Kiosk mode turns any tablet at your venue into a shared clock-in station. Staff tap their name and they're on. Timesheets are created from those punches and land in your approval queue like any other, tagged with the kiosk that recorded them.
You can run it alongside phone clock-in, or flip one switch so the tablet is the only way to punch.
Links on this page go straight into the app; if you're not signed in you'll be asked to log in first.
Setting up a kiosk
On the tablet itself, go to Settings, Venue, Kiosk and tap Set up Kiosk on this device. Check the name (one is filled in for you) and tap Start Kiosk Mode. You can also go straight to the setup screen.
The kiosk binds to the device it was set up on and stays armed for a year, even if you sign out of Roster on it.
From then on that tablet shows the clock-in screen. Staff clocking off never leave it. Tapping Exit kiosk asks you to confirm, because exiting retires that kiosk: it drops off your Active kiosks list and the tablet has to be set up again. After exiting, the tablet lands on the setup screen, and if someone with manager access is still signed in on it, their Settings are one tap away. So sign out of Roster on the tablet once the kiosk is running, and consider turning off Can view individual pay for admins who arm the kiosk (on their profile under Role & access) so a tablet left on the counter shows no one's pay.
Openers who arrive before a manager can re-arm the tablet themselves if you tick Can set up a kiosk on their profile. It grants nothing else.
Lost the tablet? Open Settings, Venue, Kiosk on any other device and tap Revoke next to it, or Revoke all. A running kiosk checks in every minute, so it drops back to the setup screen within about that long.
A tablet that loses its connection says so and reloads itself when it can; "Out of date - tap to refresh" means a newer version is waiting.
PINs
PINs are off by default - staff tap their name and confirm. Turn Require a PIN on the kiosk on from the Kiosk tab (the same switch also sits under Timesheets settings) if you want each punch tied to a person who proved who they are.
A PIN belongs to the person, not the venue. Someone who works at two of your venues, or for another business using Roster, uses the same PIN everywhere.
Staff set their own, either way:
- On the tablet. The first time they tap their name with PINs turned on, the kiosk asks them to create one, then carries on with the punch. It works for staff who never open the app.
- In the app. Profile, then Kiosk PIN.
You can't see or choose anyone's PIN - that's the point of it. If someone forgets theirs, open their profile on the Team page and hit Reset; they'll set a new one the next time they tap their name.
Clocking in, breaks and clocking off
Staff find their name, tap it, confirm, and get a green confirmation with their name and the time. With PINs turned on they enter their PIN first.
The list opens on Scheduled: everyone rostered today, in shift-start order, so the person about to tap is near the top. The other tabs are On shift, Clocked off and All, each with a count, plus a search box.
Tapping someone already on shift offers Start break (or End break) and End shift:
- Breaks of 20 minutes or less are recorded as paid rest breaks, longer ones as unpaid meal breaks. A break under a minute is ignored.
- A break punched on the kiosk replaces the break on the roster. If nobody punches one, the rostered unpaid break is applied at clock-off, so hours are never overstated.
- A running break ends by itself at End shift.
Someone who ends their shift early by mistake taps their name again: the shift reopens and keeps its original start, as long as it is still within the 2-hour window below.
Staff using their own phone instead go to Clock, which shows the same shift and the same buttons.
Making the kiosk the only way to clock on
The quickest way is the Kiosk-only clocking switch on the Kiosk tab. One tap blocks every way to record hours off the tablet:
- Punching from their own phone
- Punching from a browser
- Typing the hours in by hand afterwards
- Submitting an unscheduled shift themselves
The third one matters more than it looks: a worker who can't punch on their phone can otherwise add the timesheet by hand the next morning from My timesheets, going back 14 days, with none of the kiosk's attribution.
Turning it off puts all four back to normal.
Whatever this is set to, a worker can only ever touch a timesheet you haven't approved yet. Once you approve one it's locked to them, and only a manager can change it.
Or set them one at a time
The same switches live individually on Settings, Venue, Timesheets, along with the rest of the clock rules. Everything here applies to the whole venue and every shift.
| Setting | What it does | Default |
|---|---|---|
| Clock in from their own phone | Off forces punches onto the kiosk | On |
| Clock in from the web | Off blocks clocking in from a browser | On |
| Workers can enter their own hours | Off means forgotten punches go through a manager | On |
| Workers can submit unscheduled shifts | Off means hours for a shift that wasn't rostered go through a manager | On |
| Managers are exempt | Managers keep their own-device access when the rules above are off | On |
| Clocking on early | Limits how early a shift can be started | Up to 2 hours before |
| Submit matching timesheets automatically | Punches close to the roster skip the worker's confirmation (see below) | On, 60 minutes |
| Require a PIN on the kiosk | On asks each person for a PIN before the punch | Off |
Set some but not all of the first four and the Kiosk-only switch shows as off with a note.
