ScanRoster
Back to Resources

Attendance

Custom QR attendance that a photo of the code cannot fool.

One printed code per venue, staff checking in on their own phones, and a record every manager can trust: here is how ScanRoster’s QR check-in works, and why each check exists.

Updated 26 September 20264 min readBy the ScanRoster team
A check-in, from wall to recordexample
Venue code on the wallOne printed code per venue, by the staff entrance
  1. Scanned on their own phoneIn the browser, nothing to install
  2. Signed in as SR-2847Staff ID and PIN, or an emailed code
  3. Checked in, 08:58Inside the geofence, clock verifiedRecorded
  4. Attendance recordLive for the manager, ready for payroll

Why a QR code on the wall, not a clock on the wall

A time clock is hardware: something to buy for every venue, mount, keep powered and replace when it breaks. A QR check-in moves the hardware to the device every member of staff already carries. The venue prints one code, puts it where staff come in, and that is the installation.

The obvious objection is that a code can be photographed and scanned from anywhere. That is why the code on its own proves nothing. The code says where; it never says who. Identity comes from the employee signing in on their own phone, and location comes from the phone itself, which is checked against the venue’s geofence at the moment of the scan.

What happens on a scan

  1. The code identifies the venue. Each venue has its own signed code. A code that has been tampered with, revoked or belongs to another company is refused with a plain message rather than a technical error.
  2. The employee signs in. With their ScanRoster staff ID (for example SR-2847) and a PIN or password, or with a one-time code sent to their email. Once signed in on their phone they stay signed in, so the next scan is a single tap.
  3. ScanRoster decides what the scan is. If the person already has an open shift, the scan offers a check-out, even on a day they were not rostered, so nobody is ever stuck unable to close a shift. Otherwise it is a check-in, matched to their rostered shift if there is one.
  4. At check-out, the break is recorded. Staff pick the break they took from a fixed list, from none up to three hours. Worked time is the time between the two scans minus that break.

The checks, and why they flag rather than refuse

Every scan is checked, and a scan that fails a check is recorded and flagged for a manager, not thrown away. Refusing a scan at the door creates a worse problem than it solves: someone who genuinely worked a shift ends up with no record of it, and the argument happens on payday instead of the same afternoon.

Geofence
The phone’s location is compared with the venue’s pin and radius. Inside, outside, or unknown when location is switched off; the distance is kept with the record.
Clock
The server’s clock is the reference, not the phone’s. A device clock that runs ahead is detected and the scan is flagged instead of being trusted.
Roster
A check-in with no rostered shift is allowed, because emergency cover still has to be paid, and it is marked so the manager can confirm it.
Duplicates
A second check-in while a shift is open is refused. A scan retried after a dropped connection is recognised as the same scan, not counted twice.
Breaks
A break longer than the time actually on shift holds the paid total at zero and flags the record, rather than producing negative hours.

When the signal drops

Basements, walk-in fridges and back corridors are where hospitality staff often are when they need to clock in. A scan made without a connection is queued on the phone and sent as soon as it can be, for up to 72 hours. The recorded time is the time of the scan, not the upload, so hours and pay are unaffected; the delay is shown alongside it for audit.

When somebody forgets to check out

A shift left open does not run forever. An hourly sweep closes it at the rostered end time plus the same grace period used for lateness, or after a fixed fallback when there was no roster, and marks it as auto-closed for a manager to confirm. Nobody is paid for sixteen hours because a phone died at the end of service, and nobody loses a shift because they did.

What the manager sees

Check-ins appear on the dashboard as they happen: who is on the floor now, today’s scans in the venue’s own time, and anything that needs a look. Each flagged record says why it was flagged in plain words. From there the hours flow into each employee’s record and into the pay run, and they feed attendance analytics across venues.

Setting it up

Generate the code from the venue’s page, print the poster, and drop the venue’s pin on the map so the geofence has somewhere to measure from. Until the pin is set, scans are still recorded, with location marked as not checked.

See it on your own venue.

Start free with one venue. Print the check-in code, add your team, and the first shift is recorded the same day.