Before you start
This system records who worked, where, and for how long. It has two halves. The dashboard is a website used in the office. The app is an Android app used in the field. They talk to the same records.
| Who | What they use | Where |
|---|---|---|
| Administrator, manager | The web dashboard | https://twinfusion.co.ke/attendance/admin/ |
| Supervisor, foreman | The Android app, signed in | On their own phone |
| Worker | The Android app in staff mode | A shared phone at the site |
Everything in this manual is something you can actually press. Where a capability exists in the system but has no screen yet, it is listed under Not on a screen yet rather than described as if you could use it.
All times shown are East Africa Time. Hours are shown as 8h 30m in the dashboard and as decimal hours in the CSV export. The system records time; it does not calculate pay.
Part 1Administrator
The web dashboard, used in the office. This part assumes you have an administrator or manager account.
1.1 Signing in
- Open https://twinfusion.co.ke/attendance/admin/ in a browser.
- In Email or employee ID, type your email address or your employee code.
- Type your Password.
- Press Sign in.
If your sign-in belongs to more than one workspace, the page comes back asking which one to open. Pick it from the Workspace list, type your password again, and press Open workspace. The password is asked for a second time because it is never held between steps.
Administrators, super administrators and managers. Ordinary employees have no dashboard password at all — they use the app. The sign-in page says so: "Manager and administrator sign-in. Field staff use the mobile app."
After eight failed attempts the account is locked for fifteen minutes and you will see Too many failed attempts. Try again in 15 minutes. Wait it out; there is no way to shorten it.
Signing out
Your name sits at the bottom of the dark sidebar on the left. Press the power symbol beside it. Always do this on a shared computer.
1.2 Finding your way around
The sidebar on the left is the whole dashboard. Everybody who can sign in sees:
- Dashboard — today at a glance, and the exceptions that need a decision.
- Live map — everyone currently clocked in, on a map.
- Timesheets — the record of hours worked. Corrections happen here.
- Directory — the people.
- Locations — the sites and their geofences.
Administrators and super administrators also see:
- Devices — the shared handsets that clock people in by face.
- Automations — automatic rules and the organisation's attendance settings.
- Plan & billing — the subscription.
Below the menu, departments are listed as a tree. Clicking a department opens Timesheets already filtered to it. A number beside Timesheets is the count of attendance records waiting for a decision.
The bell at the top right is your inbox. Open it to read alerts; press Mark all read to clear the badge.
A manager can open Dashboard, Live map, Timesheets, Directory and Locations, but cannot add, edit or remove people, and cannot create or change locations. Those buttons are simply not drawn for them.
1.3 The Dashboard
This is the page that opens when you sign in. It answers one question: what needs my attention today?
The date
The date box at the top left changes the whole page. Pick a past date to see that day. Back to today returns you.
The five tiles
- Attendance rate — how many of the headcount checked in.
- Currently clocked in — people on shift right now.
- Late arrivals — people who checked in past their shift's grace period.
- Out of bounds — people who checked in outside a geofence.
- Hours logged — total hours, with overtime underneath.
The three live tiles refresh by themselves every 30 seconds. You can leave the page open on a wall screen.
Exceptions & alerts
The list at the bottom is the working part of this page. Every row is somebody whose day needs a decision — late, outside the fence, a suspicious location reading, or a shift that was never closed. A row marked Awaiting review is waiting on you.
Each row carries the buttons that settle it:
- Approve accepts the record as it stands. It is marked approved with your name against it.
- Reject asks "Why is this being rejected?" You must type a reason — cancelling the box cancels the rejection.
- Add note attaches a comment to the record without deciding it either way.
- Timesheet opens that person's full timesheet.
See all in Timesheets at the top right of the panel opens every flagged record for that day.
Approving or rejecting here decides one attendance record. It does not hire or dismiss anybody, and rejecting a record does not delete it — the hours stay on the timesheet with the rejection recorded against them.
1.4 Live map
Everyone clocked in, listed on the left and pinned on the right. The two are the same list. Both repaint every 20 seconds.
- A pin is purple normally and red when the check-in landed outside its fence.
- A pin fades when the phone has not reported a position for 30 minutes; the roster row shows No ping 30m+.
- Each row shows the check-in time, how long they have been on shift, the site, and the phone's battery level when it was reported.
- Fit all zooms out to show everybody.
- Manage sites jumps to Locations.
Blue outlines on the map are the site geofences. A worker inside one is where they should be.
1.5 The Directory
The people. It has two views and you switch between them at the top left.
Board view
Four columns, one for each stage of joining: New registration, Pending ID verification, Active employee, Offboarded. Each card shows the person's name, employee code, job title, department, their employment type, and an On shift tag if they are clocked in right now.
Drag a card into another column to move that person's stage. The change saves immediately and a message confirms it. Drag it back to undo.
List view
A dense table: employee, employee ID, department, team, manager, employment type, number of sites, stage, account status, and when they were last seen. Two buttons sit at the end of each row — Edit and Timesheet.
Searching
- Type into the box marked Name, employee ID or email.
- Press Search.
- Press Clear to go back to the full list.
Opening somebody's profile
Click anywhere on a card or a row — not on a button — and a panel slides in from the right. It shows:
- Four figures for this month: days worked, hours worked, late days and fence breaches.
- Contact and employment details, including when they last signed in.
