A Credential Is Not a Person
What a badge read, a PIN entry or a terminal punch actually attests, the inference between that and a person, and why writing the inference down changes the case.
One badge read, and the claims it was asked to support
Of six claims, one is supported, two are consistent with more than one explanation, and three rest on nothing. This is one employer's own file, not a statement of what any rule requires about evidence.
Every time system records a credential rather than a person. A badge read attests that a card was presented to a reader. A PIN entry attests that four digits were typed. A punch attests that a button was pressed on a terminal. None of those is a statement about who was standing there, and the step from the first to the second is an inference the employer makes.
The identity gap described in “A Credential Is Not a Person” matters when teams assess hourly timesheet template in a transparent workflow for hourly timesheet template. The platform may make an activity or timestamp visible, yet a responsible review still distinguishes the device or account from the person, checks another source and records what the evidence does not establish.
That inference is usually reasonable. It is also almost never written down, and the cases that collapse are the ones where nobody noticed they were making it.
For a separate benchmark relevant to “A Credential Is Not a Person”, consult the U.S. National Archives records management guidance. Use it to test scope and safeguards against an external standard before the process is approved.
What each method actually attests
Stated plainly, the list is shorter than most people expect.
| Method | What it records | What it does not establish |
|---|---|---|
| Badge or card | A credential was presented | Who held it |
| PIN | A sequence was typed | Who typed it |
| Mobile app check-in | A device reported a location | Who held the device |
| Fingerprint or face | A biometric matched a template | Only that, within the system's error rate |
| Workstation sign-on | A credential authenticated | Who was at the keyboard |
| Supervisor confirmation | A person says they saw somebody | What they actually remember |
Only one row attests to a person at all, and even that one attests to a match rather than to an identity.
Writing the inference down
The useful discipline is a single sentence in the file: what the record shows, and what is being inferred from it.
The badge read establishes that this credential was presented at 07:51. We infer that the employee presented it, because the badge is issued to them and has not been reported lost. We have no record of who held it.
That paragraph takes a minute and changes everything downstream. It makes the gap visible to the person making the decision, it makes the case honest when it is put to the employee, and it survives being read by somebody else two years later.
An absence is not a record
The second common error is treating silence as evidence. Nothing was recorded between eight and half past four, so the person was absent; nobody reported the badge lost, so the employee had it.
Both of those turn an absence into a positive finding. A system that records nothing has not recorded an absence; it has recorded nothing. Whether that gap means anything depends on whether the system would have recorded something had the person been there, which is a question about the system rather than about the person.
Two records of one credential are one source
Where a door reader and a time terminal both show the same badge within a minute, the natural reading is that two independent systems agree.
They do not. They are two readings of one credential, and if the credential was presented by somebody else, both are wrong in the same way. Independence means a different kind of evidence — a face, a colleague, an output, a device the person carries — not a second machine reading the same card.
The error rate nobody asks for
Biometric systems have a false match rate and a false non-match rate, and both are published by the vendor and almost never requested by the employer relying on the output.
Asking for them is not pedantry. If a system is relied on to say that this person and no other presented themselves, the rate at which it is wrong is part of what the record is worth, and it is the first thing anybody competent will ask about.
What this changes in practice
Not much, most of the time: the inference holds, the person agrees, and nothing turns on it. The discipline earns its keep in the small number of cases where it is contested.
In those, an employer who wrote down what the record showed and what was inferred from it is in a wholly different position from one that recorded a conclusion. The second has no answer when the inference is questioned, because it was never identified as one.
The register that makes it possible
All of this depends on knowing which credential belongs to whom, on the day in question, and that register is frequently less reliable than the logs drawn from it.
Badges get reissued, temporary cards are handed out and never recovered, and a credential number that belonged to one person in March belonged to somebody else by September. Before drawing anything from a badge number, confirm who held it on the date — from the issue register, not from the current one.
Where to put it
In whatever file the matter lives in, at the point the record is first relied on — not at the end, when a conclusion is being written up.
The order matters because an inference written after a decision tends to be constructed to support it. Written at the point the record is pulled, it is a description of what was found, which is what it needs to be.