M masamenu.tr
🍽️ Hall, Kitchen & Back Office

🕒 Clock-in and Clock-out

Venue terminal (tablet / QR on a monitor), geofence and auto clock-out of forgotten shifts

Documentation

Clock-in and clock-out

Employees clock in and out themselves — and those marks immediately become the fact in the timesheet (the Plan vs fact tab of the Staff section) that payroll is computed from. The server always sets the time: it cannot be tampered with from a device.

Open: Admin panel → Staff → My cabinet (employee) and Staff → ⚙ Schedule and clock-in settings (owner; managers see them read-only).


What ends up in the timesheet#

A shift in the timesheet is a plan (if it was on the schedule) plus the fact: clock-in, clock-out and breaks. Every fact has a source:

Source How the fact appeared
The employee “I’m in” / “I’m out” in the personal cabinet — from a phone or a shared computer
Venue terminal PIN on the tablet terminal or a QR code from the venue monitor (see below)
POS A colleague marked from the shared POS terminal by their PIN, or a manager did
Device presence Auto timesheet: a waiter logged in on a tablet is on shift (per-location option)
Manual The owner or a manager edited the time in plan vs fact

A manual edit always wins over automation: after it no automation touches the shift.

If the employee arrives without a scheduled shift, the clock-in creates an unscheduled shift — visible in plan vs fact with its own marker.


Clock-in from the employee’s phone#

In My cabinet, the “Today” block shows the status (“Not on shift” / “On shift since 09:02”) and buttons:

  • I’m in — opens the shift: if there is a scheduled shift today the fact attaches to it, otherwise an unscheduled shift is created;
  • Break / Back — actual breaks inside the shift; a break left open is closed with the clock-out time;
  • I’m out — closes the open shift (including a night shift started yesterday).

Forgot to clock? The cabinet has “Forgot to clock” — a timesheet correction request confirmed by a manager.


Where clock-in is allowed: geofence or venue terminal#

The “Clock-in gate” setting in “Schedule and clock-in settings” decides whether clock-ins are accepted from anywhere:

Mode Behaviour
Off Accepted from anywhere, no checks
Warn (default) The browser sends its position; a clock-in farther than 300 m from the venue goes through but is flagged “outside location” — managers see the flag in plan vs fact
Strict A clock-in beyond the configured radius is refused with a message like “you are 800 m away, 300 m allowed”. No position (browser permission denied) — refused too. Clocking a colleague in by PIN from the POS is refused as well: a PIN proves who is clocking in, not where; bind the POS as a terminal (below) or allow it geolocation
Only from a venue terminal Accepted only with proof from a bound device — a tablet, phone or monitor that physically stays at the venue. Position is not requested

The geofence compares the browser position with the coordinates of the shift’s location (set in the location card). If the location has no coordinates, there is nothing to check and the clock-in passes.

The gate does not have to be the same everywhere. The “Per-venue and per-role overrides” block below sets the mode, the radius and auto clock-out separately for a given location and for a given role:

  1. Press “+ Add override”, choose “Venue” or “Role”, then pick which one (venues come from your locations, roles from those your employees actually hold).
  2. Fill in only what must differ. Anything left as “as for the account” keeps coming from the settings above — that is not “off”.
  3. Save: the block saves itself, independently of the panel’s “Save” button.

Which rule wins when several apply: employee role → shift venue → account, field by field. So “strict, 80 m at the downtown venue” together with “gate off for couriers” means a waiter of that venue clocks in within 80 m while a courier clocks in from anywhere — the role outranks the venue rule.

When you need a terminal. Browser geolocation is soft evidence: it can be spoofed, and in dense areas the error exceeds the radius. A terminal is as hard as its mode: the tablet with a PIN pad requires standing at the tablet; the QR on a monitor is single-use and lives for two minutes — a screenshot forwarded to a colleague works once and only until it expires, so “clock in the whole shift with one photo” is off the table, but a single collusion per scan is not ruled out. If you need strictness, use a tablet, not a monitor.


Venue terminal: binding a tablet or monitor#

A terminal is any tablet, phone or computer with a browser that stays at the venue. One account can bind several terminals (one or two per location).

  1. Open Admin panel → Staff → ⚙ Schedule and clock-in settings on the device itself. Sign in as the owner, a manager or with a device code.
  2. In the “Clock-in terminals” block press “Bind this device”, name it (“Tablet at the entrance”) and optionally pick a location.
  3. The device receives its secret and keeps it in the browser — it is never sent again or shown. The “This device is terminal …” note and the “Open terminal screen” button appear right away.
  4. Switch the clock-in gate to “Only from a venue terminal” and save.
  5. Open the terminal screen (/clock-terminal) and leave it on: the screen keeps itself awake, and the mode (tablet or monitor) is remembered in the address.