- Postings — the sites they are attached to, current and ended, with hours worked at each.
- Recent attendance — their last days, with in, out, hours, status and whether the check-in was inside the fence.
- Devices — the phones that have paired with their account.
The buttons along the bottom of the panel are Delete permanently, Remove, Reset password, Edit and Done. They are covered below.
1.6 Adding an employee
- Open Directory.
- Press Add employee at the top right.
- Type the Full name. This is the only field that must be filled in.
- Leave Employee ID blank and the system allocates the next one (EMP0001, EMP0002 and so on). Type one only if your payroll already uses a particular code.
- Fill in Email and Phone if you have them. Neither is required.
- Set the Job title and the Role — Employee, Manager or Administrator.
- Set Employment type: Office, Field, Hybrid or Casual / daily.
- Choose a Department, a Team and who they Report to, if those apply.
- Choose a Shift. Leave it on — Organisation default — unless this person works different hours; the shift is what decides whether an arrival counts as late.
- Set Joined on and the Onboarding stage.
- Temporary password — leave it blank and one is generated for you.
- Under Attendance policy overrides, switch on anything that should apply to this person only: Require a selfie at check-in, Allow check-in outside a geofence, Track route while on shift. Leave them off to use the organisation's settings.
- Under Assigned locations, tick every site this person works at. The first one you tick becomes their primary site.
- Press Create employee.
Immediately after saving, a box appears with the temporary password. It is shown once and cannot be read back afterwards. Copy it before you close the box. If you lose it, use Reset password on the person's profile to issue a new one.
Somebody with no assigned location has no geofence to check in at. Their profile says so plainly: "Not posted to any site yet — without a posting this person has no geofence to check in at." If they will use a shared site phone, the posting is also what puts them on that phone's list of recognisable faces.
1.7 Editing an employee
- In list view, press Edit on their row. Or open their profile and press Edit at the bottom.
- Change what you need to.
- Press Save changes.
Two fields appear only when editing:
- Engaged until — for casual engagements. Clear it to make the engagement open-ended.
- Account status — Active, Suspended or Archived. Suspending or archiving signs the person out of every device immediately.
Employee ID, Shift and Temporary password disappear when editing — they are set at creation.
Resetting a password
- Open the person's profile.
- Press Reset password and confirm.
- The new password is shown once. Copy it and give it to them.
Every signed-in device for that person is signed out at the same time.
1.8 Postings: adding and ending
A posting attaches somebody to a site. It is what allows them to check in there, and it is the record that explains, months later, why their punches at that site were accepted.
Adding a posting
- Open the person's profile.
- Find the Postings section and press Add posting.
- A numbered list of locations appears. Type the number of the one you want and confirm.
Ending a site posting
Use this when someone finishes at a site but stays employed.
- Open the person's profile.
- In Postings, press End on the row for that site.
- A box asks for the end date and offers today. Accept today to stop check-ins immediately, or type a different date.
- The confirmation names the hours kept, for example: "Posting to Kitengela Yard ends 2026-09-01. 146h 20m of recorded work there is retained."
The posting stays on the list, greyed out and tagged ended. That is deliberate: attendance at a site somebody is no longer posted to would otherwise look unexplained. Press Re-post to put them back.
A posting you end stops the shared site phone recognising that person the same day. This is different from a posting that merely lapsed on its own end date — see 2.3.
Deleting a posting
A small ✕ appears beside a posting only when nobody has worked any hours against it. That is for a posting added by mistake. Once there are hours the button is not offered, and the system refuses: This posting has 12 attendance records against it, so it cannot be deleted. End it instead — that keeps the history and stops future check-ins.
1.9 Removing someone
Remove takes a person out of the directory. It is the correct action for almost everybody who leaves.
- Open the person's profile.
- Press Remove.
- Read the confirmation: "They are signed out everywhere and their postings end. Every hour they worked is kept and stays payable, and you can restore them later."
- Confirm.
What actually happens:
- The account is archived and hidden from the directory.
- Every signed-in device for them is signed out.
- Every posting is ended.
- Every recorded hour is kept. The confirmation message names the total, for example "312h 45m of recorded work is retained and still payable."
- If they were still clocked in when you removed them, the message tells you to close that shift under Timesheets.
Nothing is destroyed by Remove — the record is hidden, not deleted, and the system supports putting the person back. In this release there is no button on the Directory screen to do the restoring; if you remove somebody in error, contact your system administrator rather than re-creating the person, because a second account splits their attendance history in two.
Two removals that are refused
- Your own account: You cannot remove your own account.
- The last active administrator: This is the last active administrator. Promote somebody else first, or nobody will be able to sign in and manage the organisation.
Permanent deletion
Delete permanently is the last button on the profile and the least prominent, because it is nearly always the wrong one.
- Open the profile and press Delete permanently.
- A box asks you to type
DELETEin capitals. Anything else cancels.
If the person has even one attendance record, the deletion is refused outright:
Amina Yusuf has 42 attendance records. Permanently deleting the account would delete those too, so it is not allowed. Remove them from the directory instead — that hides the account and keeps the hours.
Permanent deletion is only for a duplicate or a mistyped entry that never worked a shift. It cannot be undone, and it takes the person's face template and paired devices with it.
