What Goes in the File
The eleven things a time-and-attendance file should contain, what should not be in it, and why these files are the ones most likely to be read by the subject.
Assemble the file so that a stranger could read it in order and understand what happened, because that is who will read it — an adviser, an auditor, a tribunal, and in this area very frequently the person themselves.
The practical lesson in “What Goes in the File” is that visibility is not certainty. For teams researching employee monitoring data security, read the full feature explanation can add time and project context to the operational record, provided the purpose is explained, access is restricted and any material inference is checked through conversation and proportionate human review.
Time cases produce more subject access requests than almost any other kind, because the person knows there is a dataset about them and wants to see it. That should shape how the file is written from the first day.
For a separate benchmark relevant to “What Goes in the File”, consult the The Open Group architecture framework. Use it to test scope and safeguards against an external standard before the process is approved.
What belongs in it
- The trigger: how the matter came to attention, and from whom.
- The threshold decision: why it was looked at.
- The raw extracts from every system, with extraction dates.
- The clock offsets used, and when they were measured.
- The timeline, with gaps marked.
- The list of alternative explanations considered, and what became of each.
- The comparison group results, for everybody in it.
- Every account taken, with dates.
- What was disclosed to the person, when, and by what route.
- The finding, separating record from inference.
- The outcome, the reasons, and the appeal position.
Eleven items. The sixth and seventh are the ones that distinguish an investigation from a case, and they are the ones usually absent.
What should not be in it
Speculation about motive. Characterisations of the person. Email chains where managers discussed what they would like the outcome to be. Material about other people that is not necessary.
The third does the most damage. A thread in which three managers decided a week before the meeting is both disclosable in many circumstances and worse than whatever the finding was.
Written as though they will read it
Every note in a file about a person is a note the person may read. In this area that is not a theoretical possibility.
The practical test is simple and it costs nothing: would this sentence be comfortable to read aloud to the person it is about? Where the answer is no, the sentence is usually a conclusion dressed as an observation.
The data that sits outside the file
Extracts live in the file; the systems they came from do not. A file that references a door log without containing it depends on a system whose retention period is thirty days.
Extract and attach. The whole period, not the useful rows, for the reasons set out elsewhere here.
The summary sheet
One page at the front: who, what dates, how it arose, what was found, what followed, what was paid or recovered, and the retention date.
Half of those fields are the ones later readers get wrong, particularly the dates, and having them stated once authoritatively prevents every subsequent reader from deriving them separately.
How long the file is kept
Set a date and record it. These files contain unusually sensitive material — monitoring data, accounts about colleagues, sometimes images — and keeping them indefinitely is the default and the wrong answer.
What period is appropriate differs by jurisdiction and purpose and is a question for somebody qualified in the place concerned.
Who may see it
A time-and-attendance file contains monitoring data, accounts about colleagues and sometimes images, which makes it more sensitive than most employment records and usually less protected.
Restrict access to a named group, log it, and say in the file who that group is. The question of who has been reading a file is asked more often than people expect, and an answer requires the log to exist.
Material about other people
Witness accounts, punches by colleagues at the same terminal, a rota showing everybody. Each of those is a record about somebody who is not the subject of the file.
Keeping only what is necessary, and keeping it in a form that can be redacted, is what makes disclosure possible later without a separate project. The alternative is a file that cannot be shown to the person it concerns because of what else is in it.
The index at the front
A numbered list of what the file contains, with dates. One page.
It takes five minutes at closure and it is what allows anybody — an adviser, an auditor, the person — to see what exists without reading everything, which is also the fastest way to notice what is missing.
Closing it
Everything in, summary written, retention date set, owner named by role rather than by person.
Four things, five minutes, and the difference between a record and a folder. It is also the point at which anything that should not be in the file can still be removed for a legitimate reason — which is not available once a request has arrived.