NYC RedCode training needs certificate-to-card review
New York City immediately invalidated RedCode Site Safety Training certificates, while affected cards may still scan as active during a 90-day replacement period through December 7. Public and project systems need to distinguish certificate source, card issuer, replacement progress, and the city's current status.
Editorial figure by Civic Permit Review. Source context: NYC Department of Buildings Site Safety Training information.
Separate the invalid certificate from a temporarily active card
The New York City Department of Buildings says it immediately invalidated Site Safety Training certificates issued by RedCode Inc. after its September 8 announcement. Its current SST information page also says affected cards will remain active when scanned on a job site during the 90-day grace period through December 7, 2026. A records system that stores only 'card valid' can therefore miss the source and replacement status of a training certificate beneath that card. Conversely, a system that marks every affected card revoked immediately would overstate the agency's current guidance. Both conclusions require certificate-level and card-level evidence.
For an affected record, distinguish the worker's verified identity, each underlying course certificate and issuing provider, the SST card issuer and identifier, the agency's current card status, the date of each validation, and the replacement action required. Preserve the September 8 announcement as a dated event and the current DOB SST page as the operational guidance reviewed September 21. If the two records appear to differ on an edge case, the authoritative agency's current instructions and individual record should resolve it; an internal badge color must not silently override the city. This is an editorial record-design recommendation, not a determination of a worker's eligibility.
Keep the two replacement paths distinct
DOB says workers with RedCode-issued SST cards must complete the required training and obtain a new card from a DOB-registered course provider by December 7. The current guidance treats cards issued by other providers using RedCode certificates differently: those cards can remain active after December 7 if the worker completes the required replacement training during the grace period. Without that replacement, the card will be revoked. A review workflow therefore needs both the card issuer and the certificate issuer; 'RedCode-related' is too broad to decide which path applies.
The city also says workers who used RedCode certificates for DOB worker certifications and licensing requirements must complete required training by the same deadline. That creates a separate licensing-record question, not a conclusion that every building permit or every professional license changed status on September 8. A jurisdiction should map the affected agency function and credential record before changing an applicant, contractor, site access, or licensing status. The DOB guidance supplies the public transition rule; the current individual status must come from the city's own verification process.
Make a scan an observation with a date and source
The DOB announcement says an SST card can be scanned with a smartphone app to validate its authenticity, and that affected cards remain active when scanned during the grace period. A scan result is useful evidence of what the city service returned at a particular time. It does not prove the worker completed replacement training, that an underlying RedCode certificate regained validity, or that the same card will remain active after the deadline. Record the verifier, scan time, card identifier, response, and source so a later review can distinguish an old successful scan from current agency status.
A useful scenario test covers four cases: a RedCode-issued card before replacement, a card from another registered provider that depended on a RedCode certificate, a replacement training record completed during the grace period, and a card checked after December 7. Ask which record shows the course provider, who enters replacement evidence, how the agency's live result is checked, and what happens when the card record and certificate history disagree. Escalate uncertain cases to the qualified DOB or site-safety owner instead of relying on a generic portal checkbox.
Preserve the agency's scope and the open questions
The city's September 8 announcement says roughly 2,000 active RedCode-issued cards were affected and describes free training offered through the Department of Small Business Services. That approximate public count does not identify an individual worker, establish that each worker lacked training, or measure the number of cards later replaced. The announcement refers to criminal allegations against the provider; the publication does not make an independent finding about any worker's conduct, training history, or fitness for a site. The DOB current page is the better source for the two card replacement paths and the December 7 date.
The operational priority for permit, licensing, and site-safety record owners is a dated issuer-to-certificate-to-card trace with a clear route to current DOB verification. The publication cannot verify individual cards, substitute for the department's decision, or advise a particular site whether a worker may enter. Later agency guidance, a changed deadline, or a particular card result would require a new dated record rather than a silent rewrite of this September 21 analysis.
Enterprise buyer test
Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.
A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.
What we will watch next
Civic Permit Review will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.