Three things worth knowing. Turning off Clock in from their own phone blocks clocking out and breaks as well as in, deliberately: nobody clocks off from the car park. Leave Managers are exempt on; if the tablet dies mid-service it's how somebody still records a shift, which is why the Kiosk-only switch never touches it. And phone versus web is judged from the browser, so a phone on "request desktop site", or an iPad, counts as web: turn both off if you mean "tablet only".
Limiting early starts
Clocking on early has three options: up to 2 hours before the shift (the default), up to a set number of minutes early, or not before the scheduled start at all.
On the kiosk, a punch always has to match a published shift starting within 2 hours either side of now, so a kiosk punch more than 2 hours early has no shift to attach to whatever this is set to. The options only narrow that window, which is also why the minutes option stops at 120. From their own phone, staff start the day's rostered shift from the Clock screen, and the same 2-hour limit applies there, so pick one of the other two options if you want early punches tighter than that.
It only ever blocks early punches. Someone running late is never locked out, and clocking off is never affected.
Staff also can't dodge it by starting an "unscheduled shift" at the same moment, as long as they have a shift rostered later that day. Someone genuinely called in on a day off is unaffected.
What happens to the timesheet afterwards
Every punch creates a timesheet. What differs is whether the worker has to confirm it.
Timesheets that submit themselves
If the punch matches the roster, Roster submits the timesheet on the worker's behalf and it goes straight to your approval queue. Matching means both ends are within the allowed window: clocked on within it of the rostered start, and clocked off within it of the rostered finish. Default is 60 minutes (up to 180), adjustable under Timesheets settings, or switch it off so everything waits for the worker.
Both ends have to match, deliberately: checking only the finish would sign off an early start the worker never saw.
Anything that doesn't match still waits for the worker to confirm: a big variance either end, an unscheduled shift (there is no rostered time to compare against), or a shift the system closed because nobody clocked off.
This has nothing to do with kiosk mode. The rule is the same whether the punch came from a tablet or a phone, because what matters is whether the hours look right, not which device recorded them.
Changing the hours afterwards
A timesheet stays editable until you approve it, auto-submitted or not.
Whether the worker can edit depends on Workers can enter their own hours. On, they can correct the times from My timesheets. Off, they can still confirm what the clock recorded, but corrections come to you. A kiosk-only venue usually wants it off, so the tablet's record is the record.
An edited timesheet is visibly edited. Once anyone changes the times, the row in your queue carries an edited tag and shows what the clock actually recorded ("clock said 5:08pm - 5:27pm") beside it, so you compare before approving. The original punch is never overwritten. The review panel also names the kiosk and who set it up.
When a punch is refused
Most refusals are one of these:
- "Set a PIN" next to a name - they haven't created one yet. Tapping their name walks them through it, then carries on with the punch.
- "Wrong PIN" - after 5 wrong attempts in 5 minutes the kiosk locks that person out of that tablet until the oldest attempt is 5 minutes old.
- "Too early" - the message names the time they can clock in from. Change the rule under Timesheets settings.
- "No shift rostered" - nothing published for them starts within 2 hours either side of now. A draft shift doesn't count, so check the schedule is published. The kiosk offers to start an unscheduled shift instead: they pick what they're doing and the shift is created on the spot (in the kiosk's bound location, if you set one), landing in your timesheet queue like any other. Early-start limits still apply, so this can't be used to clock on before a rostered shift is due. A venue with no roles has nothing to pick, so create your roles first.
- "You're still clocked in at ..." - a person can only hold one open timesheet at a time, including at another venue. They clock out there first.
If none of that explains it, you can add the timesheet yourself from the Timesheets page.
What kiosk mode doesn't do yet
Being straight about the current limits:
- The bound location you pick when setting up a kiosk is shown in the header and becomes the area of any unscheduled shift started there, but it doesn't filter the list. A kitchen tablet still shows the whole venue.
- The name list isn't grouped by area. It's sorted by status and shift start time.
- There's no photo capture on punch.
- Kiosk punches carry no location. Phone punches record one where the phone allows it, and Roster flags punches made away from the venue rather than blocking them.
Related
- Leave requests - time off, approvals and the off-per-day limit
- All FAQs - setup and how the rest of Roster works