Skip to content
The Second Method

Home / The fallback

The Keypad Code, and the Objection To It

A code can be shared, which is the whole argument against it. The argument is weaker than it sounds and the alternative it protects is worse.

The fallback · Analysis

The cleanest fallback is a code the person enters themselves at the same terminal. It works without another human being, it captures the real time, and it costs nothing to issue.

The alternative described in “The Keypad Code, and the Objection To It” must produce a record as usable as the primary method. A team assessing a practical route to time tracking with screenshots for time tracking with screenshots should run the full fallback from clocking through approval and payroll, then compare delay, correction effort and employee access without making the alternative a penalty.

It is rejected on almost every site for one reason: a code can be told to somebody else, and the system was bought partly to stop exactly that. The objection is real and it is usually overweighted, because it is compared against an imagined alternative rather than the actual one.

For an independent benchmark relevant to “The Keypad Code, and the Objection To It”, consult the WHO mental-health-at-work resources. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.

What the objection is actually protecting against

One person entering another person's code to cover an absence or a late arrival. That is the behaviour the biometric was bought to prevent, and a shareable fallback reopens the door.

Worth being precise about the size of the door. The fallback is used by a small, named group, at known terminals, and every use is logged. It is not a general return to codes; it is an exception route with a list of people on it. The exposure is bounded by how many people are on that list and how often they use it, both of which are measurable.

What the objection costs when it wins

The alternative chosen is almost always the supervisor override, which has its own integrity problem and nobody counts it. A supervisor entering a time on behalf of somebody else is, as a record, weaker than a code entry: it depends on one person's account of another person's arrival, and the system records it as an administrative correction indistinguishable from every other correction.

So the comparison is not between a shareable code and a perfect record. It is between a shareable code and an unverifiable one, plus six to nine minutes of two people's time per event.

The controls that make a code defensible

Issue codes only to people with a recorded reason — an enrolment note, a documented failure rate, a medical or occupational cause. The list is short and it exists on paper.

Log code use separately from biometric use, which most systems do by default, and review it monthly. Set a length that is not a birth year. Change it when a person's circumstances change. And make clear, once, that lending it is the same offence as lending a badge, which the handbook already covers.

The monthly review, which is the actual control

Three questions of the code-use report. Is the volume rising. Is it concentrated on the people whose records say it should be. And is any code being used at a terminal or an hour that does not fit the person it belongs to.

That last one catches substitution far more reliably than refusing to issue codes does, because it looks for the behaviour rather than removing one of the ways to perform it. A site running that report monthly has a stronger control than a site that refused codes and does nothing.

Where a code genuinely is the wrong answer

High-security environments where presence itself is the control. Regulated settings where identity at the point of record is a legal requirement rather than an operational preference. Sites with a documented history of substitution rather than a general concern about it.

In those cases the answer is not the supervisor override either. It is a second biometric modality, or a card plus a biometric, or a staffed point — all of which cost money, which is the real reason they are not chosen. Naming that trade-off honestly is better than choosing the override and describing it as a control.

The sentence that should be in the policy

Something like: where the reader cannot match a person who is enrolled, that person may record their time using their own code at the same terminal, and use of the code is logged and reviewed.

One sentence. It takes the most common event in the system out of the realm of improvisation, removes a daily interaction that nobody enjoys, and produces a record that says what happened. What it does not do is eliminate every risk, and no arrangement available at this price does.

Choosing the codes

Small details decide whether a code is a control or a formality. Not a birth year, not a locker number, not four digits that appear anywhere else on the person's paperwork. Not sequential by payroll number, which is the most common shortcut and makes every code guessable from any other.

Issue them randomly, privately, and in writing to the person rather than through a supervisor. The whole weight of this method rests on the code being known to one person, and handing it over verbally in a corridor is the point at which that stops being true.