Back to Docs

BYOD self-login

Let staff clock in from their own devices with location-based security.

BYOD self-login

Bring Your Own Device (BYOD) lets employees clock in and out from their personal phone or browser, without needing a shared kiosk. Each staff member gets their own account and can only manage their own attendance.

How it works

  • An owner or co-owner enrolls the employee from their profile and sends an email invite
  • The employee accepts the invite, sets a password, and signs in at /app/clock
  • The personal clock page shows only their data: shifts, attendance, and requests
  • Clock actions use the same geofencing and WiFi allowlist as the kiosk

You can run BYOD on its own, or alongside a shared kiosk — pick Personal devices when you set up the location, or turn on personal login later in location settings.

Enrolling staff

Owners and co-owners invite employees from the employee detail page:

  1. Open Employees and select a staff member
  2. Find the Personal device login card and turn the switch on
  3. Enter the employee's personal email and click Invite email
  4. The employee accepts the invite from their inbox and creates their password
  5. They can now sign in at /app/clock from any browser or install ClockTap as a PWA on their phone

The card shows a status badge — Invite pending, Active, or Disabled — so you always know where each employee stands. If the location has no geofence or allowed networks yet, a warning appears on the card; staff can clock in from anywhere until you configure restrictions under Locations → Edit → Restrictions.

Enroll staff, then clock in from a personal device

Turn on Personal device login and send an invite from the employee page, then sign in as that employee at /app/clock to clock in, review shifts, and file requests.

The My Clock page

After signing in, employees land on My Clock (/app/clock):

  • Clock in / out — same start/end time display as the kiosk
  • Today's shift — tap View all for the next seven days
  • Attendance — recent clock-ins for the current week
  • Corrections, Overtime, and Leaves — file and track requests without opening the dashboard

Bookmark /app/clock or add ClockTap to the home screen for one-tap access on a personal device.

Security

Self-login respects the same restrictions configured for your kiosk:

  • Geo-fencing — Clock actions require a location within the configured radius
  • WiFi allowlist — Devices must be on an approved network (by public IP)

When both are turned on, staff must satisfy both to clock in.

What employees can do

Staff with self-login can:

  • Clock in and out from their own device
  • View their attendance history
  • See upcoming shifts
  • File manual entry corrections
  • Submit overtime requests
  • File leave requests
  • Cancel pending requests

They cannot:

  • View other employees' data
  • Approve or reject requests
  • Manage location settings
  • Access the dashboard or reports

Approvers

Approvers get the same self-service surface plus their approval powers. They can:

  • Clock in/out via /app/clock (self-scoped)
  • View their own attendance and shifts
  • Open the Approvals inbox to approve the team's leave and overtime requests

They cannot approve their own requests, and they do not get the rest of the dashboard — attendance, payroll, shifts, and location settings stay owner-only.

Disabling self-login

If an employee loses their device or should no longer have self-login access:

  1. Open their employee page
  2. On the Personal device login card, turn the switch off
  3. Their sessions are revoked and they can no longer access /app/clock

Turn the switch back on to restore access. To clear the email entirely, use the trash button next to it and confirm — a fresh invite is required to re-enroll.