How to Build a Credential Register for a Small Shop

Why this matters

Almost every shop that loses a licence loses it while believing it is current. The credential itself was never the problem. The problem was that nobody could answer, in under a minute, the question "what do we hold, who holds it, when does each one die, and where is the paper." A register answers that question on demand. Without one you are relying on renewal notices reaching an address you may have moved from years ago, and on one person's memory of what they signed up for when the shop had three people instead of nine.

Building the register is a one-time sweep and then a small monthly habit. The sweep is the part shops skip, because it feels like it should take an hour and it takes a day. That day is the whole return.

Step 1: Sweep, do not list

The instinct is to sit down and type out the credentials you remember. That produces a list of the ones you already knew about, which are exactly the ones that were never at risk. Sweep instead: go looking in the places credentials hide, and write down whatever you find.

Six places worth searching, in this order:

  • The issuing authority's own public lookup. Most licensing boards publish a searchable roster. Search your company name and each person's legal name. This finds credentials nobody in the shop remembers registering.
  • The insurance file. Your general liability, workers compensation, and commercial auto certificates all have expiry dates, and several licence types are conditioned on those policies staying in force.
  • The bank and bond file. A licence bond is a separate instrument with its own term, issued by a surety, not by the licensing board.
  • Every truck. Vehicle-linked credentials and driver medical certificates live in glove boxes and wallets.
  • Payroll. Every person on payroll gets checked against the register at the end of this process. A person with zero rows is either genuinely uncredentialed or a gap.
  • Old email. Search each person's inbox for the issuing authority's name. Confirmation emails carry identifier numbers that are otherwise a phone call to recover.

Skipping the authority lookup is the most common shortcut and it defeats the exercise, because the whole point is finding what you did not know you had, including credentials that have already gone dormant.

Step 2: Decide what counts as a row

A row is any credential whose expiry can stop work, void a job, or fail a customer's vendor check. That test is deliberately broad: it captures the company licence and the licence bond, but also the insurance certificate a general contractor demands before you mobilise, and the individual certifications your people hold in their own names.

It excludes two things people try to put on it. Training records are not credentials. A toolbox talk, an internal competency signoff, and an equipment familiarisation session all belong in a training log, because no external authority issues them and no inspector asks for the card. And an internal skill level ("second-year", "lead") is a pay-band label, not a credential. Keeping those off the register is what keeps it short enough that people actually read it.

Step 3: Fix the schema before you type anything

Enter one row with the wrong columns and you will re-enter twenty. Settle these fields first.

Field Why it earns a column
Credential name The authority's own wording, not your nickname for it
Holder The company, or a named individual. Never blank, never "the shop" when a person actually holds it
Issuing authority Who you contact, and whose lookup you verify against
Identifier number The number a customer or inspector will ask you to read out
Effective date Tells you the cycle length once you have two of them
Expiry date The one everyone remembers to include
What it gates Written as a consequence: "cannot pull permits", "cannot mobilise on commercial work"
Renewal dependencies Continuing education, bond, insurance proof, a qualifying individual, an exam
Lead time How far ahead the renewal must start, driven by the longest dependency
Renewal owner One named person. Not a department, not "office"
Status Active, Pending, Deficient, Lapsed. Four values, no free text
Proof file A link to the actual document, not a note saying where it is
Verified at source The date someone last confirmed status on the authority's lookup

The last field is the one almost nobody has, and it is the one that catches the failure that actually happens: a renewal that was filed and paid but never accepted, sitting in a deficient state while your internal record says "submitted, done."

Step 4: Attach proof, or it is not a row

A register with dates and no documents fails the only test it will ever face. When a general contractor asks for evidence at four on a Friday, "we hold that, I will find it Monday" is functionally the same answer as "we do not hold that."

Store the document image itself against the row. Name files so a stranger can pick the right one without opening it: holder, credential, expiry year. And keep the superseded copy for at least one full cycle after renewal, because the question you will eventually be asked is not "are you current" but "were you current on the date we did that job."