1.10 Locations and geofences
A location is a site with a boundary drawn around it. That boundary is the geofence. A check-in inside it is normal; one outside it is flagged, and may be refused.
The page shows your sites down the left and a map on the right. Click a site card to load it into the editor.
Creating a geofenced site
- Open Locations and press Add location.
- Type the Name — what your people call the place, not what the map calls it.
- Fill in the Address if you want it on record. It is free text and is not used to position the fence.
- Find the place. In Find by address or place type at least three characters — a street, an estate, a landmark — and press Search or the Enter key. Pick a result and the pin drops there. See below for the detail.
- Set the Type: Office, Client site, Warehouse or Remote. This is a label only; it does not change how the fence behaves.
- Choose the Fence shape — Circle (pin + radius) or Polygon (drawn ring).
- For a circle: the pin is the centre. Drag the Radius slider, or type an exact figure in the box below it. The slider runs to 2,000 m; typing allows anything from 10 m to 20 km.
- For a polygon: click the map at each corner of the site. You need at least three. Undo point removes the last one; Clear starts the ring again.
- Set Max GPS accuracy (m) — the default is 75. A position reading blurrier than this is rejected rather than trusted.
- Pick a Map colour so this site is easy to pick out.
- Tick any departments and teams that should be posted here. Everyone in them can then check in at this site.
- Press Create location.
Circle or polygon?
| Use a circle when | Use a polygon when |
|---|---|
| The site is roughly round or compact — an office, a shop, a gate, a single yard. It is quicker to set up and easier to widen later: move one slider. | The site is long, L-shaped, or sits beside somewhere you must not include — a road corridor, a fenced plot on a corner, a warehouse that backs onto a neighbour. A circle would have to be so wide it would swallow the street. |
For a circle, distance is measured from the edge of the ring. A worker reading 130 m from the centre of a 120 m fence is 10 m outside — and that is what the breach will say.
Searching for an address
- Type at least three characters into Find by address or place.
- Press Search, or the Enter key. Enter will not save the form — it only runs the search.
- Pick a result from the list. The pin drops there, the latitude and longitude fill in, and the map zooms to it.
- If you left Name or Address blank, they are filled in from the result. Anything you typed yourself is left alone.
- Drag the pin, or click the map, to fine-tune the position.
The search tells you what it found:
- "Type at least three characters of the address to search." — the query is too short.
- "Nothing matched that. Try a nearby landmark or town, or click the map instead."
- "The address lookup service could not be reached. Click the map or type the latitude and longitude instead — the location will save either way."
You can always place a site by clicking the map or typing the coordinates. The address search is a convenience; if it fails, the location still saves.
Editing a location
- Click the site's card in the left-hand list. The editor opens with its fence drawn.
- Wait a moment. Save changes stays greyed out until the current department and team assignments have loaded, and the tick boxes are locked until then.
- Make your changes and press Save changes.
If you tick any department or team when saving, the whole assignment list for that site is replaced by what is ticked. Individual people posted to the site one by one are managed from the Directory and are not touched here.
If you see "Could not load current assignments — editing disabled", close the panel and open it again. Saving in that state would wipe the site's assignments.
Taking a location out of use
- Open the site in the editor.
- Press Deactivate at the bottom left.
- Confirm: "Deactivate this location? History stays intact, but nobody can check in here."
The site stays in the list marked inactive. Nothing is deleted.
1.11 Timesheets
This is where hours are reviewed, corrected and signed off. It is the page that feeds payroll, so every change made here is recorded.
Filtering
The row of controls at the top narrows the table:
- A from and to date.
- All departments — pick one.
- Any status — present, late, half day, absent, on leave, holiday, weekend, missing checkout.
- A search box for a name or employee code.
- Flagged only — records the system has marked for a human to look at.
- Pending only — records waiting for approval.
Press Apply to run the filters, or Reset to clear them.
The totals
The six tiles describe the whole filtered range, not just the rows visible on screen: records, people, hours worked, overtime, late minutes and how many are pending review.
Correcting a punch
Times and the day's status are edited directly in the table.
- Click the Check in or Check out cell you need to correct.
- Type the corrected date and time.
- A box asks "Reason for this adjustment (recorded in the audit trail):" Type why. This is not optional in practice — it is what makes the change defensible months later.
- The Worked and Late columns recalculate themselves from the corrected times.
The Status cell works the same way, from a list, and does not ask for a reason. Notes on a record are added with the Add note button.
The system refuses it: Check-out cannot be before check-in. If both times are wrong, correct the check-in first.
Approving and rejecting
- Find the row. Rows awaiting a decision show pending in the Approval column.
- Press Approve to accept it.
- Press Reject and type why. The reason is required.
Your name appears under the approval status once you have decided.
Flagged records — what the flags mean
A flagged row is shaded and its reason appears when you hover over it. The reasons the system writes are:
| Flag | What happened |
|---|---|
| Outside <site> by <distance> | The punch was taken outside the geofence, and by how far. |
| Mock location reported | The phone was running a fake-GPS app. |
| Weak GPS fix (<n>m) | The position reading was blurrier than the site allows. |
| Synced <n> h after the event | The punch was taken offline and only reached the server much later. |
| Auto-closed: no check-out recorded | The shift was left open past the cut-off and the system closed it at the scheduled end of shift, not at the moment it noticed. |
| Provisional registration awaiting approval | The worker was registered in the field and nobody has ratified the engagement yet. The hours are real. See 1.13. |
A record can carry more than one reason; they are joined with a semicolon.
