Kiosk and time clocking
The kiosk is a screen by the entrance: PIN or QR code, optional photo and location. Checks are ordered so a failed clock-in does not consume a one-time code.
Clock in at a kiosk — step by step
This is what an employee sees at the screen:
- The kiosk starts on Time clock kiosk. If it asks for a code, enter it in Kiosk code and click Open kiosk. Usually, the person setting up the kiosk does this once; the address remembers the code afterward.
- On Choose an option, click the tile for what you want to do: Clocking (record a time event), Status (view your current status), or Leave.
- Select how to identify yourself with Scanner / Keyboard or Camera. For the camera, you may need to click Enable camera and choose Front or Rear.
- Identify yourself using a method enabled on that kiosk: scan your QR code, present your RFID card, or click PIN and enter it on the on-screen keyboard. The screen says Scan code to clock in. The PIN button appears only when PIN code is enabled in the kiosk settings.
- Under Available actions: choose an event, such as Clock in or Clock out. A dot on the tile suggests the action that fits your current status.
- If the kiosk asks for a comment (Comment (required)), enter one. This happens when you clock in late, with the message Add a comment — you are clocking in late.
- Wait for confirmation: WORK STARTED, WORK ENDED, STARTED, or ENDED. Only then has the event been saved.
- If it is refused — Invalid code, You are too far from the kiosk to clock in., or This kiosk requires a photo. — meet the requirement in the message and repeat from step 4. Your one-time QR code has not been consumed; see “Checks performed during clock-in.”
Three ways to record work time
- Kiosk — a dedicated screen by the entrance; no system login required.
- Panel — an employee clocks in from their own account.
- Manual entry or correction — handled by HR (Event log, corrections, and workdays).
Kiosk configuration
Each kiosk has a code, warehouse, location description, allowed event types, login methods, and optional photo and location requirements, late-arrival tolerance, comment requirement for late arrivals, and live statistics.
Configure these under Settings → Attendance. Saving requires 2FA confirmation for kiosks, event types, and login methods. Viewing settings does not require confirmation.
Event types and login methods are configured per company. Items without a company assignment are system templates shared by everyone. Copy a template rather than changing it if you want your own names.
Checks performed during clock-in
The order is deliberate. Knowing it helps explain the messages:
- Does the kiosk exist?
- Is this event type allowed on this kiosk?
- Do the login details match, and are the credentials not locked?
- Is the location inside the allowed area, if the kiosk requires it?
- Is there a photo, and is it actually an image in an allowed format and size, if the kiosk requires one?
- Is the event type active?
- Does the event make sense for the employee's current state? You cannot clock in twice, clock out without clocking in, or end a break that never started. The server checks this, not the screen.
- Is the event a repeat of the same event made moments ago? An identical clock-in within one minute is treated as a double-click and does not create a second event.
- Is the clock-in late, and is a comment required?
- Only now is a one-time QR code consumed.
The last check is deliberately at the end: a failed clock-in does not burn a one-time code. An employee with a dynamic QR code who forgot a comment can correct the issue and clock in with the same code.
Exclusive groups
Event types can belong to an exclusive group; two events in the same group cannot be active at once. Starting the second automatically ends the first, and the system marks that end as automatic.
In practice, moving from a break to training does not require you to end the break manually.
Employee status comes from configuration
Whether someone is “at work,” “on a break,” or “away” comes only from event type settings; nothing is hard-coded. A new type works immediately when its flags are set correctly.
Security
The kiosk works without a system login; it is designed to stand at an entrance. This has some consequences:
- The kiosk code alone is enough to retrieve its configuration.
- Activating a kiosk also requires a secret token.
- Clock-ins are rate-limited per credential on each kiosk, not per IP address. Everyone at a site behind one connection therefore does not share a single limit, while PIN guessing gets a very low limit.
- Credentials are locked after a series of failed attempts. A person with HR permissions can unlock them on the employee screen, with 2FA confirmation.
- Kiosk photos are checked on the server (type, size, actual contents); the file extension does not come from the browser.
- Live statistics appear only when the relevant option is explicitly enabled.
Treat the kiosk code as internal information and do not post it outside the employee area.
A night shift belongs to the day it started
A clock-in at 23:50 and clock-out at 06:10 form one workday: the day the shift began. The kiosk, reports, and workday calculation use the same local time (HR module pitfalls).
Clock in from the panel
An employee can also clock in from their account. Two rules apply: you cannot clock in twice without clocking out, and you cannot clock out without first clocking in. The system records the IP address and browser.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo