What the Score Distribution Shows
Most readers record a match score for every attempt and show it to nobody. A month of those scores answers the threshold question without changing anything.
Refusals in one month, by how far below the line they fell
Two-thirds of the month's refusals were near misses. A near miss is a tuning or enrolment question; a score far below the line is a different event entirely. The device recorded the distinction every time and the management report showed only the total.
The threshold decision is normally made in the abstract, by arguing about vendor rates and risk appetite. It does not have to be. Most systems record a match score for every attempt, and a month of those scores turns the argument into arithmetic.
The setting discussed in “What the Score Distribution Shows” should be tested against real people and real exceptions rather than accepted as a vendor default. For teams researching workforce analytics software, more information can supply time and project context, while biometric thresholds remain a separate decision with written ownership, accessibility checks and human review.
The obstacle is that the scores are not in the management report. They are in the raw event log, available on request, and almost nobody has asked.
For an independent benchmark relevant to “What the Score Distribution Shows”, consult the Grants.gov policy resources. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.
What the distribution looks like
Genuine attempts by enrolled people produce a cluster of high scores with a tail reaching down towards the threshold. The tail is made of cold hands, bad angles, marginal enrolments and hurried presentations.
The threshold sits somewhere in that tail. Everything to the left of it is refused. The question the site is really asking is how much of its own tail it is cutting off, and that is a thing you can look at rather than estimate.
The cut to make
Take every refusal in a month with its score, and express each as a distance below the threshold. Then band them: within five per cent of the line, five to twenty-five per cent below, and further than that.
The shape of those three bands is the finding. A large first band means the setting is doing most of the refusing and a small adjustment would change a lot. A large third band means the refusals are genuine non-matches, which points at enrolment quality or at something else entirely.
What a near miss actually is
A score just below the line is a successful read that did not quite make it. The person is who they say they are, the template is theirs, and the sample was marginally degraded by something physical.
Treating those identically to a far-below score is the error that runs through the whole subject. They are different events with different causes and different responses, and the device knew the difference at the moment it refused.
Cross-cutting it
Two further cuts are worth the extra half hour. By person: a handful of people whose successful reads cluster near the line are people whose enrolment should be redone, and they will become daily problems as their templates age.
By hour and month: if the near-miss band is concentrated in cold early mornings, the setting is interacting with the environment, and the cheaper fix is the environment. A site that moves its threshold to solve a problem caused by a doorway has given away identity assurance it did not need to give away.
Deciding what to change
In order of preference, and only after looking: fix the environment, re-enrol the people clustering near the line, enrol more fingers, and only then consider moving the threshold.
The reason the threshold is last is that it is the only one of the four that trades something away. The first three improve the score distribution itself, which reduces refusals without reducing assurance, and on most sites they are sufficient.
If the system does not record scores
Some do not, or do not expose them. Ask the supplier directly whether the data exists and can be exported; frequently it does and the answer is a support ticket rather than a licence.
Where it genuinely is not available, the substitute is a controlled test: a sample of thirty people presenting at a quiet hour and again at the worst hour, with outcomes recorded by hand. That is a morning's work and it produces a crude version of the same picture, which is still far better than deciding the setting from a brochure.
What the scores say about enrolment
Scores are also the only direct measure of enrolment quality available after the fact. A person whose successful reads cluster at 0.80 against a threshold of 0.75 has a marginal template, even though they have never been refused.
Pulling the median score per person and sorting ascending produces a re-enrolment list before anybody has had a bad morning. That is the one genuinely preventive measure in this whole subject, it costs a query, and no site has ever been found doing it.
What not to conclude from a low score
A single low score is not evidence of anything. Scores vary enormously with presentation, and a genuine user having a bad morning can produce one far below their own normal.
The pattern is what carries meaning: a person whose scores are consistently low, or a credential whose scores jump between two clearly separate clusters. The second is the shape that would indicate two different people using one enrolment, and it is the only thing in this data that would justify asking anybody a question.