The Badge as an Object
A credential is a physical thing with a cost, a lifespan, an issuer and a failure rate, and it is managed on most sites as though it were a database row.
Credentials in circulation, one site, reconciled
Six hundred and forty cards were issued and four hundred and ten can be accounted for. The register was never a register; it was the issuing log, which records what went out and nothing about what came back.
A badge is a manufactured object that costs money, lives in a pocket, breaks, gets lost, gets lent, and occasionally does not come back. Every one of those is an operational fact with a rate attached.
The credential problem in “The Badge as an Object” also affects how time records are interpreted. When evaluating see the complete product overview for employee monitoring software with screenshots, administrators should keep identity, access control and attendance evidence distinct, document replacement and revocation, and let employees correct a record created by a lost or shared badge.
Most sites manage the data side of this carefully and the physical side not at all. There is a user record in the system and an issuing log in a drawer, and no process that reconciles the two, which is why the count of active credentials on a mature site exceeds the headcount by a noticeable margin.
For an independent benchmark relevant to “The Badge as an Object”, consult the IRS recordkeeping guidance. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
What is actually on the card
Three separate things that people conflate. A credential number, which is what the reader reads. Printed identification — photograph, name, role — which is what humans read. And in some systems a stored template or certificate, which is what makes the card more than a number.
They have different failure modes and different consequences. A card whose printing has worn off still works at the reader and no longer works as identification, which matters at a gate with a guard and not at a time clock. A card whose chip has failed is the opposite.
The lifecycle, which has six events
Issued, used, replaced, suspended, returned, destroyed. Most sites have a process for the first and partial processes for the next two.
The last three are where the gaps are. Suspension — for a long absence, a secondment, a suspension from duty — is frequently done in the access system and not the time system or the other way round. Return is tracked by whoever runs the exit interview, if anybody does. Destruction is not tracked at all, which is how a drawer of several hundred live credentials accumulates in a facilities office.
The register that is not a register
The issuing log answers one question: what was given out, to whom, when. A register answers a different one: what exists right now, who holds it, and is it active.
The second cannot be derived from the first without the return and deactivation records, which is exactly what is missing. Building the register is a one-off exercise of reconciling the issuing log against the active credential list in the system against the current headcount, and the gap it reveals is usually uncomfortable enough that the exercise gets deferred.
What the gap actually means
An active credential with no holder is not, in most cases, a security incident waiting to happen. It is in a drawer, or a jacket, or landfill. The realistic risk is low and the governance position is poor, and the two should not be confused when making the case.
The argument for fixing it is cleaner than a threat scenario. An organisation that cannot say how many of its credentials exist cannot answer a basic question about its own controls, and that is the question an auditor asks first because it is the one that tells them whether the rest is worth examining.
The reconciliation, done once properly
Export the active credential list. Export the current headcount, including agency and contractors. Match them. Investigate the unmatched in both directions: credentials with no person, and people with no credential.
Then deactivate everything in the first category that cannot be accounted for, having warned people first, and expect a handful of complaints on the Monday from people whose spare card stopped working. Those complaints are the exercise succeeding.
Keeping it reconciled afterwards
A monthly export and match, which takes twenty minutes once the first one has been done. A rule that deactivation happens on the leaving date rather than when the card comes back, because the card frequently does not.
And a single owner for the register, which on most sites is the hardest part. The credential crosses HR, facilities, security and payroll, and in the absence of one owner each of them maintains the part they can see and nobody maintains the whole.
What it should cost to replace
The unit cost of a card is small and the administrative cost of issuing one is not. Most of the expense is somebody's time: finding the stock, encoding, updating two systems, and handing it over.
Measuring that once is worth doing, because it reframes the argument about issuing credentials more freely. A site that believes a card costs two units of currency will protect the stock; a site that knows the real cost is twenty minutes will put the effort into making the issuing process shorter, which is the thing that actually matters.