
I once watched a team decide how much proof a customer would owe us forever.
You call about your own claim, and the system wants two numbers, both exactly right, first time.
The Insight: Somebody Chose How Much Is Enough
On an insurance project, the phone system asked callers for their claim number in full and the date of birth attached to it, both exact. One wrong digit and the call dropped out to an agent for manual checking. The rule came from the privacy side, not from the people who ran the service. The business area didn't want it. The customers plainly didn't want it. The reason I was given was that there might be an edge case — someone malicious getting into a claim if the friction dropped too low. Nobody had a number for how often that had happened. I lost the argument.
That isn't proof the risk was imaginary — a control that works produces nothing to count. It is evidence that nobody was going to be asked for a number.
NIST's identity guidelines treat proving who you are as a ladder rather than a switch. Evidence is graded fair, strong or superior, and somebody decides how strong yours has to be. That choice is meant to be a risk assessment. I think it usually isn't. A false accept is an incident with someone's name on it. A false reject is a person who gives up quietly. Somebody may answer for that years later — a regulator, an audit — but not in the room where the bar is being set.
The ladder is about identity, but the shape is the same wherever a service decides how much evidence is enough.
Real-World Lens: The Bar Gets Set Where Nobody Feels It
Eleven million notes a year, and the asking is free. An independent review commissioned by the government — Sir Charlie Mayfield's Keep Britain Working review — found the fit note system "not working as intended." On the department's own figures, around 11 million are issued a year and more than 90% say the person is not fit for work. The employer asks for the note. The clinical appointment produces it. In May the government announced an overhaul, calling the process a "tick-box exercise which does not offer any support or guidance." Two of its four pilots skip the note entirely.

Norway swapped the proof for something else, and absence didn't jump. One Norwegian municipality let workers self-certify sickness absence: you told your line leader instead of fetching a doctor, and joined a counselling programme instead. Researchers studying it ruled out any large rise in absence, and found it fell among women. It was one town, and self-certification came bundled with that programme, so this is an existence proof rather than a law. But the feared thing did not arrive.
Under the Hood: The Door the Standard Leaves Open
The same standard that grades the evidence also says what to do when someone hasn't got it. Its exception handling describes applicant references — people who vouch for you "in the absence of sufficient identity evidence" — and trusted referees, trained agents allowed to make the call. I have never worked on a service that built either.
It isn't free. Someone trained to make that call costs money — a countable cost — and the moment you build the door, a name goes on whatever comes through it. Which is the same asymmetry, one floor up, except nobody in that room got to make that argument.
False accept | False reject | |
|---|---|---|
Who notices first | the institution | the person |
Who answers for it | someone, by name | nobody with a veto |
How it shows up | an incident | a handoff, a retry, someone who stops |
On that project the failed calls didn't vanish. They arrived at an agent's desk for manual checking. The cost was real, it was measurable, and it still wasn't anybody's argument.
So What?
The question isn't whether proof is reasonable. Often it is — where the real failure is money leaking out rather than people shut out — so which dominates in your service, and did anybody in the room bring a number?
I've been on the losing side of this before. The difference is the reason: last time it was a custom, this time it was a story nobody could check.
You can't argue with a number that doesn't exist.
So if you're ever in that room, ask how often it has actually happened. When nobody knows, ask what we'd have to see to find out, and who's going to look. When the number already exists, ask why it isn't in the room. Then two harder ones: what happens to the people who keep bouncing off it, and who would have to say yes to the door the standard already leaves open.
Reply and tell me: what's the last thing you had to prove about yourself, and what would have happened if they had simply believed you?
Next Wednesday: Who is this actually built for? — the joint account with one "primary" holder, the carer who isn't on the file, the relationship the drop-down doesn't offer.
Forwarded this? The Listening Loop pulls apart one invisible piece of service design every Wednesday — subscribe and the next one lands in your inbox. See you then.
Go deeper: NIST's Digital Identity Guidelines: Identity Proofing and Enrollment (SP 800-63A-4) — skip the front of it and read the exception-handling section. It is the part where a standard built to grade evidence sets out, in procedural detail, how to accept somebody's word without any.
Sources:
