The Temporary Badge That Became Permanent
A card issued for one shift, to somebody whose name was written on a scrap of paper, is still in use eighteen months later and belongs to nobody in the records.
The temporary badge is the most common permanent arrangement on any site. It is issued in a hurry, for a good reason, with the intention that it comes back at the end of the day, and a predictable share of them never do.
The credential problem in “The Temporary Badge That Became Permanent” also affects how time records are interpreted. When evaluating employment of relatives policy with accountable controls for employment of relatives policy, administrators should keep identity, access control and attendance evidence distinct, document replacement and revocation, and let employees correct a record created by a lost or shared badge.
What makes it worse than an ordinary lost card is that it was never attached to a name in the first place. A card issued to "the lad from the agency, Tuesday" and used for the next year produces attendance records against a credential that corresponds to no person in any system.
For an independent benchmark relevant to “The Temporary Badge That Became Permanent”, consult the Employment New Zealand recordkeeping guidance. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
How it happens, every time
A contractor arrives for a two-day job and is not on the system. A new starter begins before their enrolment appointment. Somebody from another site is covering. An agency sends three people at short notice.
In each case the operationally correct thing to do is hand over a card and get the work started. Nothing is wrong with that decision. What is wrong is that it ends there: no record of who, no expiry, and no process that asks for the card back.
What the records look like afterwards
Hours accumulate against TEMP-04. Payroll queries them and is told they belong to an agency worker, who is paid through the agency and whose hours are reconciled, if at all, against the agency's own timesheet.
So the site has two parallel records of the same person, neither authoritative, and the one the site holds is anonymous. If anybody ever asks who was on site on a particular night — an incident, an insurance claim, an inspection — the answer for that person is a card number.
The three fixes, in order of effort
Number the stock and keep a log with a return column. This is a notebook and ten minutes a week, and it converts anonymous cards into named ones.
Set an expiry where the system supports it. A credential that stops working at midnight solves the return problem by making the card worthless, and it is a configuration option on most access systems that nobody enables because it creates work when somebody genuinely needs it for three days.
Pre-enrol the predictable categories. Agencies send people from a pool; contractors return; sites lend staff to each other. A standing credential per regular agency worker, issued once, removes most of the volume.
The reconciliation that finds them
Pull every credential that has recorded reads in the last three months and match it against the people register. The temporary cards in active use appear immediately, because they match nothing.
On a mature site this list is longer than expected — typically a handful on a small site and dozens on a large one. Each needs the same three questions: who is using this, should they have a card of their own, and when did it stop being temporary.
Why this is worth doing before anybody asks
The honest reason is not security. It is that the site cannot currently answer a simple question about its own records, and the question gets asked at inconvenient moments: after an incident, during a contract audit, in a dispute about hours with an agency.
Being able to produce a named list of everyone on site at a given hour is the baseline capability a time and access system is supposed to deliver. A drawer of unnumbered cards is the single most common reason a site cannot do it, and it is also the cheapest thing on the list to fix.
The rule, in one line
No credential leaves the drawer without a name, a date and an expiry written against its number, and the drawer is reconciled weekly.
That is the whole control. It needs a notebook, a numbered stock, and somebody whose job it is. What it replaces is an arrangement that everybody knows is untidy, that nobody owns, and that quietly undermines every record the expensive part of the system produces.
Why the drawer wins
Every site that has tried to tighten this has met the same resistance, and it is worth understanding rather than overriding. The drawer exists because people turn up unexpectedly and work has to start.
Any control that makes issuing slower will be bypassed within a fortnight. The ones that survive make issuing just as fast while capturing the name: a numbered stock, a book on top of the drawer, thirty seconds. Trying to route temporary issues through an approval process is how sites end up with a second, unofficial drawer.