A terminal with a location accepts clock-ins only for shifts at that location: a shift elsewhere is refused with “today’s shift is at another location”. An unscheduled shift started from a location’s terminal gets that location automatically.

Revoke a terminal from the same list: a device with the old secret is refused at its next clock-in. If the browser’s site data is cleared, the secret is gone — just bind the device again.

Under every terminal in the list you can see when it was last used (“5 min ago”, “3 h ago”) or “not used yet”. If a terminal has been silent for more than a day, its row is highlighted with a warning — check that the tablet is on, online and showing the terminal screen.


Tablet mode: PIN pad#

The terminal screen shows four large buttons — I’m in, I’m out, Break, Back from break. The employee taps one and enters their cashier PIN (4–6 digits, issued in the employee card). No list to search and no login switching: the PIN is unique within the account, so the server knows who clocked in — the screen shows “Anna: clocked in at 09:02” for a few seconds.

A wrong PIN gets a neutral “Wrong PIN” with a delay, and after ten failures within a quarter of an hour the terminal (or the employee entering a PIN from a phone) is locked for 15 minutes — guessing other people’s PINs is pointless. All errors are spelled out: “already clocked in”, “not on break”, “this month is closed”, “an open shift from 17 September is still running”.


Monitor mode: QR on screen#

The terminal shows a large QR code that changes every 30 seconds. The employee scans it with their own phone camera — their personal cabinet opens with a green “Venue terminal confirmed” note and the usual “I’m in” / “I’m out” buttons. No position is requested: the code from the screen already proves the person is standing in front of the monitor.

The code stays valid for about two minutes after it is shown; too late — the note changes to “The QR code has expired — scan it again”. One scan is good for one clock action.

Every QR is single-use. The monitor fetches a fresh one from the server every 30 seconds, and after the first clock action the code is burnt on the server: a forwarded screenshot works once — for whoever opens it first — and only until it expires; the second person sees “terminal not confirmed — scan again”. If the monitor loses its network, it falls back to the old-style code (valid for the same two minutes, but not single-use) so the screen at the entrance never goes blank.

This mode fits any screen without touch — a TV at the entrance, a monitor at the bar — and requires nothing from the employee beyond the phone they already use for the cabinet. Hours do not go to whoever photographed the screen: the code is single-use and lives two minutes, and the clock action comes from the employee’s personal login.


Ways to register leaving with minimal effort#

Clock-out is forgotten more often than clock-in: people are tired and leave. Meni offers several ways to close a shift, and they combine — from the cheapest to the most precise:

Method What it needs Precision When to enable
Auto clock-out by schedule Nothing: an account setting Scheduled end of the shift Always, as a safety net when a schedule is kept
Auto clock-out by cap Same setting Clock-in + N hours For unscheduled shifts, so they do not hang for weeks
“I’m out” from the phone Personal login To the minute Default for everyone
PIN on the terminal A tablet at the exit To the minute When leaving must be marked on site
QR from the monitor Any screen To the minute When there is no tablet but everyone has a phone
A colleague marks from POS POS terminal To the minute Cashier leaving together with closing the cash shift
Device presence Waiter tablets on the venue Wi-Fi, per-location option Last tablet signal Fully automatic timesheet for a hall with tablets
“Forgot to clock” correction Employee request, manager decision As stated by the employee Always available as the last resort

Deliberately not done: background phone geolocation (browsers do not offer it, and an app tracking employees after the shift is a privacy question) and biometrics (dedicated hardware and stricter personal-data rules).


Auto clock-out of forgotten shifts#

The “Auto clock-out for forgotten shifts” block in “Schedule and clock-in settings”:

  • Close open shifts automatically — the switch, off by default;
  • Wait after the scheduled end, minutes — the grace period (default 30): if no clock-out arrives within it, the shift is closed at the scheduled end, not at the current time — the automation never invents hours beyond the schedule;
  • Cap for unscheduled shifts, hours — for shifts without a plan or started after the scheduled end: close N hours after clock-in (default 12; 0 — leave them alone, they stay in the plan-vs-fact list of open shifts).

Auto clock-out is overridable too: in the “Per-venue and per-role overrides” block a venue or a role can get its own grace and cap (a courier — 8 hours instead of 12), or auto clock-out can be enabled at one venue only while staying off everywhere else.