Seeing what was changed
- Press History on the row. A number beside it is how many edits it has had.
- The panel lists every change: which field, the old value, the new value, the reason given, who made it and when.
- If nothing has been changed it says "No edits recorded — this row is exactly as the app captured it."
Exporting
Export CSV downloads exactly what your filters are showing. The columns are:
Employee code · Name · Department · Date · Check in · Check out · Worked (h) · Late (min) · Overtime (min) · Status · Approval · Check-in fence · Distance (m) · Site · Travelled (m) · Flag reason
Hours in the export are decimal, so 8h 30m appears as 8.5.
1.12 Staff devices
A staff device is a shared Android phone left at a site. Workers clock in on it by face, with nobody signed in. The Devices page is where you provision them from the office. (A supervisor can also set one up from the phone itself — see 2.1.)
Adding a device from the dashboard
- Open Devices and press Add device.
- Give it a Label, for example Gate handset — Kitengela. Write the same name on the back of the phone. It is what names the device on every punch it makes.
- Choose the Site. A device pinned to a site only searches the people posted there, which is both faster and much less likely to mistake one worker for another. Leave it on Any site in this workspace only for a phone that genuinely travels.
- Leave Require a liveness check switched on. It is what stops a printed photograph clocking somebody in. Turn it off only where a person is watching the handset.
- Press Create device.
- A pairing code appears in large type. It is shown once. Press Copy code or write it down.
Pairing the phone
- On the handset, open the app and choose Administrator, then Pair device.
- Type the code. It is not case-sensitive and the dash is optional.
- The phone stores its own credential and goes straight to the face screen.
The code expires after 30 minutes. If it lapses, or if you close the panel before pairing, press New pairing code on the device's card.
Reading a device card
| Tag | Meaning |
|---|---|
| paired | Working. The card shows when it was last seen and from which address. |
| code waiting | A pairing code has been issued and has not expired yet. |
| never paired | The code was never used and has expired. Issue a new one. |
| revoked | Stopped. The reason and the date are shown. |
| liveness on / off | Whether the phone asks people to blink or turn their head. |
| N faces in range | How many enrolled people this device can recognise. |
Re-pairing and revoking
- Re-pair issues a fresh code — for a phone that was wiped or replaced. It does not stop the old phone. The existing credential keeps clocking people in until the new code is redeemed.
- Revoke stops the device immediately and asks for a reason. Use this for a lost or stolen phone. A revoked device cannot be given a new code — create a new device instead.
1.13 Casual and daily labour
The rule this part of the system is built on: "can work" and "has been approved" are two different facts.
A labourer hired at 06:40 has to be clocking in at 06:45. Waiting for an office to open would mean the hours were worked and never recorded — and unrecorded hours are the one failure this product exists to prevent.
So the system does this:
- A supervisor registers the worker at the site phone with a name and phone number. Email is optional. See 2.2.
- The worker is created as an active employee straight away and can start work. They are given an employee code automatically and are recognisable at that phone from that moment.
- Their engagement is marked pending. Every shift they work while pending is recorded normally but is flagged with "Provisional registration awaiting approval" and set to pending approval, so it reaches a reviewer in Timesheets instead of sliding into payroll unexamined.
- An administrator later rules on the engagement itself — whether this person is genuinely on the books.
Whatever is decided about the engagement, the hours already worked stay on the record and stay payable. Rejecting a field registration closes the engagement — the person can no longer clock in from the next scan — and it leaves every attendance record completely untouched. The system records how many shifts and how many minutes are retained at the moment of the decision, so payroll can still settle them.
The same holds for Remove in the Directory and for rejecting an individual timesheet record. A judgement about the future never deletes the past.
The engagement decision does not yet have its own screen in the dashboard. What you can do today, and what most reviews actually need, is in Timesheets: tick Flagged only or Pending only, look for the flag Provisional registration awaiting approval, and approve or reject each shift. If you decide the person should not be on site at all, open them in the Directory and set their Account status to Archived, or use Remove — both keep their hours.
1.14 Other screens
Two more pages exist for administrators. They are named here so the sidebar holds no surprises; they are not covered step by step in this manual.
- Automations — rules of the form if this happens, and these conditions hold, then do that, plus the organisation-wide attendance settings. A set of built-in alerts (geofence breach, late arrival, mock location, missing check-out) fires whether or not you configure anything.
- Plan & billing — the workspace's subscription and its seat allowance. If a plan limit is reached, adding an employee is refused with a message naming the limit.
NewFace check-in (new in this release)
Everything in this section is new or changed in version 1.1.0. If you have used the app before, this is what is different.
What changed
Face recognition now comes first. A worker no longer needs a login page at all. The app opens, asks who is holding the phone, and a worker goes straight to a camera screen. If the system knows their face, the clock starts.
- The app no longer starts at a sign-in screen. It starts at "Who is using this phone?" with two choices: I'm staff and Administrator.
- A supervisor can turn a phone into a staff device on the spot, by signing in on it and pressing Set up this device for staff. No pairing code, no trip to the dashboard.
- An unknown face can register itself, standing at the phone, with a name and a phone number — and start work immediately.
- Locations are searchable by address in the dashboard, so a crew sent somewhere new can be given a fence in a minute.
