Lending It
Card sharing is the behaviour biometrics were sold to stop. Why people do it is worth knowing: most of the reasons are about the arrangement, not dishonesty.
Badge sharing is the stated reason a great many sites bought a biometric reader. One person clocks in for another, the hours are paid, and the credential made it possible.
The record in “Lending It” becomes useful only when people understand what it proves and how to correct it. For teams exploring gdpr employee monitoring, this practical implementation page can connect time and project context with manager review, provided collection is proportionate, access is limited and consequential decisions remain subject to human explanation.
It happens, and it is worth separating into its varieties before designing against it, because they have different causes and only one of them is the thing people imagine.
For an independent benchmark relevant to “Lending It”, consult the California labor standards resources. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
The four kinds
Covering an absence: one person clocks in another who is not there. This is the version everybody means and it is the least common.
Covering a late arrival: the person is coming, is ten minutes away, and a colleague clocks them in. Extremely common, usually reciprocal, and understood by everybody on the floor as a minor kindness rather than a fraud.
Convenience at a queue: one person takes three cards through the reader because the queue is long and the three of them walked in together. No time is gained and no money is involved.
And the forgotten badge: somebody borrows a colleague's card because their own is at home and the alternative is finding a supervisor. This one is created entirely by the absence of a working fallback.
Why only one of them is a fraud problem
The first costs money and is dishonest. The second costs a few minutes and sits in a grey area everybody recognises. The third costs nothing. The fourth is the site's own process failure being routed around by somebody trying to start work.
Designing a control that treats all four identically produces a system that is experienced as disproportionate, and disproportionate controls are the ones people put effort into defeating. A site that responds to the fourth kind with a disciplinary process has taught its workforce that the honest route is expensive.
What a biometric actually fixes
It fixes the first and the third outright: you cannot present somebody else's finger. It fixes the second only if the late person cannot be entered any other way, which is rarely true, because the supervisor override exists.
So the common outcome is that substitution moves from the card reader to the override, where it is harder to see and carries a supervisor's name on it. That is not nothing — a supervisor is unlikely to enter a false time for somebody who is absent altogether — and it is considerably less than the step change the business case described.
The controls that work without a biometric
A second check that is not the clock: a supervisor who knows who is present, a work allocation that has to be collected, an operational system that has to be logged into. On most sites the person's actual presence is evidenced three or four times in the first hour by things that have nothing to do with the terminal.
Pattern review also works, and it is cheap: the same two credentials read within a few seconds of each other, every day, is a visible signature. So is a credential read at a terminal the person's work never takes them near.
What to do about the tolerated kind
Decide, and say so. A site that genuinely does not care about ten minutes should write down a grace arrangement, which removes the reason for the behaviour entirely. A site that does care should say that too, and then make sure the honest alternative — a late arrival recorded as a late arrival — is not punished more heavily than the dishonest one is likely to be caught.
What does not work is the common position: a rule that forbids it, a practice that ignores it, and an occasional case where somebody is made an example of. That arrangement is read accurately as arbitrary, and it costs more in trust than the minutes are worth.
Where the fallback comes back in
The fourth kind — the borrowed card because mine is at home — disappears the moment there is a five-minute temporary card process or a self-service code.
That is worth stating plainly in any business case for a biometric: part of the sharing it is being bought to stop is not a behaviour problem at all. It is people routing around a missing process, and the missing process costs a drawer of numbered cards and a log.