I work as a senior developer in a small/medium UK-based company with multiple offices. Rarely do personnel go between the different offices. Our office has a publicly accessible reception area but the various departments are secured with keycode-locked doors. Junior employees only receive codes for departments they are expected to access regularly. We don't wear any passes or ID badges.

At this time, there happened to be only a new start - "James" - and I working in the IT department. The rest had gone home for the day. I was called away to help in a task I knew would only take a few minutes, so I was confident James could be left unsupervised for such a short time. During this time however, someone tried to access the IT room. They tried to input a code for the door, it was incorrect, and then tried to force the door open anyway before knocking. James opened the door but did not let the visitor inside. The visitor said he was looking for me. James explained I would be back soon but the visitor simply replied with "I'll just wait for him in here then". He then tried to get past James into the room, but James still did not let him in. According to James, he asked again who he was but the visitor just repeated "I'll just be waiting for Kozaky". James held his ground though and the visitor left in a bad mood. When I returned, James explained the situation and described the visitor. I did indeed know him as a manager from another office who is technically a superior to us, but not someone whom we would ever directly report to. The visit was unplanned as well.

My currently out-of-office manager emailed me with a message along the lines of "Did James really not let that guy into the IT department? Did he really not know who he was?" I explained it was all true, but that the visitor did not even give his name. I also mentioned I was briefly out of the room, that had I not recognised him, I would probably have done the same thing, and that if James is disciplined for this, I should take some of the blame for leaving him alone. I would guess there are less than 20 people in superior roles to my own but even I have not met all of them and would likely not recognise them.

My questions are:

  • Should an employee be disciplined for not recognising those further up the chain of command?
  • Should employees be encouraged to learn who is above them, even if they will never directly report to them?


15Just to elaborate, from the current version of the question, it cannot be determined with absolute certainty that the higher management wants the OP to punish James. If it turns out that the higher management had no such intention, then there really isn't much of a question here.Masked Man 2017-09-29T08:42:50.357

4Did you ever find out what the visiting manager came to discuss with you? It's not directly relevant to the question(s) at hand, but if it was something urgent, it might help to add some context about the actual consequences of James' actions beyond just hurt feelings.AffableAmbler 2017-09-29T14:00:25.893

1Does the company's security policy have anything to say on the topic of allowing someone into secured areas, when that person doesn't have the access code for that area?Dan Henderson 2017-09-30T05:30:15.340

1If you already have the feeling that you would have done the same, the question about punishment of someone below is hypocritical per definition. Moreover, the one above him should be punished, because he was unable to identify himself :/dgrat 2017-11-14T13:08:07.087

Not hypocritical. The OP is being proactive in collecting arguments for or against discipline on the chance that someone else might try to apply such a measure.WGroleau 2018-02-01T10:33:52.397



Sounds to me like James did the right thing: he refused someone he didn't know entry to a secured area when they didn't know the door code and didn't identify themselves. All of which is totally reasonable and best practice under the circumstances.

As for whether he should have recognized the person - it's not unreasonable for someone who is relatively new to the organisation to not recognize someone from an entirely different office. Especially where that person isn't in their direct reporting line. Disciplining him for this would be ridiculous in my book.


14Absolutely this. Imagine someone came there who looked ALMOST like some higher-up, acted like that, and was let in! THAT would be a security-breach, instead of an annoyed Manager. If there is trouble because of that, someone should ask if someone who doesn't have credentials and doesn't care to identify himself should be allowed into that room...Layna 2017-09-28T10:50:39.813

345+1 Another scenario: Higher-up with well-known face gets fired, no one knows about it, and people open the door to him out of fear of being disciplined. What an idiotic system. It's the higher-up who should be reprimanded.rath 2017-09-28T11:06:44.987

92Yes. A well-run organisation should make it clear to the Manager that they acted improperly and that if they do it again they will be disciplined. Terrible conduct.Francis Davey 2017-09-28T11:29:01.950

202James should be PRAISED for having the integrity to do what was absolutely the right thing despite the fact that he was new.Kevin 2017-09-28T12:52:29.610

70In my company CEOs do not have access to the server rooms, so even recognizing someone does not mean you know what access level they have, and asking someone to remember the access level of everyone else above them is just ridiculous.PlasmaHH 2017-09-28T14:24:34.520

5The only thing missing from this near-perfect answer is that the manager who tried to bull his way into the room should at least be slapped on the wrist. He could claim that he was "testing security" but trying to force his way into the room, but his apparent compliant that James acted correctly is unacceptable!G. Ann - SonarSource Team 2017-09-28T15:10:15.693