What the worker sees
The staff screen is a live camera. There is nothing to press to start it.
| State | On screen |
|---|---|
| Waiting | "Look at the camera to clock in", with the site name at the bottom. |
| Checking | An action to perform — blink, turn, nod — then a short wait. |
| Recognised | Their name and Clocked in or Clocked out, with the time and the total worked today. |
| Already on shift | Their name, how long they have been working, and the buttons Clock out and My history. |
| Not recognised | "We don't know this face yet" and a Register me button. |
| No GPS yet | "Waiting for a location fix — nobody can clock in until this device knows where it is." No punch is sent without a position. |
A result stays on screen for about 20 seconds and then the screen returns to waiting, so the next person in the queue never sees the previous person's details.
Face enrolment and consent
Before any face is recorded, the person is shown a notice in full and must agree to it. The notice is not a tick box buried in a form; it is a screen with I agree and Not now, and Not now simply exits.
What is stored
- The phone measures the face and turns it into a list of numbers — a face template.
- Only those numbers are sent to the server.
- No photograph of the face is uploaded, and none is kept on the phone.
- The numbers cannot be turned back into a picture of the person.
- The template is used only to verify attendance. It is never used to identify anybody anywhere else.
Separately from the template, the system records that consent was given: when, on which device, under which version of the notice, and a fingerprint of the exact wording that was shown. The wording itself is not stored twice.
Asking for it to be deleted
A worker can withdraw at any time. On a phone where they are signed in with their own account, that is Face verification → Delete my face data → Delete permanently. The templates are deleted outright — not marked inactive — and the consent is recorded as withdrawn.
A casual worker who has no login of their own cannot reach that screen. They should ask their supervisor, who should pass the request to an administrator.
There is no button in the dashboard for an administrator to view or delete somebody's face data on their behalf. Until there is, a deletion request from a worker without a login has to go to whoever maintains the system. Do not promise a worker a same-day deletion you cannot perform.
Liveness — why people are asked to blink
Before the system will even look at who a face belongs to, it asks for a movement it chose at that moment — a blink, a nod, a turn of the head — and checks that it happened. This is what stops somebody holding up a photograph of a colleague.
It is not perfect and the system does not pretend otherwise: it defeats a held-up photograph, not a purpose-built attack. That is why a shared phone should be somewhere a person can see it.
How sure the system has to be
A face is only accepted when it is both a strong match and clearly better than the next-best person. Two similar faces scoring almost the same is not a match — it is a coin toss, and the cost of losing it is clocking in the wrong person. In that case the system refuses and asks the person to try again.
This is also why a device should be pinned to a site. Searching the eight people who work at a gate is far safer than searching four hundred across the company.
Part 2Supervisor / Foreman
In the field, on a phone. You need a supervisor, manager or administrator account to do any of this.
2.1 Setting up the phone as a staff device
This turns a phone into the site's clocking device. Do it once, on the phone that will stay at the site.
- Open the app. If it asks "Who is using this phone?", choose Administrator.
- Sign in with your employee code and password.
- On the home screen, find the card headed Set up this device for staff and press the button of the same name.
- Choose where the phone lives. Pick the site from the list. Choose Anywhere in the organisation only if the phone genuinely travels between sites.
- Give it a Name for this device — at least two characters. Staff never see it; supervisors do, in the device list.
- Leave Ask staff to blink or turn their head switched on.
- Press Set this device up.
The phone signs you out, opens straight into the face screen, and is now the site's device. It will come back to that screen after a reboot, an update or a crash.
- You need a connection. The credential is issued by the server.
- Getting the phone back out of staff mode needs an administrator's employee code and password. See 2.6.
If you were given a pairing code from the office instead, choose Administrator then Pair device and type the code. Both routes end in the same thing.
2.2 Registering a worker in the field
Use this for a casual or daily hire who is not on the system. It takes under a minute and the worker can start immediately.
- Hand the worker the site phone, or hold it for them. They look at the camera.
- The screen says "We don't know this face yet". Press Register me.
- Enter the Full name — at least two characters, as it should appear on the record.
- Enter the Phone number. This is required. It is how the worker will be reached.
- Email address (optional) — skip it. Most day labourers do not have one, and it is not needed.
- Fill in Job title (optional) if it helps. How are you engaged? is already set to Casual, which is right for a day hire; change it to Field, Office or Hybrid only if it is not.
-
Engaged until (optional) — a date in the form
2026-12-31. Leave it blank if you do not know. Leaving it blank is safer than guessing. - Press Continue.
- The consent notice appears. Let the worker read it, or read it to them. They press I agree — or Not now, which stops the registration and is a legitimate answer.
- The camera opens. The worker follows the prompts — look straight ahead, turn slightly left, turn slightly right — until the angles are captured.
- The screen says "You are registered". Press Start work.
- The phone returns to the face screen. The worker looks at the camera once more and the clock starts.
The worker is created as an active employee with an automatically allocated employee code, posted to this device's site, and marked as awaiting an administrator's ratification. They can work today and they will be recognised tomorrow without registering again. Their shifts are flagged for review until somebody in the office rules on the engagement — and whatever is ruled, the hours they worked are kept.
Things that will stop you
- "Enter a phone number of at least three characters so your supervisor can reach you." — the phone number is not optional.
