‘Could you hold the door? I forgot my pass.’ Kindness is not identification
Someone carrying coffee, a parcel or a toolbox may look like an employee. Keep them out of the office without abandoning ordinary courtesy.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 8 September 2026
- READING TIME
- 7 min read
- TOPIC
- Identity and Access
You enter the office with coffee in one hand and a phone in the other. Somebody behind you says, “Thanks, I forgot my pass today.” They look like an employee, know the company’s name and appear completely at ease. Holding the door feels like ordinary courtesy.
That is why following another person through a controlled entrance works. It requires neither force nor an elaborate story. It relies on our natural reluctance to stop somebody in a doorway and ask an awkward question.
You can refuse entry without making an accusation
A simple answer might be: “Reception can help you get in — I still need to use my own pass.” Let the door close and point out the visitor entrance. You are not deciding whether the person is lying. You are applying the same rule to everyone, including a familiar colleague without identification.
If you feel safe doing so, ask whom they are visiting and offer to contact reception or the meeting host. A delivery driver, engineer or new employee should have an established route inside. High-visibility clothing, a parcel, a company T-shirt or knowledge of an executive’s name is not a substitute for a pass.
Do not grab the person, block them physically or create a confrontation. If they become aggressive or enter despite your refusal, move somewhere safe and report it immediately to security, reception or the contact named in your organisation’s process.
A visitor should be somebody’s visitor
The host should collect their guest, explain the rules and accompany them when the meeting ends. A visitor badge should be visible and permit access only where necessary. At departure it goes back to reception rather than into a pocket “for next time”.
If you see somebody without identification in a controlled office area, you can calmly ask whether they know where reception is. If you would rather not approach them, report their location and description. A report is not an accusation; it lets the responsible team verify the situation.
A pass that does not work is not permission for a shortcut
An employee with a flat, lost or forgotten pass should use the fallback process. Security can confirm their identity and issue a temporary badge. Letting them through “because I know them” removes the record of who actually entered the protected area.
If your own pass fails, do not ask colleagues to work around the rule. Report the problem, even when it costs a few minutes. That means other people do not have to decide when politeness should override the process.
The organisation must not leave one employee to manage the conflict
Doors and card readers are not enough when people do not know how to decline politely. The organisation should give everyone one sentence they can use and a clear reporting number or channel. Reception needs to respond promptly, or people will create more convenient shortcuts.
Avoid a culture of blame as well. Someone who accidentally allowed another person through should feel able to report it at once. A quick description of the place, time and visitor is more valuable than silence caused by fear of punishment.
What the source says and what Breachroad recommends
The UK’s Government Security function describes tailgating as gaining unauthorised access by following an authorised person or pretending to be trustworthy. It recommends wearing passes and, where people feel comfortable, challenging somebody without one or reporting them through the organisation’s process.
Breachroad recommends placing the decision with reception or security, not the employee standing in the doorway. The employee’s job is simpler: do not lend your access and point the person towards the proper route.
If a pass is genuinely missing, our article You lost your office badge explains what happens next. We practise these everyday scenarios in our cybersecurity training.