The check runs every 30 minutes. An auto-closed shift carries the “⏱ auto-closed · awaiting confirmation” badge in the timesheet (with a hint — by schedule or by cap), and the employee gets a work-chat notice: “No clock-out recorded — your shift was closed automatically at 18:00 per the schedule. Confirm the time in “My hours”; if you left at a different time, request a correction.” A manual edit removes the badge. Closed months and presence-based shifts are never touched.

The inferred time is an assumption, not a clock action, so a person has to confirm it:

  • the employee sees two buttons on such a shift in “My hours”: “Correct” — the time is confirmed as is, and “Set clock-out” — a window opens with the inferred time where they enter the real one; a regular correction request goes to the manager and the hours change after approval;
  • the manager, when closing the period, sees the exception “Auto-closed shift awaiting confirmation” and reviews it with “Confirm as is” — the period cannot be closed while it is open;
  • in the payroll draft the employee’s line with such shifts carries a ⏱ n badge — the amount is computed from the inferred hours as is, the badge only reminds that the hours are assumed.

After confirmation the badge becomes “⏱ auto-closed · confirmed” (the hint says by whom). For the floor and delivery the shift is closed from the moment of auto clock-out — confirmation concerns only the timesheet and payroll.


Sources of the fact and payroll#

Payroll is computed from timesheet hours, so every fact stores where it came from, and plan vs fact shows it with badges: “📡 auto” for presence, “⏱ auto-closed” for auto clock-out, the “outside location” flag for a distant clock-in. The terminal that confirmed a clock action is recorded in the shift too. Managers see all of it in Plan vs fact, employees in My hours, and both can start a correction until the month is closed.

Every shift with a fact has a 🕘 “Clock-in history” icon in Plan vs fact: the full list of attempts for that shift — time, action (in / out / break), who pressed it (the employee, a manager by name or the automation), from where (phone, POS, terminal by name, auto clock-out) and the result — recorded, or denied with the reason (wrong PIN, “terminal only”, outside the location). Denials are kept too: a run of wrong PINs from one tablet is visible at once.

A clock-in is not lost when the connection drops: if the phone did not get the server’s reply, the app repeats the same request by itself, and the server recognises the repeat and does not record a second clock-in — you see the same shift, not an “already clocked in” error.


FAQ#

Can an employee without a login clock in?#

On the terminal — yes: the tablet accepts the PIN of any employee who has one; no login is needed. From a phone or by QR — no: there the clock action comes from the personal login.

What if the terminal breaks or is taken away?#

Revoke it in the terminal list and temporarily switch the gate to “Strict” or “Warn” — employees clock in from their phones. Forgotten shifts are closed by auto clock-out.

Can the terminal be required for one location only?#

Yes. In “Schedule and clock-in settings” open the “Per-venue and per-role overrides” block → “+ Add override” → “Venue” → pick the location and set its gate to “Only from a venue terminal”. The account-wide setting stays as it was (“Warn”, say), and locations without a terminal keep working as before.

The same way you can lift the gate where it gets in the way: an override for the “Courier” role set to “Off” lets couriers clock in from anywhere even when the whole account is on “Strict”. The role outranks the venue, the venue outranks the account.

Nothing happened: the scan only proves presence, the button makes the clock action. After two minutes the code expires and must be scanned again.

Will auto clock-out inflate hours?#

It never invents hours beyond the schedule: by schedule the shift closes at the scheduled end even if the check ran later, and by cap exactly the configured number of hours after clock-in. But it does not know when the person actually left: someone who left early is credited until the scheduled end, someone who stayed late only until it. That is why the inferred time is not a fact but awaits confirmation: the shift is marked “⏱ auto-closed · awaiting confirmation”, the employee is notified and, in “My hours”, either presses “Correct” or “Set clock-out” and enters the real time (a correction request goes to the manager, who approves it). Until the shift is confirmed, its line in the payroll draft is flagged and the period cannot be closed — the manager reviews such shifts with “Confirm as is”. If the manager then reopens the shift (removes a wrong clock-out), the automation leaves it alone.

I forgot to clock out yesterday — today “I’m in” does not work#

An employee can have only one open shift. The cabinet and the terminal tell you which one is still running (“an open shift from 17 September”): press “I’m out” — it closes at the current time — then clock in and request a correction for yesterday’s clock-out. Enable auto clock-out so it does not happen again.


Was this article helpful?