Skip to content

Ask Norma on Shared Devices: Shared Device Policy Access Without Breaking the Audit Trail

Ask Norma on Shared Devices: Shared Device Policy Access Without Breaking the Audit Trail
21 September 2026

Shared device policy access is the compromise most aged care facilities have quietly made. There are four tablets on the floor and fourteen staff on shift. Logging in and out between every interaction costs time nobody has, so a device gets logged in at the start of the shift and passed between whoever needs it. Everyone knows this is not how it was designed to work. Everyone does it anyway, because the alternative is slower than the work allows.

The consequence is that the audit trail records the wrong person. Every query, every lookup and potentially every entry is attributed to whoever logged in first, which means the record showing who did what is quietly wrong across an entire shift.

[IMAGE: shared device policy access - care staff passing a shared tablet during a shift while checking facility policy, alt text "shared device policy access on a shared aged care tablet"]

Two problems that get treated as one

Facilities tend to lump this together as a device issue. It is actually two separate problems with different solutions, and conflating them produces policies that address neither properly.

Attribution

Who did this. If four workers use a device logged in as one person, the system cannot tell you which of them recorded an observation or checked a procedure. For clinical entries this is a genuine integrity problem, because the record of who assessed a resident is part of what makes the assessment meaningful.

Infection control

A device carried between residents, handled with gloves and put down on surfaces, is a transmission route. This has nothing to do with attribution and needs its own cleaning protocol, but it gets bundled into device policy and then addressed vaguely.

Separating the two is the first practical step. A policy attempting to solve both in one paragraph usually produces a rule about wiping devices and says nothing useful about identity.

Why login friction drives the behaviour

Staff do not share logins because they are indifferent to record integrity. They share logins because the cost of not doing so is paid immediately, in seconds during a task, while the cost of doing so is abstract and deferred.

Anyone designing around this has to reduce the immediate cost rather than restate the rule. Repeated instruction to log in and out changes nothing if the process takes thirty seconds and interrupts care. This dynamic, and the fatigue it produces, is examined in more depth in the broader discussion of mobile accessibility in aged care compliance.

A distinction worth drawing is between actions that must be attributed and actions that need not be. Recording a clinical observation must be tied to an individual. Looking up what the facility's procedure is does not carry the same requirement, because reading policy is not an action taken on a resident.

That distinction is what makes Ask Norma workable on a shared device in a way that clinical entry is not. A worker can check a procedure on whatever device is nearest without creating an attribution problem, because nothing is being recorded against a resident. The lookup is fast precisely because it does not need the identity ceremony that a clinical entry does.

Designing around the split

A practical facility policy separates device use into two categories and sets different expectations for each.

Reference use, meaning looking up policy, procedure or guidance. Low friction, any available device, no requirement for individual login because nothing is being written to a resident record.

Record use, meaning anything entered against a resident. Individual authentication required without exception, because attribution is the point.

Stating this explicitly does two things. It stops staff treating all device use as equally burdensome, and it makes the case for strict authentication on clinical entry credible, because the rule is no longer being applied to situations where it serves no purpose.

How the assistant behaves across the hardware a facility actually owns, rather than a vendor demonstration environment, is worth establishing before writing the policy. Norma on existing devices covers this on equipment already in use.

What this looks like on a shift

The practical version is less elaborate than the policy language suggests.

A worker is about to assist a resident with something they have not done before at this facility. They pick up whichever tablet is on the trolley, ask Norma what the procedure is, read the answer, and put the device down. No login, no attribution question, perhaps twenty seconds. They then complete the task and, when they record it, authenticate properly against their own credentials because that entry is going into the resident's record.

The same device served both purposes with different rules, and the audit trail stays accurate because the only thing written was written by an identified person. Staff adopt this readily once it is explained, because it matches how they already think about the difference between reading and recording.

What breaks it is a blanket policy that treats every interaction as requiring authentication. Faced with that, staff share a login for everything, including the clinical entries where attribution genuinely matters. The strict rule produces a worse outcome than the differentiated one, which is the counterintuitive part worth explaining to anyone writing the policy.

What the audit trail should be able to show

The test is whether the provider can answer a direct question: who recorded this, and how do you know.

If the honest answer is that the entry is attributed to whoever logged the device in that morning, the provider has a record integrity problem regardless of how good the clinical care was. This surfaces during incident investigation, when establishing who observed what and when becomes the central question and the system cannot answer it.

Facilities sometimes discover this only during an investigation, which is the worst possible moment. Checking it proactively is straightforward: pick a recent clinical entry and ask whether the named person actually made it. Doing this on a handful of entries tells you quickly whether the practice matches the policy.

The broader framework for access control and data handling sits in data privacy and access security, and device practice needs to be consistent with it rather than an informal exception to it.

Agency and casual staff on shared devices

Agency workers compound the problem. They may not have individual credentials, they are on site briefly, and the path of least resistance is to hand them a device already logged in as a permanent staff member.

This produces records attributed to someone who was not present. It is a straightforward integrity failure and it is common, and it tends to go unexamined because it is nobody's specific responsibility to notice.

Provisioning short-term credentials is an administrative burden, and facilities weigh that against the risk. What is not defensible is having no position at all, leaving each shift to improvise. The related question of how agency staff reach policy at all is covered in policy access for agency staff.

The reference and record split helps here more than anywhere else. An agency worker can use Ask Norma on any available device from the moment they walk in, with no provisioning required, because reading policy creates no attribution problem. Their clinical entries still need proper credentials, but the thing they most urgently need on a first shift, which is knowing how this facility does things, is available immediately rather than waiting on an account.

Infection control on the device itself

Handled separately, as it should be. A device moving between residents needs a cleaning protocol with the same specificity as any other shared equipment: what product, at what frequency, whose responsibility, and what happens when a device is used in an isolation room.

Cases and screen protectors that tolerate the cleaning products a facility actually uses are worth specifying, since a device that degrades under disinfectant will quietly stop being cleaned. The pattern is predictable and the fix is a procurement decision rather than a training one.

Frequently Asked Questions

Q: Why is shared device policy access a problem in aged care?

Because shared logins break attribution. If several workers use a device logged in as one person, the system cannot establish who recorded an observation, which undermines the integrity of the clinical record.

Q: Can staff use Ask Norma on a shared device?

Looking up policy does not write anything to a resident record, so it does not carry the same attribution requirement as clinical entry. That is what makes reference lookup workable on any available device while clinical entry still requires individual authentication.

Q: How should a facility policy handle shared devices?

By separating reference use from record use and setting different expectations for each. Applying strict authentication to all device use makes the rule feel arbitrary and encourages staff to work around it everywhere.

Q: What about agency staff without individual credentials?

Handing them a device logged in as a permanent staff member produces records attributed to someone who was not present. Facilities need a position on short-term credentials rather than leaving each shift to improvise.

Q: How can we check whether our audit trail is accurate?

Take a handful of recent clinical entries and confirm the named person actually made them. This reveals quickly whether practice matches policy, and it is far better discovered proactively than during an incident investigation.

Q: Is device cleaning part of the same policy?

It is a separate problem requiring its own protocol covering product, frequency, responsibility and isolation room use. Bundling it with attribution tends to mean neither gets addressed properly.