Welcome back

Review and approve employee timesheets

Pay period
0
Needs review
0
Pending
0
Approved
0 of 0 submitted

Timesheet Entries

Employee
Pay period
Hours
Validation (T·I·S)
Quality
Status
Xero
Review
Showing 0 of 0 entries
Employee
Wing
ID
Clock-in
Hours
Leave balance
Xero
Status
Report period
Loading…
Filter by wing:
Total rosters
Drafts
Published
Avg coverage
Templates
Earliest start
Latest end
Avg duration

All shift templates

Organisation

Facility identity and locale (managed via tenant provisioning)

Organisation name
Shown in the manager header, reports and the Xero payroll header
Managed
Facility name
Sub-name shown in the employee clock-in app
Managed
Timezone
All timestamps, pay periods and reports use this timezone
Managed
Locale
Date format, currency symbol and number separators
Managed
Base domain
Set at deployment time (CDK)
Fixed
Vanity subdomain
Your branded host for the back-office app — provisioned during tenant onboarding
Managed

Pay period

Cycle length, start day and calendar anchor (org-admin only)

Cycle length
How long each pay period runs
Managed
Start day
Pay periods begin on this day of the week
Managed
Calendar anchor date
All periods are calculated from this epoch — must align with the Xero payroll calendar
Fixed
Approval reminder threshold
Approval reminders are sent this many days after the period ends
Managed

Timesheet rules

Hour thresholds that trigger warnings and flags during timesheet review

Long-shift warning
Flags any single shift longer than this as a warning
h
Max shift (excessive)
A shift exceeding this triggers a red "excessive hours" flag requiring review
h
High weekly hours
Weekly total above this generates an amber compliance note
h
Excessive weekly hours
Weekly total above this escalates to a red flag and blocks Xero sync
h
Default break deduction
Auto-deducted from any shift of 5 hours or longer when the roster has no break (NZ meal-break default)
30 min Fixed

Security & fraud prevention

Multi-layer clock-in validation — each tier adds an additional verification check

Security tier
BASIC
  • Facial recognition
  • Identity verification
Fraud prevention: ~60%
MEDIUM
  • Facial recognition
  • Identity verification
  • GPS geo-fence
Fraud prevention: ~85%
HIGH
  • Facial recognition
  • Identity verification
  • GPS geo-fence
  • Bluetooth beacon
Fraud prevention: ~95%
GPS geo-fence
Enable GPS validation
Require clock-ins from within the facility geo-fence (used by the MEDIUM and HIGH tiers)
Allowed networks
Facility IP ranges (CIDR)
Clock-ins from outside these networks trigger a Wi-Fi security flag
Bluetooth beacon
Enable beacon validation
Require the facility Bluetooth beacon to be detected on clock-in (recommended for HIGH tier)
Identity verification
Face-match confidence threshold
Minimum Rekognition confidence to pass identity verification. 80% is liberal; 95% is strict.
%

Facial recognition

AWS Rekognition configuration and quality settings

Face-match confidence threshold
The same value as Security & fraud — edit it there
% Set in Security
Re-enrolment temp window
Staged photos sit in temp storage for this long before being committed or deleted
48 hours Fixed
Recognition collections
Each organisation uses isolated Rekognition collections — no cross-tenant face matching
Per-organisation (isolated) Managed
Quality scoring system
3-dot validation (Timesheet · Identity · Security) applied to every clock-in
3-dot system Managed

Manager PIN

The global PIN that unlocks the enrolment area on the employee kiosk. Rotate it whenever a manager leaves.

Current PIN
Checking status…
Set a new PIN
New PIN
6–12 digits. Employees never see this — it only gates the kiosk enrolment area.
Kiosk lockout
Reset lockout
Clears a kiosk locked out by too many wrong PIN attempts

Leave types

Which leave types are available and whether they are paid

TypePaidAvailability
Alternative Holiday accrual: 7.5 h per public holiday worked (Holidays Act 2003, s56–s60). Fixed by statute — not editable here.

Xero & payroll

Connection status, time-rounding, and leave mapping

Xero
Connected — payroll sync is active
Connected
Xero
Authorisation expired — reconnect to resume payroll sync
Expired
Xero
Not connected Connect your Xero organisation to sync timesheets, leave, and pay runs
Xero
Xero Couldn't reach Xero — retry, or disconnect and reconnect
Can't reach
Payroll calendar
Xero payroll calendar ID synced from your Xero organisation
Managed
Time-rounding mode
How clock-in/out times are converted to payable hours on sync
Managed
Leave → Xero mapping
Leave typeXero leave type
Names must match exactly: each leave type syncs to the Xero leave type shown, so it must exist under that name in your Xero organisation. Some, like ACC, you add in Xero yourself. Public Holiday is handled natively by Xero, so it isn't synced as leave.

Notifications

Email triggers and recipients for automated payroll alerts

Approval reminders
Remind managers to approve timesheets after the pay period closes
Reminder threshold
Sent this many days after the pay period ends — mirrors the Pay period setting
Managed
Pay-run summary
Email a summary to managers when a pay run is submitted to Xero
Pay-run freeze
Notify managers when a roster publish is blocked by an active pay run
Error alerts
System-level errors (Xero sync failures, Lambda errors) are sent to the ops email below
Always on Managed
Email addresses
From address
SES-verified sending address configured at deployment time
Fixed
Ops / error email
Global inbox for system error alerts — shared across all organisations
Managed
Manager recipients
Pulled from the Cognito ‘managers’ group — they always receive these alerts
Additional recipients
Extra addresses outside the managers group — added to every reminder, pay-run and freeze email

Users & access

People with access to this organisation

Adding, editing and removing users is managed by your administrator.

Password policy

Password rules — managed centrally

Minimum length
8 charactersManaged
Required character types
Upper + lower + digitsManaged
MFA
Optional (TOTP)Managed

Data & compliance

Retention policies and audit-trail configuration (NZ Employment Relations Act)

Timesheet retention
Held 7 years for IRD tax records; NZ Employment Relations Act s130 sets a 6-year minimum for wage and time records
7 years Fixed
Glacier archive threshold
Exports older than this move to S3 Glacier Instant Retrieval for cost efficiency
90 days Managed
Audit log
All approval, rejection and config-change events are written to CloudWatch Logs and cannot be deleted by managers
Enabled (immutable) Managed
Enrolment photo retention
Biometric photos are stored in S3 (SSE); temp staging photos auto-delete after 48 h
Per-employee (S3 SSE) Managed