My boss pretended he couldn’t use Zoom, until he forgot the recording was on – Part 3

Story code: ST-001356

Part 3: The Audit File

I sat at the IT desk, watching the playhead on the media player sweep across the timeline of Webcam Recording File WR-904. On the left side of the split screen, Vance’s terminal window showed his administrator credentials-credentials he had claimed he never received from the district office. On the right, his face was illuminated by the blue glow of his triple-monitor setup. He wasn’t squinting. He didn’t have his reading glasses on. He typed with the fluid, rhythmic cadence of a seasoned network engineer.

Then, he did something that made me freeze the frame. He reached to the corner of his desk, pulled a secondary hardware key out of a drawer, and plugged it in to authorize the secure shell connection. That key was only issued to system administrators who had completed the state’s advanced security training. Vance had signed the receipt for that key three years ago, yet his public service record claimed he had failed the basic digital literacy assessment twice to excuse himself from remote training duties.

An email notification popped up in the corner of my screen. It was from Sarah.

“Leo, Principal Vance says his virtual grade book is locked again. He asked me to manually enter all ninety-eight of his student attendance records for the mid-term report before the district database closes at five. Is there any way you can unlock his screen from your end? I’m in the middle of grading essays.”

I looked at the system dashboard. Vance’s grade book wasn’t locked. The status indicator was green. He had simply set his sharing permissions to ‘View Only’ for his own account, a setting that took three deliberate clicks in the advanced console, then sent Sarah a screenshot of the greyed-out input boxes.

“I’m looking at the server logs, Sarah,” I replied. “His portal access is fully functional.”

Ten minutes later, the desk phone rang. The caller ID displayed the main office.

“Leo,” Vance’s voice was low, devoid of the jovial, bumbling tone he used in the virtual classrooms. “I was looking at the system maintenance log. I see there was a minor firewall alert during my session this morning. A routine glitch, no doubt.”

“It was a security exception, Principal Vance,” I said. “The system registered a manual root bypass.”

“Yes, well, these new systems are highly sensitive,” he said, his breathing steady over the line. “I must have triggered it while trying to get my screen to respond. Let’s go ahead and clear that log from the active queue. We have the regional board audit starting tomorrow morning, and I don’t want their team getting bogged down by automated false positives. Clean the queue, please.”

“The system auto-archives all security exceptions, Principal Vance,” I said. “The logs are write-once. I don’t have deletion permissions for security backups.”

A pause stretched over the line. “I’m sure an administrator override can handle a simple queue cleanup, Leo. I’ll send you the authorization ticket. Just make sure the exception file is cleared before eight tomorrow.”

He hung up. He didn’t realize that the authorization ticket he was about to draft would require him to use the very administrative credentials he claimed he didn’t know how to access. And more importantly, he didn’t know that the regional board’s automated compliance scraper had already queued WR-904 for retrieval.


Leave a Comment