People and HR

Attendance and biometric check-in

Attendance tracks working time as check-in/check-out per person per day, from four surfaces that all land in one ledger: the app on a phone or laptop, a wall-mounted biometric terminal, a tablet kiosk at the door, and plain one-tap. Your workspace policy decides which methods count.

MethodHow it verifies
GPSCaptures location on punch; optionally only accepted inside your configured check-in areas (geofence).
Device thumb (passkey)The phone or laptop fingerprint sensor (or Face ID / Windows Hello) signs a challenge. No fingerprint image ever leaves the device or is stored.
Face verificationEnrollment computes a face signature on your device (models served by WorkBOS, no outside service); every punch is matched against it on the server and a wrong or unregistered face is refused, on check-in and check-out. The stamped selfie (date, time, timezone, location burned into the image) is stored as evidence for the policy retention window; enrollment is consent-based and revocable.
Biometric terminalZKTeco-class fingerprint/face/iris/palm devices push punches to WorkBOS over their cloud protocol. Templates stay on the device; WorkBOS stores only the punch.
KioskA tablet at the entrance where each person types their kiosk code. Good for teams without smartphones.
  1. 1

    Set the policy

    Attendance → Policy (admins): choose allowed methods, photo requirement, check-in areas, working shifts (morning, evening, night or custom), lateness grace, photo retention and timezone. A company-specific policy overrides the workspace default.

  2. 2

    Assign shifts

    Attendance → Shifts is the readiness board: every member with their shift, face and thumb status and a Ready badge. People can pick their own shift during setup; an admin-set shift is locked. Lateness is graded against shift start plus grace, with expected hours next to worked hours and break minutes.

  3. 3

    Make enrollment mandatory

    Turn on Require enrollment in the policy and every member must pick a shift and register a face or device thumb before their first punch. A guided wizard walks them through it, new members are nudged when they join, and the server refuses punches until setup is complete.

  4. 4

    Add devices

    Attendance → Devices: register a terminal by its serial, then copy the device key shown once on the next screen and enter it on the device along with the Cloud Server address. Every device needs its own key: without one it cannot send punches, and the list shows "Not set" against any device that still needs one (use Set device key on the device panel). A kiosk works the same way through its one-time link.

  5. 5

    Map people

    Click a device row to map its user IDs (or kiosk codes) to your people. Do this before go-live: unmapped punches are dropped, with the last unknown ID noted on the device row.

  6. 6

    Punch

    People check in from the Attendance page with their allowed method. Hours, breaks and day status roll up automatically and feed Payroll.

Biometric privacy: passkey punches store no biometric data at all; terminal templates never leave the terminal; face photos are evidence with per-workspace retention and one-click enrollment revocation. Every verification decision happens server-side.

Was this page useful?