper investigation and they are easier to run once the operational causes have been removed, because the noise is gone and what is left stands out.

The cost of getting the diagnosis wrong

Treating a queue as dishonesty produces an expensive control, a workforce that has been told what the employer thinks of it, and the same behaviour expressed differently.

Treating dishonesty as a queue produces a control that does not address it and a case nobody brings. Both errors are avoidable by spending the afternoon described above before spending anything else.

The badge nobody reported lost

A credential that has gone missing and not been reported is the quiet version of this problem: somebody has a working badge that belongs to nobody, and every record it produces is attributed to a former holder.

Reconciling issued credentials against current staff, once a quarter, finds them. It is a short query, it is nobody's job, and it removes an entire category of record that cannot be interpreted.

Writing down the diagnosis

One paragraph: what the pattern looked like, what was checked, what the cause was judged to be and on what basis.

That paragraph is what makes the subsequent decision defensible and what stops the organisation reaching for a control it does not need. It is also the only thing that will tell the next person, in three years, why the terminal was moved.