@Layna: Not just an accidental breach, either. It'd be a good way to intentionally get into a secured area.jamesqf 2017-09-28T16:13:44.797

71In the military I've been told I had permission to use lethal force to prevent anybody attempting to forcibly gain access to a secured area and that in that specifically including higher ranking officers in the military. "Everybody knows the rules. If they try to access a secured area without proper authentication they are to be forcibly dealt with." The superior should commend the new guy if anything for bravely standing up for physical security measures in the face of overwhelming pressure.leigero 2017-09-28T18:08:31.153

2I'm now more confident in my belief the other manager simply assumed too much, flew off the handle and complained to our own boss. If formal procedures continue, our own boss, James and I are confident the powers will side with us (and if they don't, I may think of dusting off the CV as well!). James doesn't need to know all his superiors on Day 1.Kozaky 2017-09-29T07:45:40.807

2I hope it's reasonable to not recognize every single executive at a company even after being there for a year or more (not even allowing for turnover), otherwise I'm a terrible employee, to say nothing of my friend who is face blind.Todd Wilcox 2017-09-29T12:24:59.670

Lovely answer! You can check out this video of a guy who's a professional penetration tester, basically he enters your building, then walks out with harddrives, laptops and the keys to your car ;)

peufeu 2017-09-29T14:05:36.700

@Kozaky "if formal procedures continue" why not file your own complaint? It seems like this "other-office" boss was breaking procedure and caused an unsafe or at least uncomfortable work environment. If anyone should be talked to, it should be that guy. Then again, that could cause problems down the road, so be careful – None – 2017-09-29T18:36:52.543

2I've heard about large companies where very sensitive date is kept, and that people are sometimes tested by a high ranking manager pretending to having lost the key or forgotten the password, and asking the subordinate to let them in. If the subordinates let them in, they failed the test and might be severely disciplined or even fired.Val 2017-09-29T20:05:28.560

looks like the " superior " needs to get off his high horse and understand that regulations ought to apply to everyone. I give this James guy a lot of credit for telling the visitor to shove offuser32882 2017-09-30T08:31:14.043


Doesn´t matter who he is, even if I recognize him. If he doesn´t know the door code, then he doesn’t belong inside. If he is supposed to know the door code, he should follow the proper procedures to obtain it.


85Bingo - James followed procedure - so why should James be disciplined for following procedure? The guy, as you point out, was behaving as an intruder, not a manager. – None – 2017-09-28T11:58:33.973

I used to get quite frustrated when help desk would call me and ask me to add someone to an access list when the app screen clearly said they had to be added by their manager.WGroleau 2017-09-28T11:59:44.163

4James certainly "did the right thing", but we don't know if he "followed procedure". Since no-one is required to carry an ID badge (note I said "carry," not necessarily "wear at all times") there may not even be a formal procedure to follow! Just relying on a random employee "recognizing somebody" is a ludicrous approach to security.alephzero 2017-09-28T13:49:57.370

4@alephzero We do know that he did the right thing. From the question, we know that to enter the room, you're required to either know the code to enter or be accompanied by someone who knows the code. Having a badge is immaterial as it is not the entry code nor is it a person who knows the code accompanying you.iheanyi 2017-09-28T19:59:31.667

If that person was such an important manager, he should have known the way to get the code to the room - if he needs one.WoJ 2017-09-28T20:01:10.270

@iheanyi: well, put like that, perhaps James should have accompanied the manager into the room. I don't think there's enough information in the question to know what company policy says about that, but the manager thinks he should have. I lean towards saying he shouldn't, but I didn't write their company policy. Of course, telling someone your name is normally a reasonable start along the road to them accompanying you anywhere, and this manager opted not to even do that, so regardless of policy he got what was coming to him ;-)Steve Jessop 2017-09-29T18:05:36.540

@WoJ: he does know a way to get in though: find an employee who recognises you and is aware that you're authorised to be in there, and get them to let you in. There was just one tiny flaw in the manager's otherwise-perfect scheme. James didn't recognise him and had no clue whether he was authorised to be there or not. If Kozaky had been there the plan presumably would have gone off without a hitch, which I'd guess is among the reasons why the manager didn't just find out the code before heading over.Steve Jessop 2017-09-29T18:12:38.553

