Kiosk mode turns any tablet at your venue into a shared clock-in station. Staff tap their name and they're on. Timesheets are created from those punches and land in your approval queue like any other.
You can run it alongside phone clock-in, or flip one switch so the tablet is the only way to punch.
Links on this page go straight into the app. If you're not signed in, you'll be asked to log in first and then land on the right screen.
Setting up a kiosk
Open Roster on the tablet you want to use, go to Settings, Venue, Kiosk and tap Set up Kiosk on this device. Give it a name, like "Front counter iPad", and tap Start Kiosk Mode. You can also go straight to the setup screen.
Do this on the tablet itself rather than your laptop. The kiosk binds to the device it was set up on.
From then on that tablet shows the clock-in screen and nothing else. It stays that way until someone taps Exit kiosk and signs back in as a manager, so a device left on the counter can't be used to browse your rosters or wages.
Lost the tablet? Open Settings, Venue, Kiosk on any other device and revoke it. The kiosk is signed out the next time it loads.
PINs
PINs are off by default - staff tap their name and confirm. Turn Require a PIN on the kiosk on from Settings, Venue, Timesheets if you want each punch tied to a person who proved who they are.
A PIN belongs to the person, not the venue. Someone who works at two of your venues, or for another business using Roster, uses the same PIN everywhere.
Staff set their own, either way:
- On the tablet. The first time they tap their name with PINs turned on, the kiosk asks them to create one. Nothing to set up in advance, and it works for staff who never open the app.
- In the app. Profile, then Kiosk PIN.
You can't see or choose anyone's PIN - that's the point of it. If someone forgets theirs, open their profile on the Team page and hit Reset; they'll set a new one the next time they tap their name.
Clocking in
Staff find their name, tap it, confirm, and get a green confirmation with their name and the time. With PINs turned on they enter their PIN first.
The list orders itself so the person about to tap is near the top:
- Anyone already clocked in, so clocking out is quick
- People scheduled today, in order of shift start time
- Everyone else, alphabetically
There's a search box and All / On shift / Scheduled today filters as well, which matter once a venue is past a screenful of names.
Clocking out is the same flow. Tapping the name of someone already on shift offers Clock out instead.
Staff using their own phone instead go to Clock, which shows the same shift and the same buttons.
Making the kiosk the only way to clock on
The quickest way is the Kiosk-only clocking switch on the Kiosk tab. One tap blocks all three ways to record hours off the tablet:
- Punching from their own phone
- Punching from a browser
- Typing the hours in by hand afterwards
That third one matters more than it looks. Blocking the two punch surfaces locks the front door and leaves the back one open: a worker who can't punch on their phone just adds the timesheet by hand the next morning, from My timesheets, going back 14 days. You get the same paid minutes with none of the kiosk's attribution.
Turning it off puts all three back to normal.
Whatever this is set to, a worker can only ever touch a timesheet you haven't approved yet. Once you approve one it's locked to them, and only a manager can change it.
Or set them one at a time
The same three switches live individually on Settings, Venue, Timesheets, along with the rest of the clock rules. Everything here applies to the whole venue and every shift.
| Setting | What it does | Default |
|---|---|---|
| Clock in from their own phone | Off forces punches onto the kiosk | On |
| Clock in from the web | Off blocks clocking in from a browser | On |
| Workers can enter their own hours | Off means forgotten punches go through a manager | On |
| Managers are exempt | Managers keep their own-device access when the rules above are off | On |
| Clocking on early | Limits how early a shift can be started | Up to 2 hours before |
| Require a PIN on the kiosk | On asks each person for a PIN before the punch | Off |
Set some but not all of the first three and the Kiosk-only switch shows as off with a note, rather than pretending a half-measure is the full thing.
Nothing changes for your venue until you change it. Every setting starts where the product already behaved.
Two things worth knowing. Turning off Clock in from their own phone blocks clocking out as well as in, which is deliberate: it stops someone leaving early and clocking off from the car park. And leave Managers are exempt on, because if the tablet dies mid-service it's the reason somebody can still record a shift. It's deliberately not part of the Kiosk-only switch, so one tap can never lock out the only people who can fix a lockout.
Limiting early starts
Clocking on early has three options: up to 2 hours before the shift (the default), up to a set number of minutes early, or not before the scheduled start at all.
Two hours is the ceiling in every case, including the default. Clocking on works by matching you to a published shift starting within 2 hours either side of now, so a punch more than 2 hours early has no shift to attach to. These options only narrow that window, they can't widen it - which is also why the minutes option stops at 120.
It only ever blocks early punches. Someone running late is never locked out, and clocking off is never affected.
Staff also can't dodge it by starting an "unscheduled shift" at the same moment, as long as they have a shift rostered later that day. Someone genuinely called in on a day off is unaffected.
What happens to the timesheet afterwards
Every punch creates a timesheet. What differs is whether the worker has to confirm it.
Timesheets that submit themselves
If the punch matches the roster, Roster submits the timesheet on the worker's behalf and it goes straight to your approval queue. Matching means both ends are within the allowed window: clocked on within it of the rostered start, and clocked off within it of the rostered finish. Default is 60 minutes, adjustable under Timesheets settings, or switch it off so everything waits for the worker.
Both ends have to match, deliberately. If only the finish were checked, someone who started an hour early and left on time would have the extra hour signed off in their name without ever seeing it.
Anything that doesn't match still waits for the worker to confirm: a big variance either end, an unscheduled shift (there is no rostered time to compare against), or a shift the system closed because nobody clocked off.
This has nothing to do with kiosk mode. The rule is the same whether the punch came from a tablet or a phone, because what matters is whether the hours look right, not which device recorded them.
Changing the hours afterwards
A timesheet stays editable until you approve it, auto-submitted or not.
Whether the worker can edit depends on Workers can enter their own hours. On, they can correct the times from My timesheets. Off, they can still confirm what the clock recorded, but corrections come to you. A kiosk-only venue usually wants it off, so the tablet's record is the record.
An edited timesheet is visibly edited. Once a worker changes the times, the row in your queue carries an edited tag. So an auto-submitted kiosk punch that was later adjusted is distinguishable from one nobody touched.
One limit worth knowing: the tag tells you the times were changed, but not what they were before. The original punch is kept - clock events are never overwritten - it just isn't shown on the timesheet yet. If the number looks wrong, ask before approving.
When a punch is refused
Most refusals are one of these:
- "Set a PIN" next to a name - they haven't created one yet. Tapping their name walks them through it, then carries on with the punch.
- "Wrong PIN" - after 5 wrong attempts in 5 minutes the kiosk locks that person out for a few minutes.
- "Too early" - the message names the time they can clock in from. Change the rule under Timesheets settings.
- "No published shift starting nearby" - the kiosk looks for a published shift starting within 2 hours either side of now. A draft shift doesn't count, so check the schedule is published. If nobody rostered them, the kiosk offers to start an unscheduled shift instead: they pick what they're doing and the shift is created on the spot, landing in your timesheet queue like any other. Early-start limits still apply, so this can't be used to clock on before a rostered shift is due.
- Already clocked in somewhere - a person can only hold one open timesheet at a time, including at another venue.
If none of that explains it, you can add the timesheet yourself from the Timesheets page.
What kiosk mode doesn't do yet
Being straight about the current limits:
- The bound location you can pick when setting up a kiosk is stored and shown in the header, but it doesn't filter the list. A kitchen tablet still shows the whole venue.
- The name list isn't grouped by area. It's sorted by status and shift start time.
- There's no photo capture on punch.