Reading the Refusal Log
The device already knows everything in this section of the collection. Pulling the figures out of it takes an afternoon and nobody has ever done it.
Every refusal described so far is recorded. Each one carries a timestamp, a terminal, usually a credential or user, often an attempt count, sometimes a match score. The site is sitting on a complete account of its own problem and reading it in the form of individual complaints.
The failure described in “Reading the Refusal Log” is easier to investigate when the clock event is joined to a clear operational record instead of treated as proof of misconduct. A team reviewing how employees cheat time trackers for how employees cheat time trackers should test retries, missed punches, corrections and employee review while preserving a non-biometric fallback that does not depend on finding a supervisor.
An afternoon with the export turns that into four cuts, each of which points at a different fix. None of this requires analytics software; it requires somebody to ask for the raw log rather than the summary report.
For an independent benchmark relevant to “Reading the Refusal Log”, consult the NIST Privacy Framework. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
Getting the data out
Ask the administrator for a raw export of read events, not the management report. The report is usually a count of successful clockings by person, which is the one view that contains none of the information in question.
What is needed: timestamp, terminal, user or credential, outcome, and whatever else is there — attempt number, finger index, match score, capture quality. Take everything, in a flat file, for twelve months. If the retention setting means only ninety days exist, that is itself the first finding.
Cut one: by hour and by month
Covered elsewhere in this section and it is the cut to do first because it is the one that resolves the argument about cause. Refusals as a share of reads, in a grid of month against hour.
A strong pattern means environment. A flat field means enrolment. Most sites show both, with a baseline set by enrolment quality and a seasonal peak on top of it, and the two have different owners and different fixes.
Cut two: by terminal
Refusal rate per terminal, same population where possible. Readers in different places perform differently, and the variation is frequently larger than anybody expects — a factor of three between the best and worst device on one site is not unusual.
The worst terminal is then a physical question: where is it, what is the light, how is it mounted, when was it last cleaned, what is the approach to it. Standing in front of it for ten minutes at shift change usually answers it.
Cut three: by person
Refusals per person, sorted descending, with the count of distinct people included. The shape matters more than the total.
A long flat distribution means a systemic problem affecting everybody slightly. A steep one, where thirty people account for most refusals on a site of four hundred, means a re-enrolment list and a decision about method for those individuals. The second shape is far more common and far cheaper to act on, and it is invisible in any site-wide average.
Cut four: by department or trade
Group the per-person figures by the work people do. This is the cut that converts a technical finding into a management one.
A maintenance department at five times the site average is not a department with a discipline problem. It is a department whose hands the method does not suit, and the conversation that follows is about issuing cards to fitters rather than about attendance. Many sites have had the other conversation for years without ever producing this table.
What to do with the output
One page, four charts, and a short list of actions attached to each: clean and reposition these two terminals, re-enrol these thirty people with three fingers, move this department to cards, and set the threshold decision in front of somebody who can take it.
Then repeat it quarterly, which takes an hour once the export is set up. The value is not the first report, which mostly confirms things people half knew. It is the second one, which shows whether anything that was done made a difference, and that is the first time the site has ever been able to answer that question.
What the summary report hides
It is worth naming why this exercise is necessary at all. The standard management report counts successful clockings per person and flags missing ones, which is the view payroll needs and the worst possible view of system health.
In that report a person refused four times and successful on the fifth looks identical to a person who walked up once. All of the information in this note is discarded before the report is drawn. Asking for the raw log is not an advanced analytical step; it is asking to see the data that the convenient view throws away.