Folks, I agree that I wrote a good answer, but isn't 206 upvotes a little excessive?WGroleau 2017-09-30T10:04:29.403

@stevejessop Why would he acompanny somebody he doesn't know. The unknown individual's next action could be a tazer to the spine.T.J.L. 2017-10-01T15:24:49.913

@T.J.L: well, rather the point of the question is whether or not he should have known him. My point is merely that the question doesn't contain enough information about company policy to establish whether or not James was supposed to recognise him and, hence, supposed to "accompany him in". Saying, "I got X wrong because I got Y wrong" explains your reasoning but doesn't mean that somehow you're doing the job the company (however unreasonably) expects you to do, which (in the opinion of this manager) includes recognising managers.Steve Jessop 2017-10-02T23:01:55.977


Should an employee be disciplined for not recognising those further up the chain of command?

No they shouldn't, James did the right thing and your manager will/should support him now that he has the facts. But life is not always fair. This is fairly straightforwards though and even the disgruntled manager knows it.


37Yes. James is fine, especially when the manager point blank refused to identify himself.Snow 2017-09-28T10:14:11.667

Please consider an [edit] to expand why this was the right thing to do.


James did the right thing. In fact, James proved himself resistant to a social engineering trick often referred to as a "Bavarian fire drill".

IF anything James should be commended as he has demonstrated that he will adhere to policy and not be intimidated by someone using social engineering tricks.

A similar thing happened to a friend of mine when he was in the military. He was ordered to guard an area. An officer of some rank decided to try to bully his way in and nearly got shot. He was officially given a dressing down, but unofficially congratulated and told "good job". His record remained intact.

22Linking TV Tropes is the social-engineering attack!Nat 2017-09-28T23:26:38.200

2Which begs the question: why was he officially given a dressing down? It sounds like he followed his orders. Military politics?marcelm 2017-09-29T12:22:53.020

@marcelm yes, military politics. He followed orders perfectly, but he had a run in with a superior officer. So, to satisfy the military politics, he was given an official "talking to", but it didn't go in his record. It DID bolster his career though.Richard U 2017-09-29T12:37:00.227

1One of the interesting things about the military, which I learned from a (UK, not US) civilian contractor rather than first hand, is that to get on you have to learn which rules are real rules, that must be followed, and which rules are arrant nonsense that would cripple the organisation if anyone followed them, but that you must pretend to follow. Naturally, this distinction is never written down anywhere. Sounds like there was a difference of opinion in this case between the "officer of some rank" and the person with actual authority, but that the visitor was widely regarded as in the wrong!Steve Jessop 2017-09-29T12:48:14.373

@SteveJessop my father and brother were both US military. I tried to enlist but was rejected due to my bad hearing. Your friend was right, and there is an additional unwritten rule. If you irritate the wrong person, then EVERY rule will be enforced on you, some contradictory, so that no matter what you do, you WILL be violating some rule. One thing they do is have two superiors of equal rank give you contradictory orders. Since neither outranks the other, both have equal precedent and you WILL be disobeying orders regardless of your actions.Richard U 2017-09-29T12:54:47.023

My friend got some kind of equivalent-rank eventually, sufficient that he no longer had to go and fetch an officer every time he wanted a grunt on guard duty to step aside so that he could test-fire the microwave radar when they were stood in the "cooking zone". Presumably that meant sometimes he was one of the two superiors of equal rank...Steve Jessop 2017-09-29T12:58:58.413

In the military, officers usually have to be very careful when greens have their first guard duty, as they take the "use lethal force to stop anyone from entering" so seriously, that they tend to shoot officers who otherwise would be used to a more casual way of entering into some areas without wasting too much time with paperwork.Val 2017-09-29T20:13:28.187

@Val We had a junior Marine get reprimanded for chambering a round in response to a Colonel who wanted access to a secure area and wouldn't take no for an answer. As I recall, the justification was along the lines of: An officer running his mouth about wanting you to let him in is not someone "forcing entry", and he should be respectfully declined, even if he is being disrespectful to you.TemporalWolf 2017-09-29T22:12:00.910


I'm just going to answer the questions as stated here, since the security process aspect of the question here is clearly understood and has been handled appropriately.

Should an employee be disciplined for not recognising those further up the chain of command?

No. If they don't identify themselves or carry security credentials (business card, key code number, security pass), then the existing security measures trump everything.

Should employees be encouraged to learn who is above them, even if they will never directly report to them?