Step 5: Set the completeness rule, then count gaps honestly

State the rule as a Boolean at the row level so nobody negotiates it:

A row is complete when every schema field is filled AND a proof file is attached AND the verified-at-source date is within the last 12 months. Anything short of all three is a gap, not a row. The unit of analysis is the individual row, not the credential type and not the person.

The reason this is an AND and not a scoring system is that each of the three failures produces the same outcome at the counter. A row with a perfect expiry date and no document cannot be shown. A row with a document and no source verification can be a year out of date. Partial credit is exactly the thinking that lets a lapse survive a review.

Step 6: Reconcile against payroll, then set the cadence

Close the sweep by putting the payroll list next to the register. Every person on payroll should have at least one row, or an explicit note that their role requires none. That reconciliation is what turns the register from a snapshot into a control, because it catches the new hire whose certification nobody asked for and the departed employee whose credential the shop is still quietly relying on.

Then set the recurring pass: monthly, one owner, fifteen minutes, working only the rows inside their lead-time window. The register does not need daily attention. It needs to be re-verified against the source on a schedule and reconciled to headcount when headcount changes.

Worked example: the first sweep at a nine-person shop

A nine-person shop, one owner, one office manager, seven field technicians. Before the sweep the owner wrote down the credentials he could name from memory and got 11. The sweep found 23.

The 23 broke down as 7 company-held rows (the company licence, the licence bond, three insurance certificates, a local business registration, and one firm-level certification) and 16 individually-held rows (the qualifying individual designation, seven trade certifications, two individual renovator certifications, four driver medical certificates, and two specialty endorsements). So 16 of 23, about 70 percent, were held by people rather than by the business. That single ratio reframed the whole exercise for the owner, who had been thinking of licensing as a company-level obligation.

Proof documents existed for 15 of 23 rows, about 65 percent. Three rows, 13 percent, were already expired at the moment of the sweep: one specialty endorsement five months past, one individual renovator certification two months past, and one driver medical certificate seven weeks past. Two further rows fell due within 60 days.

Now run the completeness rule from Step 5 against that result. Fifteen rows had proof, but only 9 of those 15 also carried a verification against the issuing authority's lookup within the last 12 months. Under the rule as written, 9 of 23 rows, about 39 percent, were complete on day one. The other 14 were gaps, including all three of the expired rows and the six rows that had a document but no source check.

Note what that does to the headline. The shop did not discover "three problems." It discovered three active lapses inside a register that was 61 percent incomplete, which means the three found were the ones that happened to be visible. The six proof-without-verification rows were not clean results, they were unmeasured ones, and treating them as passes is the exact error the rule exists to prevent.

The reconciliation step then added one more finding the credential sweep missed entirely: a technician hired four months earlier appeared on payroll with zero rows. Nobody had asked him for anything at onboarding.

How to verify you got this right

Three checks, all runnable in an afternoon:

The stranger test. Hand the register to someone who does not work in the office and ask them to produce current proof of the company licence and of one named technician's certification. If they cannot do it without asking you a question, the schema is incomplete or the files are not attached.

The source-of-truth test. Pick three rows at random and check them against the issuing authority's public lookup rather than against your own file. Your register's status field should match what the authority shows. A mismatch on even one of three means the verified-at-source field is not being worked, and that is the failure mode that produces a lapse nobody noticed.

The headcount test. Count people on payroll, count people with at least one row, and confirm the difference is fully explained by roles that genuinely require no credential. An unexplained difference of one is a person working without something.

If the register survives all three, the remaining work is cadence, not construction.

References

  • U.S. Environmental Protection Agency, 40 CFR Part 745 Subpart E, which certifies the firm separately from each individual renovator and is why a small shop typically carries both a company-held and a person-held row for the same rule
  • U.S. Department of Transportation, Federal Motor Carrier Safety Administration, 49 CFR Part 391, under which a driver medical examiner's certificate runs a maximum of 24 months and may be issued for a shorter term at the examiner's discretion, so its expiry cannot be assumed from the cycle length
  • Your state or local licensing authority's public licence lookup, which is the only authoritative source for a status field
  • See related: Tracking Licenses and Continuing Education So Nothing Lapses; What a Shop Must Hold Versus What a Person Must Hold; How to Track Expiry Before It Becomes an Emergency