- "That email address does not look right. Correct it, or clear the field — email is optional." — clearing it is usually the right answer.
- "Write the date as YYYY-MM-DD, for example 2026-12-31, or leave it blank."
- "Registering needs a connection — your face cannot be recorded for later." — you cannot register somebody offline. Move to where there is signal, or send them to work and register them when the connection is back.
2.3 A returning casual worker does not re-register
A worker who was registered last week, last month, or on the last job does not go through registration again. They walk up, look at the camera, and the clock starts.
Registering the same person twice creates two accounts for one human and splits their attendance history in two. It cannot be tidily undone.
The system deliberately protects this. When a posting to a site simply lapses — somebody set an end date, the job ran a week longer — the worker is still recognised for 30 days afterwards and their punch is accepted, with the re-engagement written into the record for an administrator to see. That is because the alternative is worse: the hours get worked anyway and go unrecorded, or somebody registers the same person a second time.
A posting an administrator deliberately ended is different. That takes effect at once, and the worker will not be recognised from that day.
So if a known worker is refused at the camera, the first question is not "register them again". It is: has somebody ended their posting, or has their account been suspended? Ask the office before you create a second record.
2.4 When somebody is refused
Work through this before registering anybody a second time.
| The screen says | Do this |
|---|---|
| We don't know this face yet — for somebody who is registered | Try once more in better light, facing the camera squarely, without a cap pulled low. If it still refuses, ring the office: the person's posting may have been ended or their account suspended. |
| A liveness message — blink, turn, expired | Ask them to hold the phone at eye level and follow the prompt properly. A check that takes too long expires and has to be started again. |
| Waiting for a location fix | Step into the open. The phone will not send a punch without knowing where it is. |
| This device has no connection | Face clocking cannot be saved for later. Note the time on paper and clock them in when the signal returns, then have the office correct the times in Timesheets. |
| A distance message — You are 300 m from … | You are outside the site's fence. Move onto the site. If the crew really is working somewhere new, the office needs to add that location. |
| You are already checked in | They have an open shift. They should clock out first. |
2.5 Watching your team
On your own phone, signed in as a supervisor, the Team tab shows today.
- A summary line: headcount, clocked in, not clocked in, late, out of bounds, and the attendance rate.
- Filters across the top: Everyone, Clocked in, Not clocked in, Late, Out of bounds.
- Each person's row shows their state, how long they have been on shift or how late they were, their site, and a Flagged tag where the record needs review.
- Refresh pulls the latest.
The phone can sound an alert when somebody on your team clocks in. Use Mute check-in alerts to silence it; arrivals still appear on the screen.
2.6 Taking the phone back out of staff mode
- On the face screen, press and hold the site name at the bottom of the screen.
- The unlock box appears.
- Type an administrator's or manager's employee code and password.
- Press Unlock.
The phone stops clocking staff in and returns to the sign-in screen. The password is checked against the server, so this needs a connection.
An ordinary employee's credentials will not do it: "Those credentials are valid, but only an administrator or manager can take this device out of kiosk mode."
Part 3Worker
What you see and what you do. Most workers only need section 3.1.
3.1 The shared site phone
There is no password and nothing to remember. The phone is already on the camera screen when you pick it up.
Clocking in
- Stand in front of the phone. The screen says "Look at the camera to clock in".
- Hold it at eye level and look straight at it.
- If you are asked to blink, nod or turn your head, do it slowly. This is how the phone knows it is looking at a person and not a photograph.
- Your name appears with Clocked in and the time. Your shift has started.
- Hand the phone to the next person. The screen clears itself after about twenty seconds.
Clocking out
- Look at the camera again, exactly as before.
- Your name appears with how long you have been working, and a Clock out button.
- Press Clock out. The screen confirms the time and your total for the day.
The phone works out for itself whether you are arriving or leaving. If you are already on shift, it offers to clock you out. If you are not, it clocks you in.
Seeing your own record
- After the phone recognises you, press My history.
- "Your last few days" lists your recent days — the time in, the time out, and the hours.
- Press Hide my history, or just wait. The screen clears itself.
Only your own days are shown, and only right after the phone has recognised your face. Nobody can look up your record on that phone without you standing there.
If the phone does not know you
- The screen says "We don't know this face yet".
- If you have never registered, press Register me and follow 2.2. Your supervisor should be with you.
- If you have registered before — even months ago, even on a different job — do not register again. Press Try again, and stand in better light. If it still refuses, tell your supervisor. Registering twice splits your record in two and can cost you hours.
3.2 Your own phone
Some staff — usually those with a job title and an email — are given their own login and use the app on their own phone. If you were never given an employee code and a password, this section does not apply to you; use section 3.1.
Signing in
- Open the app and choose Administrator at the first screen if you are asked.
- Type the Employee code your supervisor gave you and your Password.
- Press Sign in.
You need a connection the first time only: "You need a connection to sign in the first time. Once signed in, clocking in works offline."
Clocking in and out
- The Today screen shows where you are, how accurate the GPS reading is, and how far you are from your site.
- Wait for a GPS reading. If it says "Waiting for a GPS reading", step outside and press Refresh.
- Swipe the slider marked Swipe to check in.
- If a selfie is required, the camera opens. Take it.
- If you are outside your site's area, you are asked for a note: "You are outside the designated area. Add a note to proceed." Say why — for example, delivering at the client site.
