
Access logs are the automatic records of every entry attempt in an operation, with identity, point, time and outcome. Analysing them makes it possible to identify repeat fraud, such as badge lending, tailgating at the turnstile, access outside the roster and successive attempts at different points. Detection becomes effective when the system cross-references those records with documents, training and rosters in real time.
Every operation with a turnstile generates access logs. Few use them. In most companies the record is only consulted after an incident — when the damage has already happened and the investigation becomes archaeology.
The point is that fraud in access control is rarely an isolated event. It is repetitive by nature: someone who discovers they can lend their badge or slip through alongside another person tends to repeat the behaviour until they are stopped. And repeated behaviour leaves a pattern.
In this article you will see what logs record, which patterns reveal recurring fraud and how to structure that analysis in practice. Read on!
What are access logs and what do they record?
An access log is the automatic record of every interaction with a controlled point — turnstile, barrier, door reader or mobile terminal. A well-formed record holds at minimum:
Identity (who presented the credential), credential used (badge, biometrics, facial), access point, direction (entry or exit), date and time and, the most underrated field of all, the outcome with its reason.
The reason for the block is the most valuable data point
A log that only says "denied" is of little use. A log that says denied for expired document, denied for being outside permitted hours or denied for lapsed training lets you separate operational error from deliberate attempt. That granularity is what makes analysis possible.
A denied attempt is not noise
Many operations discard denied attempts to "clean up" the report. It is exactly the opposite: the denied attempt is the richest signal there is, because it shows intent. See how to monitor access attempts systematically.
Which patterns indicate repeat fraud?
Credential lending
The classic sign is an entry with no matching exit followed by a new entry on the same badge. If the credential recorded two consecutive entries with no exit in between, either it was passed on, or someone tailgated. Biometrics eliminates much of that scenario — see the advantages of biometrics in access control.
Access made impossible by time and distance
The same identity recorded at two distant points with an interval shorter than the travel time. It is objective proof that the credential is being used by more than one person.
Tailgating at the turnstile
One authorised passage for two people. It shows up as a mismatch between the number of accesses and the actual occupancy of the area, or between accesses and time-clock records.
Successive attempts at different points
Denied at the main gate, denied at the dock, authorised at the service entrance. That sequential trail indicates someone testing which access point has the loosest rule — and it usually reveals a genuine configuration flaw.
Access outside the roster or at unusual hours
Recurring entries at weekends, on public holidays or overnight, with no matching work order. In isolation it may be legitimate; repeated and unexplained, it warrants investigation.
A departed employee's badge still active
Any record of someone who has already left is a serious process failure. It is the scenario covered in how to prevent improper access after departure.
How to structure the analysis in practice
1. Guarantee the quality of the record
Analysis does not fix bad data. Require direction of passage, a standardised block reason and clocks synchronised across every reader. A clock out of sync makes any time-based correlation impossible.
2. Define what normal looks like
Before hunting anomalies, establish the baseline: volume per point, peak hours, average time on site by type of contract. Without a baseline, every event looks suspicious.
3. Cross-reference with the other sources
The log alone shows little. The value appears in the cross-reference with the roster, the work order, the contractor's documentation and the time-clock record. A divergence between access and time clock is one of the most reliable indicators.
4. Prioritise by risk, not by volume
One denied attempt in a classified area matters more than twenty in the car park. Weight the alerts by the criticality of the area.
5. Close the loop
Every confirmed anomaly should turn into a rule adjustment, a permission review or disciplinary action. Analysis that does not change configuration becomes a decorative report.
Which indicators to track
A useful dashboard of access KPIs usually brings together the rate of denied attempts per point, the distribution of block reasons, the number of entries without exit, access outside the roster and repeat offences per person — that last one is what separates error from pattern.
How RainbowTec automates this detection
Doing this manually in a spreadsheet does not scale. In an operation with thousands of passages a day, the analysis has to be continuous and automatic.
On the RainbowTec platform, the decision happens before release, not in next month's report. Access control consults the third-party management base in real time: an expired document, lapsed training or a closed contract block passage automatically, with the reason written to the log.
Real-time monitoring shows occupancy by area and denied attempts the moment they occur, and the whole trail stays available for audit — with compliance backed by Bureau Veritas ISO/IEC 27001 certification and by adherence to the LGPD.
Access fraud leaves a trail. The question is whether your operation is reading that trail in time. Talk to RainbowTec and see how to turn your logs into automatic decisions.