Chapter 105
The Borrowed Badge
The evidence cage is locked, the component is gone, and the access report places Simon's badge at the door while he is receiving treatment across town. Those facts cannot all identify the same human being. Elliot asks security to say exactly what each one proves.
No one answers quickly enough.
I stand inside North Service with my hands behind my back so I do not touch the cage. The numbered seal on the front latch is intact, but the rear service door was opened electronically. The evidence bag that held the substituted Crown Chase coupling is missing from the shelf beyond it.
"Start with the lock," I say.
Rina crouches beside the reader without making contact. "The controller recorded one accepted credential at 10:14 p.m. The displayed employee profile is Simon Alvarez. That means a credential mapped to his profile opened the door. It does not establish who presented it."
Elliot nods. "Put that sentence in every incident summary."
Simon is in a treatment program approved before tonight. His attendance was confirmed through the protected employment channel, but the details do not belong in our investigation file. The confirmation proves he was checked into another facility. It does not tell us who used his credential here.
Nico arrives with two sealed laptops and sets them on an empty workbench. "Security gave me a controller export and a camera export. Separate custodians, separate clocks."
"How separate?" I ask.
"The door controller syncs to the corporate time server. The corridor camera has been running ninety-three seconds slow since its last maintenance."
That difference matters. So does the person who discovered it.
Nico records the camera clock test on video, using the current network time in the same frame. He creates the comparison at 10:47 p.m.; Rina witnesses it; the original video remains in the security archive while he hashes a working copy. His note lists the vulnerability: security's camera vendor can change the device clock remotely, and the archive does not show whether anyone did so before tonight.
We watch the corrected footage.
A person in a vendor jacket enters the rear service corridor, keeps their face below the camera angle, and disappears into the blind area behind the cage. Ninety seconds later, the same figure returns carrying a narrow gray bag.
The footage shows clothing, movement, and possession of a bag. It does not show Simon.
"His badge should be with him," Elliot says.
"It is," Rina replies. "The treatment facility logged the original credential into a secure property envelope at 6:03 p.m. We have a confirmation number, not the private intake record."
Nico turns one laptop toward me. "Then the door saw another credential mapped to the same profile."
The access system is supposed to reject duplicates. If a replacement badge is issued, the old one should be disabled. That rule exists in the employee credential service.
Vendor kiosks use a different path.
There are four of them across Wondervale, installed so approved contractors can replace damaged passes without waiting for the main security desk. The kiosks copy access templates from a local cache. During network interruptions, they can create a temporary credential and reconcile it later.
"Show me every credential event tied to Simon's profile," I say.
Nico filters the controller export. The 10:14 cage entry is obvious. A second event appears at 7:52 p.m., when kiosk three in the vendor reception lobby created a temporary badge using Simon's employee number as the source profile.
The creator field names a shared vendor service account.
"Who signed into the kiosk?" Elliot asks.
"The account is shared by the kiosk maintenance team," Nico says. "The log identifies the service credential, not the individual operator."
Rina requests the kiosk audit package from security's credential custodian. It arrives at 11:06 p.m. as a signed export, along with the kiosk's local event file. She preserves both originals and makes our working copies. The export timestamp comes from the corporate server; the local file comes from the kiosk clock, which is eleven seconds fast. The package has a dangerous weakness: the shared account can issue a badge without recording a personal operator ID.
I inspect the kiosk configuration with Nico watching every command. We do not alter production settings. He opens a read-only diagnostic screen and finds a fallback option labeled CLONE PROFILE FOR CONTINUITY.
"That should mean permissions," I say. "Not identity."
"It copies both," he replies.
The temporary badge inherited Simon's door zones and the profile label displayed in access reports. It received a different chip identifier, but the standard report hides that field unless an analyst expands the raw event.
Nico expands it.
The chip identifier at the evidence cage matches the badge issued by kiosk three. It does not match the identifier assigned to Simon's original badge.
