Attendance & Timesheets
Clocking in and out, running a tablet as a time clock, reviewing the daily time record, and the one correction Kassly cannot make.
12 min read · Updated 10 Sep 2026
On this page
Attendance is a list of punches: somebody clocked in at 8:02, went on break at 12:00, came back at 12:45, clocked out at 17:30. Kassly stores those four moments and adds them up into a daily time record — the DTR — which is what payroll pays from and what you check when the hours look wrong.
Nothing here needs an add-on. The time clock, the kiosk, the timesheet page and the CSV export are all on the Free plan.
Finding it
| Screen | Where | For |
|---|---|---|
| Timesheet | Web, /app/timesheet |
Reviewing everybody's punches, and the CSV export |
| Time Clock | Mobile app, Settings → Time & Attendance | Punching in and out on a shared tablet |
| Time clock kiosk | Mobile app, locked to the punch screen | A dedicated tablet by the door |
| My Timesheet | Mobile app, Settings → My timesheet & leave | A staff member's own record and leave requests |
The four punches
| Punch | Means |
|---|---|
| Time In | The shift starts |
| Break Start | Unpaid break begins |
| Break End | Back on the clock |
| Time Out | The shift ends |
Break time is deducted from paid hours. A person who clocks in at 8, breaks from 12 to 1 and clocks out at 5 is paid for 8 hours, not 9 — unpaid breaks are the norm in Philippine retail and food service, so that is what Kassly assumes. There is no setting to make breaks paid.
An unfinished pair counts for nothing. Hours are added up from Time In to Time Out. A shift with a clock-in and no clock-out contributes zero hours, not "until now" and not "a full shift". A forgotten clock-out is therefore an unpaid shift, and — read the next section carefully — there is no way to go back and add the missing punch.
Punches cannot be corrected
There is no screen, on the web or on the tablet, that can add, edit or delete a punch. Not for an owner, not for anybody. The record is append-only by design: what the clock captured is what stays.
Practically, that means:
- A missed clock-out cannot be filled in. The shift reads as zero hours.
- A wrong time cannot be nudged.
- A duplicate punch cannot be removed.
The only repair available is to have the person punch correctly next time, and to adjust their pay by hand — either by setting the hours-based rate against a different figure, or by adding a manual line on the payslip. See Payroll.
Given that, the practical advice is boring but real: check the timesheet daily rather than at cutoff, while people can still remember what happened.
Three ways to punch
One-tap, on a shared device. In the mobile app, Settings → Time & Attendance → Time Clock ("Clock in or out for your shift") gives the signed-in person a single Clock In / Clock Out button. It confirms with Clocked in or Clocked out, and says Punch failed if it could not be saved.
A staff PIN pad. Where a roster has been downloaded, the same card opens a full-screen time clock instead: enter your 4-digit PIN, choose the punch, take an optional selfie, done. The PIN pad submits by itself once the fourth digit is in.
A dedicated kiosk. A tablet converted to a time clock and locked to that screen. This is the setup for a wall-mounted device by the staff door.
The punch screen greets you by first name and shows where you stand — Not clocked in, On shift, On break, Off shift — then offers only the sensible next actions. The unlikely ones are tucked behind Wrong state?, so somebody who forgot to clock out yesterday can still get themselves in today.
PIN problems are spelled out rather than generic:
| Message | Means |
|---|---|
| "PIN must be 4 digits." | Too short |
| "PIN not recognised. Try again." | No staff member has that PIN |
| "That's not Ana's PIN. Try again." | Right person tapped, wrong PIN |
| "Ana has no PIN set. Ask an admin to set one." | Fix it on the Staff page |
| "PIN data not loaded yet — pull to refresh." | The roster is stale |
| "Staff list not synced yet. Connect to the internet once, then try again." | This device has never been online with this store |
Setting up a kiosk
From the mobile app: Settings → Convert to Time Clock. It is an Owner-only action, and Android only — on an iPad the app says "DTR kiosk mode is only available on Android."
