The Card That Stopped Working
Badges fail physically and predictably, usually after about the same number of months, and the replacement process is slower than the failure rate requires.
A proximity card has no moving parts and still wears out. The antenna is a fine wire loop laminated inside a thin plastic card that lives in a back pocket, gets sat on, bent, frozen, washed and dropped, several hundred times a year.
The credential problem in “The Card That Stopped Working” also affects how time records are interpreted. When evaluating this reference page for does microsoft teams track your activity, administrators should keep identity, access control and attendance evidence distinct, document replacement and revocation, and let employees correct a record created by a lost or shared badge.
The result is a steady trickle of failures that the site experiences as individual events and which are, in aggregate, a predictable replacement rate that nobody has ever calculated.
For an independent benchmark relevant to “The Card That Stopped Working”, consult the CISA insider-risk mitigation resources. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
How cards actually fail
The antenna breaks. A hairline crack in the wire loop is invisible and fatal; the card looks perfect and reads nothing. This is the most common failure and it comes from flexing, which means back pockets and wallets.
The chip delaminates, usually at the edge, usually after the card has been used as a scraper or an ice-breaker. Printing wears off, which does not stop it working but does stop it functioning as visual identification. And the card gets demagnetised, which only matters for magnetic stripe systems and which the person will blame regardless of the technology.
The ones that fail faster
Cards on lanyards fail less than cards in pockets, by a wide margin. Cards in phone cases fail more. Cards used to open doors twenty times a day wear faster than cards used twice.
There is also a quiet one: two contactless cards in the same wallet, which can interfere and produce an intermittent read that looks exactly like a faulty reader. It is worth having in mind the next time somebody reports that the terminal "works sometimes", because it is the cheapest possible fix and nobody thinks of it.
Telling a card failure from a reader failure
The single question is whether other people's cards work at the same terminal in the same minute. If they do, it is the card.
Worth saying because the default assumption on both sides is the opposite. The person believes the reader is broken, the supervisor believes the card has been lost and replaced casually, and the five seconds of testing that would settle it does not happen because nobody has framed it as a question with an answer.
The replacement process, and why it is too slow
On most sites, a failed card is reported to somebody who orders a replacement that arrives in a few days, during which the person is on a fallback. The failure rate means this is happening to somebody most weeks.
A box of pre-encoded blanks and somebody on site who can issue one in five minutes changes a multi-day problem into a five-minute one. It requires a decision about who may issue, a log, and a small amount of trust, and it is resisted on control grounds by organisations that are quite happy for the same person to spend four days on supervisor overrides instead.
The replacement rate
Replacements per hundred cards per year, and the age of cards at failure. Both come from the issuing log if anybody is keeping one.
A rate above about ten per cent a year suggests a card or carrier problem worth addressing — a thicker card, a lanyard policy, a different supplier. A rate below two suggests cards are failing and not being reported, which means people are quietly using the fallback instead and the real number is hiding in the override log.
The cheap interventions, in order
Lanyards or rigid holders, issued with the card rather than available on request. A pre-encoded stock on site with a named issuer. A five-second test routine that anybody can apply at the terminal. And a replacement log that records the old number as well as the new, so that the deactivation actually happens.
That last one is the control that matters, and it is the one most commonly missing. A site that issues replacements quickly and never deactivates the originals has solved an operational problem by creating an access one, and the two sit in different people's in-trays.
The card that works and should not
The opposite failure is worth a line. A card that has been reported lost, replaced and then found keeps working on most sites, because the deactivation was never done.
Those are the credentials that turn up in a reconciliation as reads from a number that should not exist. They are rarely sinister and they are always a gap in the process, and the gap is the same one in every case: the replacement was issued because somebody needed to work, and the deactivation helped nobody that morning.