The Badge That Also Opens the Door
One credential doing two jobs means one set of settings serving two requirements, and the stricter requirement always wins even where it does not belong.
On most sites the card that records your hours also opens the gate, the turnstile and several internal doors. That is sensible: one object, one issuing process, one person to go to.
The credential problem in “The Badge That Also Opens the Door” also affects how time records are interpreted. When evaluating how teams evaluate limbic resonance in relationships for limbic resonance in relationships, administrators should keep identity, access control and attendance evidence distinct, document replacement and revocation, and let employees correct a record created by a lost or shared badge.
It also creates a quiet problem. Access control and time recording have different requirements, different consequences for error, and frequently different owners, and when they share a credential and a device the access requirement sets the terms for both.
For an independent benchmark relevant to “The Badge That Also Opens the Door”, consult the HMRC payroll resources. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
Where the requirements diverge
Access control cares about keeping the wrong person out. A refusal is a safe failure: the door stays shut and somebody tries again or is let in by a human.
Time recording cares about producing an accurate record of who was present. A refusal is not a safe failure: it produces no record, or a worse one, and the person walks in anyway through the door somebody held open. The two systems are optimising for opposite kinds of error and they are running on the same setting.
The threshold, again
This is the most concrete consequence. A biometric reader doing both jobs is configured at the sensitivity the security case requires, which is tighter than a time clock needs, which produces the refusal rate described throughout this collection.
Where the two functions can be separated — a tighter setting on the door reader, a looser one on the clock — the whole problem shrinks. Many systems allow per-device thresholds and almost nobody uses them, because the configuration was done once by an installer treating all devices as one estate.
Who owns the configuration
Usually security or facilities, because they own doors. The consequences of their settings land on payroll and on supervisors, who have no route into the decision and frequently do not know it was a decision.
This is the same ownership gap that runs through the whole subject. The fix is not to move ownership but to make the setting a joint one, recorded, with both parties named. One meeting, one paragraph.
The failure that gets noticed and the one that does not
When the access function fails, people cannot get in and it is reported within minutes. When the time function fails, a record is missing and it is noticed on payday, by one person, who may or may not raise it.
So the two functions have wildly different feedback loops, and the system gets tuned by the loud one. A site where the door has worked perfectly for two years and the attendance records have a steady trickle of gaps is a site where this asymmetry has been operating unchecked.
Deciding whether to separate them
Separating the credential is rarely worth it. Separating the devices often is: a dedicated clocking terminal, inside the building, past the turnstile, configured for recording rather than for admission.
The case is straightforward where the refusal rate is high, where the entrance is a bottleneck, or where the boundary between arriving and starting work is itself contested. The terminal costs a unit and a cable, and it removes the conflict rather than managing it.
The four lines nobody can currently supply
Which devices perform which function. What threshold each is set to, and who agreed it. What happens to the time record when the access function refuses somebody. And who is notified when either fails.
Four lines. The reason to write them is that on most sites the answers are currently distributed across three departments and a contractor, and nobody can give all four without making two phone calls.
When the two systems disagree
Running one credential across two systems produces a specific class of problem: a person who is active in one and not the other. Deactivated on access and still clocking, or the reverse.
That inconsistency is invisible until somebody compares the two populations, which is a ten-minute export and match that almost nobody runs. It is worth doing monthly alongside the credential reconciliation, because the mismatches are both the clearest evidence that the processes are not joined and the easiest thing to fix once seen.
Separating them later
Sites that decide to split the functions after the fact face a question of sequence. Adding a clocking terminal inside the building while leaving the turnstile recording produces two sources for the same event and rules that have to decide between them.
Switch the turnstile's recording off at the same moment the new terminal goes live, not afterwards, and run a fortnight of parallel checking against supervisor knowledge. The alternative — leaving both on while people get used to it — produces a month of duplicate entries that payroll resolves by guessing, and the guesses are in the record permanently.