Yes. It makes sense for employees to be aware of the managerial hierarchy of the company, especially in the immediate chain of command above them. Knowing their names is fairly important in knowing how to deal with them if they happen to deal with you.


Posted 2017-09-28T10:03:32.400

4It does make sense to try to learn upper level management. But often the only way to learn is through photos on an org chart or corporate website. These photos tend to be the absolute best appearance of the person and are often years (decades?) out of date. Even if someone could ID a photo it doesn't mean they could recognize the person in real life.John Oglesby 2017-09-28T12:09:38.457

8LOL, I know who my manager is, and I know who his manager is (simply because they were above me in my old role). There is a great many people in this small company, who I have no clue who any of them are, and I'd do exactly the same in James' situation. Then again, I once didn't let the CEO into his office, because I didn't know who he was either (different job) and he commended me for it, so maybe I'm just lucky...djsmiley2k 2017-09-28T12:29:25.820

3Good answer except a business card shouldn't be counted as a security credential. A false manager could just have obtained one from a real manager.Sumyrda 2017-09-29T08:50:34.957


Ideally, James would not have even opened the door though, so if there is anything to be learned from this on his part it's that. I'd say there are lessons to be learned by all, but disciplining this employee is not only not right but creates liability for the company.

Lesson for senior management is there needs to be policy on this and it needs to be agreed across all areas and understood, how this should have been handled by James. Without such policy, and that being in the employee handbook or among a stack of policies all employees are required to read, understand, and sign, then the employee is expected to handle situations according to what is generally accepted across the industry -- and that is what he did.

Even if he is not formally disciplined, it sounds like the culture in this company is really not good. If it is even being contemplated to discipline a new employee for this, and/or other senior managers think their ego should trump IT security best practices.

The company paid money to put a coded lock on that door, so somewhere someone made the business case that what is in that room needs to protected and only accessible by persons authorized and with a need. I am sure that the argument the senior manager is making is "but I am authorized and not a bad guy!" Then why spend the money on that door security? If all employees are expected to personally know which other employees, at that point in time, are active employees and possess a business need to that room, then why was the money spent?

I worked for a company that is a global Fortune 50 company and their intellectual property is what pays for the jobs and lives of over 100,000 people. At that company, there is no circumstance where personal recognition is allowed to be used. No matter who, they need the credentials and physical ID card.

If your company has intellectual property that unauthorized disclosure would cause grave consequences, then the ones to discipline here are all the executives with a hand in responsibility of securing that IP. They should be disciplined for failing to create a culture that puts protecting that IP is everyone's first responsibility above all others -- including senior manager egos.

I personally would be looking for a new job if I was in your shoes. Sorry.

Edited to add: Another business reason there is a coded lock on that door is that perhaps there is a legal or regulatory requirement to have an audit trail of all who access that room. If that is the case, then your company is contemplating disciplining an employee for not breaking the law.

They should not be. The employee "James" (assuming their description of events is accurate) did exactly what they should have done.

Of course it's possible that James was rather ruder or more abrupt in the moment than he later was when describing it to you. In that case then possibly he was out of line.

i.e. the difference between "sorry, I can't let you in without a pass or code" and "get lost sucker" is pretty large.

Having said that, even if James is completely in the right - some people are petty and vindictive. It's entirely possible that this manager will decide to take things personally and attack James over it. It would be worth logging the incident in detail now. Note down the time, the location, and what happened. If there is CCTV you could even record that.

Now should the manager start making life difficult for James he will have ammunition to take to HR and/or use for legal action should that become needed.

Escalation like that isn't likely, but some people are just petty and vindictive enough to do it so it's worth having some coverage in place.

My currently out-of-office manager emailed me with a message along the lines of "Did James really not let that guy into the IT department? Did he really not know who he was?"

I'm Sorry Boss but even the million dollar security system our company had installed did not recognize the guy, how could James have? That guy did not correctly identify himself to either of them. James seems to have followed the book.

James did the right thing, but he may or may not have done it in the right way. Your company policy may or may not be good enough and/or clear enough, and he may or may not have known the policy. This is an opportunity to review (with your boss) and improve company processes and/or how they are communicated to new hires. As a benefit, the more you do that the less likely it is James can be considered responsible for doing anything wrong, and the more likely it is that the visitor will be found to have done something that either is against the current policy or that policy needs to change to forbid. As for James, the primary issues of concern seem to be:

  • He didn't allow an unknown person the free run of the IT room. This is definitely right.
  • He didn't recognise the guy and leap to attention. Entirely reasonable, especially for a new hire, unless the company induction process includes a list of names and faces and a note that it's important to learn them all! However, it seems to be why the guy is annoyed, so dealing with this as the real issue might make the spurious issue (not letting him in) go away too.

