User Guide

Kiosk clock-in

Dedicated tablet PWA for shared clock-in stations — front desk, warehouse, job site.

The kiosk PWA is a separate installable app pinned to a single physical tablet. Employees walk up, tap their name + 4-6 digit PIN, and clock in or out. A single tablet can host multiple kiosk PWAs (one per location) — each with its own home-screen icon and its own scope.

When to use kiosk vs web / mobile

🏢

Office kiosk

Fixed tablet at the front desk. Employees clock in with a PIN + first-of-day identity selfie. Best for time-and- attendance in professional-services offices.
🔧

Field-service kiosk

Portable tablet carried to customer sites. Tech clocks in on arrival, snaps job photos at clock-out. Kiosk-only users auto-submit their week on each clock-out — no weekly grid ceremony.
💻

Web / mobile

Individual login credentials. For salaried employees + consultants + admins who need the full app surface (invoice gen, reports, approvals). Kiosk supplements this, doesn't replace it.

Register a kiosk

Settings → Kiosks → Register. Fill in a display name ("Front Lobby") + optional location. Server returns a one-time device token shown ONCE in the create dialog — copy it before you dismiss. Admin then walks over to the tablet, opens the kiosk URL in a browser, pastes the token, and taps Install as app in the top bar to add the PWA to the home screen.

Tip
Settings → Kiosks has an Install app button on every row that opens the kiosk URL in a new tab, cutting the physical-install workflow from 5 steps to 2. Send the setup URL + QR by email to whoever's at the tablet — no admin login needed on the tablet itself.

Identity + proof-of-work capture

Kiosks capture identity + work proof orthogonally. Selfies answer who; job photos answer what. The capture cadence depends on the kiosk's location context and the user's proof-of-work policy.

  • ✓Office kiosk + selfie required — first-of-day identity capture at clock-in (Alice's next 4 clock-ins today skip the selfie)
  • ✓Field kiosk + require_proof_of_work=true — job photos at clock-out (per site visit); selfie skipped
  • ✓Kiosk-only users on field context — job photos are HARD-required (no skip button)
  • ✓Kiosk-preferred / any users — job photos are SOFT (entry flagged proof_of_work_pending, admin follows up)

Recovery PIN — for stuck tablets

If a tablet's storage gets wiped (browser upgrade, IT policy reset, factory restore), the device token is gone and the shell drops to the provisioning screen. Without a recovery mechanism, admin would need to physically visit the tablet + paste a fresh token. The recovery PIN closes this gap: admin sets a 4-8 digit PIN per kiosk at registration (Settings → Kiosks → Set PIN); the on-site tech taps "Lost your token? Recover with PIN" on the provisioning screen, enters the PIN, and the server issues a fresh device token — no admin round-trip.

  • ✓Bcrypt-hashed on the server (nobody can read the PIN back)
  • ✓Rate-limited: 5 failed attempts per rolling 1-hour window per device
  • ✓Every attempt (success, fail, lockout) written to the audit log
  • ✓Rotate the PIN independently of the device token whenever needed

Session-integrity guards

🕐

16-hour max session

If a tech forgets to clock out, the server rejects the eventual clock-out with a friendly "ask admin to close manually" error rather than landing a 24h+ session that pollutes daily totals.
🔒

Cross-device concurrency

Only one active clock-in per user at a time across ALL kiosks + web / mobile. Attempting to clock in on kiosk B while a session is open on kiosk A returns a named rejection: "You already have an active session on Front Lobby (open 6h)."
🪟

Single window per kiosk

Web Locks API prevents two browser windows from running the same kiosk shell simultaneously — the second window shows an amber "This kiosk is already open" guard. Avoids the concurrent-clock-in race entirely.

Rotate the device token

Suspected leak? Employee offboarded? Scheduled rotation? Settings → Kiosks → Rotate token issues a fresh token without changing the device ID — historical time entries, installed PWA scope, and previously-emailed setup URLs all keep working. Only the token itself changes. The next launch on the tablet drops to provisioning; paste the new token and continue.

Kiosk-only enforcement

Set a user's clockInSource to kiosk_only on Edit User → Access & Time Entry. From that point on the server rejects any web / mobile / timer clock-in attempts from that user — the ONLY legal path is a physical tap on a kiosk. Combined with field-context job photos, this is the auditable per-session proof pattern used by staffing agencies and field-service firms.

Note
Kiosk-only users auto-submit their week on each clock-out. Each clock-in/out cycle IS the whole submission unit — they never see the weekly grid. Reviewers see one submitted entry per session in the approval inbox.

Version pill + support

The kiosk top bar shows a small version pill (v0.1.27 etc.) baked in at build time. Support can ask "what version is this kiosk running?" without needing DevTools. The version pill also lets admin confirm a rollout succeeded at a specific tablet after a Deploy Live workflow.

What kiosks are NOT for
Kiosks are shared clock-in stations, not full-app replacements. Admin surfaces (invoice generation, reports, Settings, contract authoring) always live on desktop web / mobile with the user's normal login credentials. A kiosk device token doesn't grant admin access to anything — it only authenticates a specific tablet to capture clock-in/out on behalf of any employee with a PIN.