On this page
For owners, HR, branch managers and supervisors. Everything is under
People in the side bar: Staff directory, Attendance, Roster &
shifts, Leave, Performance & tips, Attendance devices, Staff setup,
Time clock and My time & leave. Rosters and trading shifts have their
own manual (roster-and-shifts.md), as do performance and tips
(performance-and-tips.md); what staff see of their own time is in
my-time.md.
Who sees what
| Information | Needs |
|---|---|
| The directory: name, photo, staff and badge numbers, position, department, branches, status, who is in now | employees.view |
| Phone, e-mail, address, date of birth, national ID (last 4), emergency contact, HR notes | employees.personal● |
| Pay basis, rate, currency — and every labour cost on shift reports | employees.pay● |
| Other people’s performance | performance.view● |
| Your own profile, time, leave and figures | always |
What you may not see is not sent to your browser at all (it is not hidden on the page). Saving a form you can only partly see leaves the hidden details as they were. The audit trail records that a sensitive field changed and which one — never the old or new value. A manager limited to one branch sees only the staff of that branch.
The directory and profiles
Staff directory (/staff): search by name, staff number or badge;
filter by branch, position, department and status. Now shows who is in,
on a break, on leave, or has no clock-out from an earlier shift. The
cards at the top: active staff, in right now (a card left open from an
earlier shift is not counted — it is a clock-out to enter), on leave
today, and what needs you (leave to decide, clock-outs to enter). On a
phone, where someone is shows under their name.
A profile has five tabs:
- Profile — work (position, job title, department, branches, type of employment, hired on, weekly rest days, contracted hours, badge number), personal details, pay, and access (login, roles, PIN).
- Time — in now or not, the next shifts, the last 14 days of timecards (lateness and overtime marked).
- Leave — annual and sick balances (and any other type used), the requests; approve or reject from here.
- Performance — the last 30 days, from the orders, payments, tickets and timecards they are named on, with tips owed now.
- History — employment status changes with their reasons, and the profile’s audit trail.
Add staff / Edit: choosing a position fills the job title and department. The badge / device number is the number they are enrolled under on the fingerprint or card clock (unique in the business). A login is optional: staff without one clock in with their number and PIN and appear in attendance only; performance and tips follow the login.
Status changes (active, on leave, suspended, terminated) need an effective date and a reason and are kept as history. Suspended and terminated staff cannot clock in, be rostered or use a PIN. Nobody can change their own status, and someone clocked in must be clocked out before being suspended or archived.
Change PIN sets the 4–8 digit PIN they use on the tills and the time clock.
Login account: linking a login to a profile makes it that person’s own (they see their details, and never decide their own leave or overtime). So it needs both the personal and pay permissions, and nobody but the owner moves their own login.
Staff setup
Staff setup (/staff/setup): positions (name, department, what
they are measured as — waiter, cashier, bartender, barista, kitchen,
manager, delivery, other — and the monthly pay used for labour cost when a
salaried person has no rate of their own), departments, leave
types (entitlement in days a year, carry-over, paid or not; Uganda
defaults: annual 21, sick 30, maternity 60, paternity 4, compassionate 3,
unpaid) and the rules in force (grace, overtime threshold, weekly
hours, paid breaks, missing clock-out after, minimum rest).
The time clock
Time clock (/clock) runs on an approved till — a locked till
too, so staff clock in without unlocking the POS. Staff type their
badge number or staff number (on the keypad, the digits of the staff
number do: 2 for EMP-0002), then their PIN; their photo, where
they are (in, on a break, out) and today’s shift appear, with the buttons
that make sense: Clock in, Start break, End break, Clock out. The
card clears itself after a few seconds.
A wrong number, a wrong PIN — or a PIN that is locked, not set, or a person suspended — all give the same message, and all count against the till: too many attempts lock the till’s clock for a few minutes (the clock never tells anyone who works there). A PIN locks after repeated mistakes; a manager sees it on the profile and can set a new one.
Only at the venue. The clock runs on approved tills; to be sure a
punch was taken on the premises, name the venue’s internet address or
range under the rule Clocking in only from the networks
(attendance.clock_networks): the time clock and My time then refuse
punches from anywhere else.
No connection? An offline-enabled till still records the punch — number and kind, with the till’s time — and sends it when the connection is back. The PIN cannot be checked offline, so the punch shows as unverified in the attendance exceptions for a manager to look at (every offline punch is listed there — its time is the till’s clock). A punch dated further back than the till’s offline window (72 hours) is refused when it arrives.
Attendance
Attendance (/staff/attendance, attendance.view) for one branch:
- Today — the roster against the clock: who is due, in, on a break, late, done, absent or on leave; someone still clocked in from an earlier shift shows No clock-out with Enter clock-out. Below, anyone in without a rostered shift (office staff, cover).
- Timesheets — per person for a period: days, hours worked (finished timecards only) against rostered, breaks, lateness, overtime approved / waiting / rejected, absences, corrections. CSV exports the period.
- Exceptions — missing clock-outs (open longer than the rule Flag a missing clock-out after, 16 hours unless changed), overtime waiting, punches to look at (refused as out of order from a device or offline, and offline punches without a PIN check), absences in the last 7 days, and numbers a device sent that match nobody.
Corrections (attendance.manage): Timecard opens a day: set the
clock-in, clock-out and breaks and give a reason. The original punches are
kept (voided, with who and why); yours are recorded as the manager’s. For
a forgotten clock-out the end of their shift is suggested. Enter a
punch records a missed clock-in or clock-out for someone, with a reason.
Lateness and early leave count after the grace (5 minutes).
Overtime is the time worked beyond the rostered end — or beyond 8
hours when not rostered — and waits for approval: someone with
attendance.manage who is not the employee approves or rejects it (with
a note). Only approved overtime is payable. Breaks are unpaid unless the
business sets a paid allowance.
Leave
Leave (/staff/leave, leave.view):
- Requests — waiting for a decision (approve or reject with a note to them; you cannot decide your own, or one you recorded for someone), and those decided in the last 60 days (an approved request can still be cancelled).
- Calendar — who is off each day of the month (pending requests pale, half days half height) and how many are off.
- Balances — per person and type: entitlement, adjustments, taken,
waiting, left. Adjust (
leave.manage●) adds or removes days with a reason (carry-over, pro-rating, corrections).
Days are working days on the person’s pattern (their rest days are skipped); a half day counts 0.5. Requests that overlap are refused, and so is more than the balance. Approved leave shows as on leave (not absent) in attendance and stops the roster from putting them on a shift. Record leave files a request on someone’s behalf (a sick call, say) — another manager then decides it. Staff ask for their own leave on My time & leave.
Attendance devices
Attendance devices (/staff/devices, attendance.devices●): register
a fingerprint, face or card clock (branch, vendor, model, serial
number, protocol, the device clock’s time zone). ZKTeco and compatible
clocks use ADMS push: on the device, Comm → Cloud server, enter this
server’s address with HTTPS on. Anything else posts JSON with the token
shown once at registration (rotate it if it leaks). The page shows when
each device was last heard from, its punches of the last seven days,
the latest lines received and numbers that match nobody — give the
number to a staff member (Map) and their waiting punches are applied in
order. Disable a device that is lost or replaced. Accepted only from
limits a device to the venue’s internet address or range — do it for
ADMS devices, which identify themselves by serial number alone.
Fingerprints and faces never leave the device: JupitaPOS keeps only the number each person is enrolled under — their badge number.