M cenaly.ru
🍽️ Hall, Kitchen & Back Office

🕒 Clock-in and Clock-out

Venue terminal (tablet / QR on a monitor), geofence and auto clock-out of forgotten shifts

Documentation

Clock-in and clock-out

Employees clock in and out themselves — and those marks immediately become the fact in the timesheet (the Plan vs fact tab of the Staff section) that payroll is computed from. The server always sets the time: it cannot be tampered with from a device.

Open: Admin panel → Staff → My cabinet (employee) and Staff → ⚙ Schedule and clock-in settings (owner; managers see them read-only).


What ends up in the timesheet#

A shift in the timesheet is a plan (if it was on the schedule) plus the fact: clock-in, clock-out and breaks. Every fact has a source:

Source How the fact appeared
The employee “I’m in” / “I’m out” in the personal cabinet — from a phone or a shared computer
Venue terminal PIN on the tablet terminal or a QR code from the venue monitor (see below)
POS A colleague marked from the shared POS terminal by their PIN, or a manager did
Device presence Auto timesheet: a waiter logged in on a tablet is on shift (per-location option)
Manual The owner or a manager edited the time in plan vs fact

A manual edit always wins over automation: after it no automation touches the shift.

If the employee arrives without a scheduled shift, the clock-in creates an unscheduled shift — visible in plan vs fact with its own marker.


Clock-in from the employee’s phone#

In My cabinet, the “Today” block shows the status (“Not on shift” / “On shift since 09:02”) and buttons:

  • I’m in — opens the shift: if there is a scheduled shift today the fact attaches to it, otherwise an unscheduled shift is created;
  • Break / Back — actual breaks inside the shift; a break left open is closed with the clock-out time;
  • I’m out — closes the open shift (including a night shift started yesterday).

Forgot to clock? The cabinet has “Forgot to clock” — a timesheet correction request confirmed by a manager.


Where clock-in is allowed: geofence or venue terminal#

The “Clock-in gate” setting in “Schedule and clock-in settings” decides whether clock-ins are accepted from anywhere:

Mode Behaviour
Off Accepted from anywhere, no checks
Warn (default) The browser sends its position; a clock-in farther than 300 m from the venue goes through but is flagged “outside location” — managers see the flag in plan vs fact
Strict A clock-in beyond the configured radius is refused with a message like “you are 800 m away, 300 m allowed”. No position (browser permission denied) — refused too. Clocking a colleague in by PIN from the POS is refused as well: a PIN proves who is clocking in, not where; bind the POS as a terminal (below) or allow it geolocation
Only from a venue terminal Accepted only with proof from a bound device — a tablet, phone or monitor that physically stays at the venue. Position is not requested

The geofence compares the browser position with the coordinates of the shift’s location (set in the location card). If the location has no coordinates, there is nothing to check and the clock-in passes.

When you need a terminal. Browser geolocation is soft evidence: it can be spoofed, and in dense areas the error exceeds the radius. A terminal is as hard as its mode: the tablet with a PIN pad requires standing at the tablet; the QR on a monitor lives for two minutes, and a photographed code can be forwarded by a colleague — it protects against “clocked in from home out of habit”, not against collusion. If you need strictness, use a tablet, not a monitor.


Venue terminal: binding a tablet or monitor#

A terminal is any tablet, phone or computer with a browser that stays at the venue. One account can bind several terminals (one or two per location).

  1. Open Admin panel → Staff → ⚙ Schedule and clock-in settings on the device itself. Sign in as the owner, a manager or with a device code.
  2. In the “Clock-in terminals” block press “Bind this device”, name it (“Tablet at the entrance”) and optionally pick a location.
  3. The device receives its secret and keeps it in the browser — it is never sent again or shown. The “This device is terminal …” note and the “Open terminal screen” button appear right away.
  4. Switch the clock-in gate to “Only from a venue terminal” and save.
  5. Open the terminal screen (/clock-terminal) and leave it on: the screen keeps itself awake, and the mode (tablet or monitor) is remembered in the address.

A terminal with a location accepts clock-ins only for shifts at that location: a shift elsewhere is refused with “today’s shift is at another location”. An unscheduled shift started from a location’s terminal gets that location automatically.

Revoke a terminal from the same list: a device with the old secret is refused at its next clock-in. If the browser’s site data is cleared, the secret is gone — just bind the device again.