The visitor seems to have thought that his face should work as a security pass -- that is, every employee (even new ones) should recognise it and let him in. If that is company policy, then it is sufficiently unusual (and unwise IMO) that it needs to be properly communicated, which hasn't happened here since even you don't know about it. If it is not company policy, then ideally it should be communicated to managers that their face is not an access-all-areas pass, and they shouldn't get grouchy when employees fail to treat it like one.

Should an employee be disciplined for not recognising those further up the chain of command?

Not unless their boss (you) has told them this is important. Even if the company would prefer him to recognise managers, it would be rather disproportionate to make disciplinary matter of it on the first offence, early in his employment, if he has never been told that it's important.

Should employees be encouraged to learn who is above them, even if they will never directly report to them?

If they have no useful work to be doing, then I suppose so. Recognising your own chain of command, even up to C-level, is probably useful and a good idea as a matter of courtesy to their position. A UK SME (so up to 250 employees) in which you have too many people in your chain of command to recognise them all, needs to sort out its org chart with a weed whacker! In contrast, recognising everyone in the whole organisation who outranks you is often impractical, although it does no harm provided you don't waste a lot of time on it.

For that matter, how should James have acted differently if he had recognised the guy? It's one thing to recognise him, it's another thing to let him into an area that he apparently (due to not knowing a door code) may not be authorised for. Given that each office has its own code, it seems natural to assume that those who don't know the code shouldn't be there, even if you do recognise them.

Regarding that and other security matters, you know more than we do about the details of the event and of your office's general policies, but there are various secondary things that could have gone differently.

  • He didn't establish the guy's name. You say he asked the guy his name "again" and that the guy refused to answer. You don't say when he asked the first time, so without those details perhaps James could have been clearer what it was he needed from the guy. The guy should have been willing to give his name (but, as above, it seems what he really wanted was to be recognised wherever he goes, so I suppose that's why he refused). Not that the guy's name is a magic password that should let him into the room, but asking visitors to your office what they claim their name is, is still a good idea.
  • He held a conversation with the guy while standing with the door open. This is probably wrong but for a typical office only very marginally so. It led to a situation where the unknown person "tried to get past him", and he blocked him. Presumably with body language rather than physical force, but it's still not an ideal situation to put random IT staff into. One option would be to come out of the room, close the door behind him, and hold the conversation in the corridor, and that would be the preferred option for a seriously-secure room. James could be advised to do that in future, and/or it could be made written policy for the room if appropriate. He could even wait with the guy in the corridor for your return.
  • He didn't allow the guy supervised access to the room. Now, if this IT room is a secure server room, that's certainly right. But maybe it's "just" a random office, with no particular security protocols beyond all the other offices in the building, that you sometimes do allow people into for meetings/conversations/etc. If so, then James had the option to let the guy in and sit with him waiting for you. He chose not to take that option, but could be advised to at least consider it in future. One can speculate wildly about the possibility of some burglar overpowering him once in the room, but frankly they could have done that while he was standing in the open doorway. So far as physical security is concerned, that ship sailed when he opened the door at all. Of course, if there are confidential documents visible on desks and so on then it would not be appropriate to allow someone in, even supervised, without establishing their name and authorisation to be there. This is the primary non-aesthetic argument for "clean desk" policies, which you may or may not have.
  • He didn't escort him to reception and/or call security. Presumably that would have seriously ground the guy's gears in this case. But if you're in an even lightly-secure area, and decline to identify yourself, then you shouldn't really be surprised if that's what happens from time to time! As a matter of site policy, you should probably tell James (and all employees) what they're supposed to do about possible intruders, and what they're supposed to do to distinguish themselves from intruders.

Letting someone in the room even supervised is a big can of worms. Is there any paper around they shouldn't see? If they start wondering around and poking at things what are you going to do? If the employee gets called out to a tech support issue somewhere what does he do with the guy? etcTim B 2017-09-29T14:55:09.280

@TimB: right, the policy item to look at, is whether or not that can of worms is already open in this particular office. If so (that is, if the office is generally regarded as safe for supervised visitors) then it's an option. If not then of course a new hire shouldn't take the decision to open it :-)Steve Jessop 2017-09-29T16:43:26.593