Skip to content
The Second Method

Home / Refused

What a Refusal Actually Means

The device found no match above its threshold. That is the whole of what it says, and it is read as a statement about the person standing in front of it.

Refused · Analysis

When a reader refuses somebody, it has made one narrow statement: the sample presented just now did not score above the configured threshold against the template on file. It has not said that the person is an impostor, that they presented their finger badly, or that they were not there.

The failure described in “What a Refusal Actually Means” is easier to investigate when the clock event is joined to a clear operational record instead of treated as proof of misconduct. A team reviewing employee monitoring software for employee monitoring software should test retries, missed punches, corrections and employee review while preserving a non-biometric fallback that does not depend on finding a supervisor.

Everything that goes wrong afterwards comes from treating the narrow statement as a broad one. An identification failure is a fact about a comparison between two records. It becomes a fact about a person only when somebody decides to read it that way, and on most sites that decision is made silently and by default.

For an independent benchmark relevant to “What a Refusal Actually Means”, consult the ILO working-time resources. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.

The four things a refusal can mean

The template is poor, because enrolment was rushed or the capture was marginal. The sample is poor, because of cold, moisture, dirt, a plaster, light or angle. The threshold is tight, so a genuine match scored below the line. Or the person really is not who the credential says.

The fourth is the rarest by an enormous margin, and it is the one the system was sold to catch. A site experiencing hundreds of refusals a year and no known cases of substitution is looking at the first three causes almost exclusively, and should design on that basis rather than on the brochure's.

Why the default reading is the wrong one

Because the record is binary and the explanation is not. The log says refused; it does not say why, and in the absence of a reason the reader of the log supplies one. The supplied reason is usually about the person, because the person is the only part of the transaction with intentions.

This is the same error as reading a late punch at a queued entrance as lateness. The measurement is real and the inference is not supported by it. The difference here is that the inference is about identity rather than timekeeping, which makes it considerably more unpleasant to be on the end of.

What the log would need to say instead

Most devices record more than they surface: a match score, the number of attempts, which finger, sometimes a quality metric on the capture. The administrative interface shows none of it by default.

Turning that on changes the character of the conversation entirely, because a refusal at a score of 0.72 against a threshold of 0.75 is visibly a near miss and a refusal at 0.11 is visibly something else. The first is a tuning or enrolment question; the second might be worth asking about. Without the score they look identical in the report and get treated identically.

The cost of getting it wrong in the other direction

None of this argues that substitution never happens or that refusals should be waved through. It argues that the two cases have to be distinguishable, and that the burden of distinguishing them sits with the system rather than with the person refused.

A site that investigates every refusal exhausts its supervisors and teaches everybody that the reader is unreliable. A site that investigates none loses the control it paid for. The workable position is to resolve refusals operationally at the terminal, and to review the pattern monthly, where genuine substitution shows up as something a single morning never could: the same credential read at two places, or a cluster that follows one person rather than one department.

What to say in the first thirty seconds

There is a sentence worth having, and it is for whoever is standing at the terminal: the reader has not matched, that happens, use the second method and carry on.

That sentence does three things. It gets the person to work. It records the time accurately. And it says plainly that nothing has been alleged, which is the part that prevents a technical event from turning into a grievance over the following six months. The absence of that sentence is why so many sites have a quiet, widely shared belief that the clock is used to catch people out.

Where this leaves the record

A refusal followed by a successful second-method entry is a complete and honest record: the person arrived at this time, the primary method did not match, the secondary one did. Nothing is missing and nothing is asserted that cannot be supported.

That is the standard to aim for, and it is achievable with configuration rather than purchase. What it replaces is the common alternative — a refusal, a gap, and an entry typed in later by somebody else — which is neither complete nor honest and which is the version most sites are running.