Kassly tells you what you are agreeing to before you commit: "The app will lock to the time-clock screen so staff can punch in and out. You'll need a manager PIN to exit kiosk mode."
| Choice | Options |
|---|---|
| Mode | Tiles — a grid of names, tap yours then enter your PIN. Good for a small team who know each other |
| PIN only — a keypad, no names shown. Better for a bigger or more private team | |
| Require photo on punch | On or off |
Three properties of a kiosk worth knowing:
- It works offline. Punches queue on the device and upload when the connection returns.
- One device is one branch, fixed at the moment you convert it. It cannot be moved to another branch afterwards.
- The lock is not absolute. Kassly says so itself: "Long-press Back+Overview can still escape kiosk mode (Android limitation)."
The kiosk home screen shows a wall clock, "Tap your name to clock in or out", and a pill under each name — On shift · 2h 14m, On break, Off shift, Not yet. A name is greyed out with Sync pending — log in online once or No PIN set when it cannot be used.
To take the device back, tap through to the exit prompt — "Enter a manager PIN to leave kiosk mode and return to login." A wrong PIN gives "Manager PIN not recognised.", and repeated attempts get "Too many attempts. Wait a minute and try again." Only an Owner or Manager assigned to that branch can release it.
There is no kiosk list on the web. Nothing in the web app shows you which devices are enrolled as time clocks, and there is no button there to revoke one. A kiosk is released from the device itself with a manager PIN. If a kiosk tablet is lost, contact support — you cannot cut it off from the web app.
Selfies
When Require photo on punch is on, the kiosk takes a front-camera picture as each punch is made.
- A camera failure never blocks the punch. You can also Skip and punch anyway. The punch is saved and flagged as missing its photo, which shows in the Flags column on the Timesheet page.
- Photos are deleted after 60 days. The punch stays; the picture goes. They are evidence for a dispute this month, not a permanent archive.
- Managers can open a punch's selfie from the Timesheet page.
How verification is recorded
Every punch records how the person was identified:
| Verification | Means |
|---|---|
| PIN | Entered a PIN at a time clock or kiosk. This is the only one that can carry a photo |
| Self-service | The signed-in person tapped their own Clock In button |
| Payfolk Face | A face match from a separate biometric device |
| Payfolk Fingerprint | A fingerprint match from a separate biometric device |
Face and Fingerprint are not features of this app. Kassly does not read a face or a fingerprint on a phone or tablet. Those two values only appear where a separate Payfolk biometric terminal has been installed and is feeding punches in. If you have no such device, you will only ever see PIN and Self-service.
Clock drift and offline punches
The time on a punch comes from the device that made it. Kassly records what the tablet said and does not overwrite it — which is the only way offline punching can work at all, and also the one way attendance can go wrong quietly.
Two safeguards catch it:
- A kiosk reports its clock to Kassly regularly. More than 15 minutes out and every punch from that session is flagged, and the kiosk itself shows a banner: "Clock is 18 min off — notify a manager".
- A punch whose own timestamp is more than 15 minutes away from Kassly's clock is flagged the same way.
Flagged punches appear under Flags on the Timesheet page. They are a warning only: nothing is corrected, and the flagged time is still the time payroll uses. If you see the warning, fix the tablet's clock — the punches already recorded are stuck as they are.
Offline, a device holds up to 200 queued punches before it stops accepting more, which is comfortably more than a day's worth for any branch. Sending the same punch twice is safe: the duplicate is recognised and discarded.