- The banner confirms: "Checked in. Your shift is running."
- At the end of the day, swipe Swipe to check out.
If you had no signal, the banner says your punch was "Saved on this phone and will sync by itself" with a count of what is waiting. It sends itself when the connection returns. You do not need to do anything.
Your history
The History tab shows 7, 30 or 90 days, with a summary at the top: days worked, total worked, overtime, late days and flagged days. Each day shows the times, whether the check-in was inside the fence, and your selfie if one was taken.
The Alerts tab is your inbox from the office.
3.3 Your face data and your rights
Read this before you agree. It is short and it is the whole story.
- Your employer uses face verification to confirm that it is really you clocking in and out. That is all it is used for.
- Your phone measures your face and turns it into a list of numbers — a face template. Only those numbers are sent.
- No photograph of your face is uploaded, and none is kept on the phone.
- The numbers cannot be turned back into a picture of you.
- You will be asked to blink or turn your head, so the system can tell a live person from a held-up photograph.
- Agreeing is your decision. If you would rather not, choose Not now and speak to your supervisor about recording your attendance another way.
- You can withdraw at any time. Withdrawing permanently deletes your face templates from the server.
Deleting your face data
If you have your own login on your own phone:
- Open Face verification from the home screen.
- Press Delete my face data.
- Read the warning — if your employer requires face verification, you will not be able to clock in until you set it up again.
- Press Delete permanently.
If you use only the shared site phone, you have no settings screen of your own. Ask your supervisor to pass the request to the office. You are entitled to make it, and the request should be honoured.
ReferenceTroubleshooting
The messages people actually hit, and what to do about each.
At the camera
| Message | What it means and what to do |
|---|---|
| No face was found in that photo. Point the camera at your face and take it again. | The selfie attached to the punch had no face in it — a wall, a ceiling, a pocket. The punch is not accepted until a real face is captured. Hold the phone at eye level, in light, and take it again. |
| Face not recognised. / We don't know this face yet | Either this person has never enrolled, or the match was not confident enough. Try again in better light, facing the camera squarely, cap and sunglasses off. If they have registered before, do not register them again — see 2.3. |
| Move your face into the circle. | The camera cannot see a face at all. Step closer and centre yourself. |
| More than one face in view. Make sure only you are in the frame. | Ask the person behind you to step aside. |
| That took too long and the check expired. Start again. | The liveness check has a short life. Start over and follow the prompt promptly. |
| We could not see the movements we asked for. Try again somewhere brighter, holding the phone steady at eye level. | The blink or head turn was not clear enough. Slow down and exaggerate it slightly. |
| We could not get a clear enough view of your face. Try again in better light. | The captures were not good enough to store. Move away from direct backlight. |
| Face verification needs a connection — the check is issued by the server and cannot be done offline. | Face clocking will not work offline at all. Ordinary clocking in on a personal phone does. |
Location and geofence
| Message | What it means and what to do |
|---|---|
| You are 300 m from Kitengela Yard. Check-in outside the assigned area is not permitted. | You are outside the site's geofence and this workspace does not allow out-of-bounds check-ins. Walk onto the site. If the crew genuinely is working somewhere else, the office must add that location. |
| You are outside the designated area. Add a note to proceed. | Out-of-bounds check-ins are allowed here, but never unexplained. Type why and continue. The record is flagged for review with your note attached. |
| GPS accuracy is 120m, which is weaker than the 75m required. Move to open sky and retry. | The position reading is too vague to trust. Step out from under a roof, away from a wall, and wait a few seconds. |
| A mock location provider was detected. Disable it and try again. | The phone is running a fake-GPS app. Turn it off in Android's developer settings. Punches taken this way are flagged even where they are allowed. |
| This device does not know where it is yet. Tell your supervisor. | The site phone has no GPS fix. Move it near a window or outside. |
| Location permission is needed before you can clock in. | Android has not been given permission. Press Fix permissions and allow location for the app. |
An out-of-bounds check-in from a shared phone
A shared site phone has nobody to type a note — the worker is standing at a screen with no keyboard. So when an out-of-bounds punch is permitted, the device writes the explanation itself, naming the device and the distance, for example:
Recorded away from the site by the "Gate handset — Kitengela" staff device, 310 m from Kitengela Yard. The worker was identified by face; no note could be typed on a shared device.
The record still appears in the review queue. It is not an exemption — it is an explanation.
Signing in and connection
| Message | What it means and what to do |
|---|---|
| You need a connection to sign in the first time. Once signed in, clocking in works offline. | A brand-new phone, or one that has been signed out, must reach the server once. Find signal or Wi-Fi. After that, ordinary clocking in works without a connection and syncs later. |
| This device has no connection. Face clocking cannot be saved for later — tell your supervisor and try again once it is back. | Face recognition happens on the server and cannot be queued. Write the times down on paper and have the office correct them in Timesheets. |
| This kiosk is not paired, or its access has been revoked. | The site phone has lost its credential — or somebody revoked it in the dashboard. An administrator must set the device up again. |
| Too many failed attempts. Try again in 15 minutes. | Eight wrong passwords on the dashboard. Wait; there is no shortcut. |
| Invalid or expired CSRF token. Reload the page. | The dashboard page has been open too long. Reload it and try the action again. |
| This workspace is not currently active. Please contact your administrator. | The subscription has been suspended or cancelled. Nobody can clock in until it is restored. |
Installing and updating the app
These phones do not get the app from the Play Store — it is installed directly, and the app updates itself. When a new version is ready you will see "Version 1.1.0 is available" with a Download update button showing the size, because the download may spend the phone's own data.
