The Day It Is Lost
Somebody left their badge at home. What happens in the next five minutes is the most frequently exercised process in the whole system and the least designed.
On a site of four hundred people, several badges a week are forgotten, lost or broken. It is the single most common exception the system handles, far more common than a biometric failure, and on most sites there is no process for it at all.
The credential problem in “The Day It Is Lost” also affects how time records are interpreted. When evaluating this workplace technology guide for how to detect mouse jigglers, administrators should keep identity, access control and attendance evidence distinct, document replacement and revocation, and let employees correct a record created by a lost or shared badge.
What exists instead is a ritual: the person explains, somebody writes something down, a temporary card is produced from a drawer or not, and the day proceeds. None of it is recorded in a way that would survive a question.
For an independent benchmark relevant to “The Day It Is Lost”, consult the Canada Revenue Agency payroll guidance. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
Forgotten and lost are different, and the process treats them the same
A forgotten badge is at home and will be back tomorrow. A lost badge is somewhere unknown and is still active. The first needs a day pass; the second needs a deactivation.
Most sites do neither reliably, because the person at the door cannot tell which they are dealing with and the question is not asked. "Have you lost it or left it at home?" is one sentence and it determines whether a live credential is now outside the control of the site.
The five-minute version that works
Ask the question. If forgotten, issue a numbered temporary card from a controlled stock, record who has it and that it expires at the end of the shift, and take it back on the way out. If lost, deactivate the original immediately and issue a replacement through the normal route.
Both paths are short, both are recordable, and the difference between them is a tick in a column. The reason it is not done is that temporary cards are kept in a drawer with no numbering and no log, so there is nothing to record against.
Why the deactivation is the part that slips
Because it is the only step with no immediate operational benefit. The person is already working; deactivating the old card helps nobody today.
So it is deferred and then forgotten, and the site accumulates live credentials whose location is unknown. Attaching the deactivation to the issuing of the replacement — one cannot be done without the other, in the same screen — is the only arrangement that reliably works, because it puts the step in the path of something somebody wants.
The temporary stock
Ten numbered cards, kept somewhere accessible at shift change, pre-enrolled on the system as temporary credentials with a daily expiry where the system supports it.
If the system does not support expiry, the log is the control, and the log needs a return column that somebody actually checks at the end of each day. A stock of ten with four out and no record of who has them is the normal state of this drawer, and it is how temporary cards become permanent.
Charging for replacements, and why to think about it
Many sites charge for a replacement badge after the first. The intention is to reduce carelessness and the effect is frequently to reduce reporting: people who have lost a card and do not want to pay use the fallback quietly instead, and the lost card stays active indefinitely.
If a charge is used, it should not apply to a card that has failed, and it should never be the reason somebody avoids telling you a credential is missing. Most of the sites that have modelled it find the replacement cost is trivial next to the control value of prompt reporting.
The two counts worth keeping
Replacements and temporary issues per month, and the share of temporary cards returned the same day.
The second number is the interesting one. A return rate below about ninety per cent means the temporary stock is leaking, which in practice means a handful of people are carrying a second live credential that is not in their name. That is the one genuine control weakness in this whole area, and it is created entirely by a drawer with no log.
The person who stops reporting it
The arrangement fails quietly when reporting becomes unpleasant. A charge, a lecture, a form, or a wait of several days all produce the same adaptation: people who have lost a card borrow one, use the fallback, or ask a colleague to let them through.
At that point the site has lost both the record and the control, and it will not find out until a reconciliation months later. Whatever else the process does, it has to make telling somebody the easiest available option, because every alternative the person might choose is worse for the organisation than the cost of a card.