"Can we reproduce that without issuing another live credential?" I ask.
"In the vendor's diagnostic sandbox."
Rina starts a screen recording. Nico creates a fictional test profile, sends it through the kiosk's fallback workflow, and compares the resulting records. The ordinary report displays the copied profile name, while the raw record preserves the new chip identifier. Simon's records contain the same split.
The test proves the system can produce the misleading report. The matching chip identifier ties the cage entry to the kiosk-issued badge. Neither fact identifies the person who operated the kiosk or carried the badge.
"Simon is not a suspect based on this record," I say.
Elliot looks at Rina. "Has his name gone outside this room?"
"The first automated alert included it," she says. "Security sent the alert to six managers."
"Correct it now."
Rina drafts the notice while we watch. It states that the employee association in the first alert was generated from a cloned profile and must not be treated as evidence of Simon's presence or conduct. The compromised credential is suspended. Simon's employment access is protected pending a clean reissue through the staffed security desk.
She sends the correction to the same recipients and requires written acknowledgment. Elliot calls legal and tells them any accusation based on the automated name will be treated as an evidence failure, not an employee finding.
That decision will not recover the missing coupling. It may keep an innocent man from carrying the theft in his personnel file.
Nico keeps reading the kiosk rules. His shoulders tighten.
"This is not limited to Simon," he says.
Every vendor service credential has access to the continuity function. The kiosks can clone any cached profile the shared account is permitted to view. Worse, the badge zones come from the copied profile before the reconciliation service checks whether the operator was authorized to assign them.
"How many temporary badges were issued this way?" Elliot asks.
"I can count badges," Nico says. "I cannot tell you which operators were legitimate. The audit field never captured them."
He produces the scope record at 11:38 p.m. The credential system is the creator of the underlying events. Security is custodian of the signed exports. Nico's analysis preserves the source timestamps and chip identifiers. Its stated vulnerability is blunt: shared service accounts and incomplete operator logging prevent attribution to a person.
I think about the missing coupling and the third attraction I closed tonight. Someone reached a quarantined component under lockdown. The same weakness could open an electrical room, a maintenance bay, or a medication storage corridor assigned to a contractor.
"Can we disable only the kiosks?" I ask.
"Not safely," Nico says. "Badges already issued through them will continue to work. We do not have a trustworthy list of which ones were legitimate because the same shared account created all of them."
"Can we revoke only kiosk-issued badges?"
"The chip field is available, but the current controller rules were distributed by vendor group. We would need a new rule set to distinguish them, test it, and push it to every door. Until then, any vendor credential may have a copied profile behind it."
Elliot cannot sign a new security contract tonight. He does not need one to order an emergency access restriction under existing policy.
He asks me for the safety consequence.
"If the credentials remain active, we cannot defend the restricted zones," I say. "If we revoke them, outside maintenance and deliveries stop until staffed security verifies each person and issues a clean pass."
"How long to build a verified process?"
Rina answers. "Hours for a manual list. Longer for every contractor to send authorized names."
"Then revoke them," Elliot says. "All vendor credentials. Effective now. Preserve the revocation record and publish the reason without naming Simon."
At 11:52 p.m., security pushes the emergency rule. The controller rejects every badge in the vendor group. Active contractors are escorted to staffed exits, where their identities are recorded before departure. No new vendor enters without individual verification.
The revocation is immediate and systemwide. So is the damage to tomorrow's operations.
Nico begins building a list of clean chip identifiers. Rina packages the kiosk evidence for the independent investigator. I return to the cage and photograph the empty shelf beneath its intact seal. Whoever removed the coupling exploited a copied identity and a corridor no camera could fully see.
Protecting Simon from a false accusation exposed the access failure and turned every vendor gate into a wall.
At 5:31 a.m., the food distributor refuses to unload while its drivers are barred by the credential lockout.
At 5:52, the clinic's medical supplier reaches the same gate and turns away.