- "Android needs your permission to install apps from Attendance." — press Allow installs, switch the permission on, and come back.
- "The downloaded file did not arrive intact and was discarded. Try again, ideally on Wi-Fi."
- "There is not enough free space on this phone for the update." — clear some space and retry.
- "This phone is running a version the server no longer accepts." — the update is compulsory. Nothing already recorded is lost.
Android may refuse with App not installed or a message about the signature not matching. That happens once, when the key the app is signed with changes — for example when a build moves from a test key to the real one. Android will not upgrade one over the other.
The fix, once:
- Make sure nothing is waiting to send. On a personal phone the Today screen shows the sync state — wait for All synced before going further.
- Uninstall the Attendance app from Android's app settings.
- Install the new version.
- Sign in again. On a site phone, uninstalling clears its staff credential — an administrator must set the device up again (2.1) or issue a new pairing code (1.12).
In the dashboard
| Message | What it means and what to do |
|---|---|
| This posting has 12 attendance records against it, so it cannot be deleted. End it instead … | Correct behaviour. Use End; it keeps the history and stops future check-ins. |
| … has 42 attendance records. Permanently deleting the account would delete those too, so it is not allowed. | Use Remove instead. It hides the account and keeps every hour. |
| This is the last active administrator … | Promote somebody else to administrator first, then try again. |
| Check-out cannot be before check-in. | Correct the check-in time first, then the check-out. |
| Could not load current assignments — editing disabled | Close the location panel and reopen it. Do not save while it says this. |
| The address lookup service could not be reached … | Place the pin by clicking the map, or type the coordinates. The location saves either way. |
| A polygon fence needs at least three points. | Click at least three corners on the map before saving. |
| No locations yet — add one under Locations first. | You are trying to post somebody to a site before any site exists. |
ReferenceNot on a screen yet
Honest limits of version 1.1.0. These things the system can do, but there is no button for them in the dashboard. They are listed so nobody hunts for a control that is not there.
- Restoring a removed employee. Remove is reversible by design and destroys nothing, but the Directory has no list of removed people and no restore button. If somebody is removed in error, ask whoever maintains the system — do not create a second account.
- Approving or rejecting a field registration as a whole. There is no review queue screen for engagements. Review the individual shifts in Timesheets (Flagged only or Pending only) and, if the person should not be on site, archive or remove them in the Directory.
- Viewing or deleting somebody's face data from the dashboard. A worker with their own login can delete their own; there is no administrator-side control for one who cannot.
- Approving a location a worker declared from the field. The app lets a worker declare a site they have been sent to; the dashboard has no queue for ratifying those. Create the site properly under Locations.
- Adding a worker from the supervisor's own phone. Field registration happens at the shared staff device, via Register me. There is no Add worker button on the Team screen.
ReferenceGlossary
- Geofence
- The boundary drawn around a site. A check-in inside it counts as being at work. One outside it is measured, recorded and flagged — and may be refused. A fence is either a circle (a pin and a radius) or a polygon (a ring of corners clicked on the map).
- Posting
- The link between a person and a site. It is what lets them check in there, and it is what puts them on that site phone's list of recognisable faces. Ending a posting keeps the history; deleting one is only for a posting added by mistake.
- Casual worker
- Daily or short-term labour, hired on site rather than through the office. Usually registered at the site phone with a name and a phone number, with no email and no password. They have an employee code like anybody else and their hours are recorded the same way.
- Provisional registration
- A worker who was registered in the field and can work immediately, but whose engagement no administrator has ratified yet. They are fully active and fully recognisable; their shifts are flagged "Provisional registration awaiting approval" so a reviewer sees them. The approval decides whether the engagement stands, never whether the hours happened.
- Liveness
- The check that asks a person to blink, nod or turn their head, so the camera can tell a live person from a held-up photograph. The movement is chosen by the server at that moment and can only be used once, so a recording cannot be replayed. It defeats a printed photo; it is not proof against a determined, purpose-built attack.
- Template (face template)
- The list of numbers a phone produces when it measures a face. It is what the system stores and compares. It is not a photograph, no photograph is uploaded or kept, and the numbers cannot be turned back into a picture of the person.
- Kiosk / staff device
- The same thing under two names. A shared Android phone that belongs to a site rather than to a person: nobody signs in on it, it opens straight to the camera, and it clocks workers in and out by face. It is set up either from the phone (Set up this device for staff) or with a pairing code from the dashboard, and taking it back out needs an administrator's password.
- Flagged record
- An attendance record the system has marked for a human to look at — out of bounds, a weak or faked GPS reading, a very late sync, a shift closed automatically, or a provisional worker's shift. Flagging never blocks the hours; it routes them to a reviewer.
- Out of bounds
- A punch taken outside the geofence. The record says which fence was missed and by how far — measured from the edge of the fence, not from its centre.
- Employee code
-
The short identifier on every person, such as
EMP0142. It is allocated automatically when somebody is registered in the field, and it is what an administrator or manager types to sign in on a phone.