← All writing

2026-07-04

Running an authentication desk that people can trust

Intake discipline, claim-based assignment, the 11-component inspection, why a verdict should mint a verifiable certificate, and building room for someone to say 'I'm not sure.'

Authenticating a watch looks like a technical judgment: look at the case, the dial, the movement, decide genuine or not. In practice, how much anyone should trust that judgment depends at least as much on the process wrapped around it as on the eye that made the call. A brilliant authenticator working inside a sloppy process produces opinions nobody outside the room has good reason to fully believe. A decent authenticator working inside a disciplined one produces something closer to evidence. We’ve spent a lot of time thinking about the second kind, and this is roughly what we’ve landed on.

Write it down before you look at it

Every watch that reaches the desk should get a record before anyone forms an opinion about it: brand, model, reference, serial if visible, who submitted it, how it arrived, and when. This sounds like a formality, and in a sense it is, but the order matters more than it looks like it should. If the record gets created after the inspection, shaped by whatever conclusion was already reached, it stops being a record and starts being a justification. Writing it down first means the facts exist independently of the opinion that gets formed about them, and can’t be quietly reshaped to fit it later, even unconsciously.

One name, one claim, at a time

A request should be claimed before anyone works it, and the system should refuse a second claim while the first is still open. This sounds bureaucratic until you’ve actually watched two people each give a watch a half-look, both quietly assuming the other one is doing the real pass. Diffused responsibility is where careless verdicts come from, not usually dishonesty, just the ordinary human tendency to assume someone else is covering the boring, careful part. A claim fixes that: exactly one name is attached to a decision while it’s being made, and that name is the one that should be able to explain it afterward.

Break the watch into fixed points, not one big feeling

The temptation with authentication is to let an experienced eye render one holistic verdict: genuine, not genuine, done. We think that’s a mistake, or at least an incomplete one. A structured inspection, broken into fixed components, case, dial, hands, crystal, bezel, bracelet or strap, clasp or buckle, movement, serial and engravings, papers, packaging, forces two things that a single overall impression doesn’t. First, it makes the authenticator actually look at the boring parts, and the boring parts are often exactly where a fake gets cut, a clasp with the wrong action, papers that don’t quite match the piece they’re travelling with. Second, it leaves a structured trail: a list of pass, fail, or not-applicable per component, with notes, rather than a paragraph written after the fact that reads suspiciously like it’s justifying a conclusion the writer already had in mind before they finished looking.

A verdict that only lives in your own database is worth less than it should be

Here’s the part we think gets underrated: even a perfect inspection process is only as trustworthy, from the outside, as the record it leaves behind. An internal note saying “verified genuine, see file” is worth exactly as much as people trust your internal filing to be worth. A verbal assurance from a person, however qualified, is worth exactly as much as people trust that one person. A published, independently checkable certificate, a page anyone can load, a number nobody can forge or guess from a serial, a QR that resolves to that same page from a photo of a printed tag, moves the basis of trust from “this business says so” to “here’s the record, go look at it yourself.” It also makes correcting a mistake honest instead of quiet: if a verdict turns out to be wrong, revoking it means the public page now says so, clearly, rather than the error just sitting buried in a private system nobody outside ever sees.

This is also why we think Inconclusive should never produce a certificate, no matter how confident anyone feels in the moment. A certificate is a claim your business is willing to stand behind publicly. “We’re not sure” is a legitimate, honest outcome of an inspection, but it isn’t that kind of claim, and pretending otherwise for the sake of giving the customer something to hold onto is exactly the shortcut that erodes the whole system’s credibility over time.

Build a real door marked “I’m not sure”

The most dangerous failure mode on any authentication desk isn’t a wrong verdict delivered in good faith. It’s a guess wearing a verdict’s clothing, produced by someone who felt pressure to resolve a request rather than admit uncertainty. If escalating a request looks, procedurally or socially, like admitting failure, people will quietly stop doing it and start guessing instead, and you’ll never see it happen because a confident-looking wrong answer and a confident-looking right one are indistinguishable from the outside until something goes wrong downstream. Escalation needs to be a normal, first-class outcome: it should keep the original authenticator’s name and claim attached (not anonymize them back into a queue), and it should require a specific reason, so whoever picks it up next knows exactly what stalled the first pass instead of starting cold.

None of this is exotic. It’s mostly discipline: write first, claim before you work, break the inspection into parts, publish the outcome somewhere checkable, and make room for doubt. It’s also, not coincidentally, the shape our own authentication-operations module is built around, queue, claim, the same eleven points, a verdict that can mint a certificate. If you’re weighing whether to build one of these yourself or use ours, that’s a conversation worth having at /bench.