Reviewing the timesheet
MANAGEMENT → Timesheet, at /app/timesheet, is the review screen. It shows
one row per person per day, expandable into the individual punches:
| Column | Notes |
|---|---|
| Date | The business day, so a shift that ends at 3am can belong to the previous trading day |
| Employee | |
| Branch | |
| First in | Earliest Time In that day |
| Last out | Latest Time Out |
| Hours | Worked hours, two decimals |
| Punches | How many punches that day |
| Verification | PIN, Session, Face, Fingerprint |
| Flags | Clock skew, missing photo |
Filters across the top: branch, employee, Today / This week / Pay period / Custom, and verification method. Pay period follows the Philippine semi-monthly convention — the 1st to the 15th, or the 16th to the end of the month, whichever half today falls in.
Download CSV exports what you are looking at, with columns built for a bookkeeper rather than for a developer:
Date, Time, Employee, Branch, Type, Verification, Device,
Photo missing, Clock skew warning
The Date column is the business day; the Time column is the real wall-clock
time, so a 3am punch still reads 03:00 AM.
Two limits on this page:
- Selecting more than one branch breaks the page. Picking two branches, or using Select all, produces "Couldn't load attendance". Filter one branch at a time, or leave the filter empty to see all the branches you have access to.
- Long ranges are truncated. The page loads up to 200 punches at a time and has no page control, so a month across a busy branch will silently show only part of it. Pull shorter ranges, or use the CSV export, which streams everything.
A Manager only sees the branches they are assigned to. An Owner sees them all. A Cashier cannot open the page at all.
What a staff member sees
On the mobile app, Settings → My timesheet & leave shows the person their own record for the last two weeks:
- Clock history — one line per day:
08:02 → 17:30, or No clock-in where they were absent, plus the hours worked as8.00h. - Leave requests — what they have asked for and where each request stands.
They see their own data only, and no pay figures at all — no rate, no gross, no net. Payslips are a separate screen; see Payroll.
Early-morning punches show up on the wrong day in My Timesheet. The day a punch is filed under in this staff-facing view is worked out in UTC rather than Philippine time, so anything before 8:00 AM is listed under the previous day. A 6am opening shift looks as though it happened yesterday. The punches themselves are correct, and the manager's Timesheet page groups them correctly — it is the staff member's own list that reads oddly. Check the Timesheet page when a date is in question.
Leave requests
A staff member files a request from the same screen: Request Leave, a type,
a start date, an end date, and an optional reason. Dates are typed as
YYYY-MM-DD, and the app is strict about it — "Use YYYY-MM-DD for both start
and end." and "End date must be on or after start date."
| Type | Accepted |
|---|---|
| Vacation | Yes |
| Sick | Yes |
| Unpaid | Yes |
| Other | Yes |
| Emergency | No — see below |
The Emergency chip does not work. The tablet offers Emergency as a leave type, but Kassly refuses it when the request is submitted. File an emergency absence as Other and put the reason in the box.
Every request lands in the shared Approvals queue for an owner or manager to approve or reject — see Approvals. A staff member can cancel their own request while it is still Pending, and only while it is pending.
Approved leave does not pay anybody, and does not block anything. It is a record that the absence was authorised. Approved leave creates no hours, no pay and no adjustment on a payslip; it does not stop the person being booked or rostered, and it does not appear on the timesheet. A monthly-rate employee is paid their normal period pay while on leave because monthly pay ignores attendance — not because the leave was approved. An hourly or daily employee on approved paid leave has no punches, so they compute to zero, and you have to add the pay yourself.
Who can do what
| Action | Owner | Manager | Cashier | Staff |
|---|---|---|---|---|
| Punch in and out | Yes | Yes | Yes | Yes |
| See their own timesheet | Yes | Yes | Yes | Yes |
| File a leave request | Yes | Yes | Yes | Yes |
| See everybody's timesheet | Yes | Their branches | No | No |
| Export the CSV | Yes | Their branches | No | No |
| Convert a tablet to a kiosk | Yes | No | No | No |
| Release a kiosk with a manager PIN | Yes | Yes | No | No |
| Approve a leave request | Yes | Yes | No | No |
| Edit or delete a punch | No | No | No | No |
That last row is not a permissions setting — there is no such screen for anybody, at any level. See Users and roles.