Tablet mode: PIN pad#

The terminal screen shows four large buttons — I’m in, I’m out, Break, Back from break. The employee taps one and enters their cashier PIN (4–6 digits, issued in the employee card). No list to search and no login switching: the PIN is unique within the account, so the server knows who clocked in — the screen shows “Anna: clocked in at 09:02” for a few seconds.

A wrong PIN gets a neutral “Wrong PIN” with a delay, and after ten failures within a quarter of an hour the terminal (or the employee entering a PIN from a phone) is locked for 15 minutes — guessing other people’s PINs is pointless. All errors are spelled out: “already clocked in”, “not on break”, “this month is closed”, “an open shift from 17 September is still running”.


Monitor mode: QR on screen#

The terminal shows a large QR code that changes every 30 seconds. The employee scans it with their own phone camera — their personal cabinet opens with a green “Venue terminal confirmed” note and the usual “I’m in” / “I’m out” buttons. No position is requested: the code from the screen already proves the person is standing in front of the monitor.

The code stays valid for about two minutes after it is shown; too late — the note changes to “The QR code has expired — scan it again”. One scan is good for one clock action.

This mode fits any screen without touch — a TV at the entrance, a monitor at the bar — and requires nothing from the employee beyond the phone they already use for the cabinet. Hours do not go to whoever photographed the screen: the code lives two minutes, and the clock action comes from the employee’s personal login.


Ways to register leaving with minimal effort#

Clock-out is forgotten more often than clock-in: people are tired and leave. Meni offers several ways to close a shift, and they combine — from the cheapest to the most precise:

Method What it needs Precision When to enable
Auto clock-out by schedule Nothing: an account setting Scheduled end of the shift Always, as a safety net when a schedule is kept
Auto clock-out by cap Same setting Clock-in + N hours For unscheduled shifts, so they do not hang for weeks
“I’m out” from the phone Personal login To the minute Default for everyone
PIN on the terminal A tablet at the exit To the minute When leaving must be marked on site
QR from the monitor Any screen To the minute When there is no tablet but everyone has a phone
A colleague marks from POS POS terminal To the minute Cashier leaving together with closing the cash shift
Device presence Waiter tablets on the venue Wi-Fi, per-location option Last tablet signal Fully automatic timesheet for a hall with tablets
“Forgot to clock” correction Employee request, manager decision As stated by the employee Always available as the last resort

Deliberately not done: background phone geolocation (browsers do not offer it, and an app tracking employees after the shift is a privacy question) and biometrics (dedicated hardware and stricter personal-data rules).


Auto clock-out of forgotten shifts#

The “Auto clock-out for forgotten shifts” block in “Schedule and clock-in settings”:

  • Close open shifts automatically — the switch, off by default;
  • Wait after the scheduled end, minutes — the grace period (default 30): if no clock-out arrives within it, the shift is closed at the scheduled end, not at the current time — the automation never invents hours beyond the schedule;
  • Cap for unscheduled shifts, hours — for shifts without a plan or started after the scheduled end: close N hours after clock-in (default 12; 0 — leave them alone, they stay in the plan-vs-fact list of open shifts).

The check runs every 30 minutes. An auto-closed shift carries the “⏱ auto-closed” badge in the timesheet (with a hint — by schedule or by cap), and the employee gets a work-chat notice: “No clock-out recorded — your shift was closed automatically at 18:00 per the schedule. If you left at a different time, request a correction.” A manual edit removes the badge. Closed months and presence-based shifts are never touched.


Sources of the fact and payroll#

Payroll is computed from timesheet hours, so every fact stores where it came from, and plan vs fact shows it with badges: “📡 auto” for presence, “⏱ auto-closed” for auto clock-out, the “outside location” flag for a distant clock-in. The terminal that confirmed a clock action is recorded in the shift too. Managers see all of it in Plan vs fact, employees in My hours, and both can start a correction until the month is closed.


FAQ#

Can an employee without a login clock in?#

On the terminal — yes: the tablet accepts the PIN of any employee who has one; no login is needed. From a phone or by QR — no: there the clock action comes from the personal login.

What if the terminal breaks or is taken away?#

Revoke it in the terminal list and temporarily switch the gate to “Strict” or “Warn” — employees clock in from their phones. Forgotten shifts are closed by auto clock-out.

Can the terminal be required for one location only?#

The gate is account-wide, while a terminal binds to a location. If a location has no terminal, its employees would have to use another one — better to put at least a monitor with a QR code there.

Nothing happened: the scan only proves presence, the button makes the clock action. After two minutes the code expires and must be scanned again.

Will auto clock-out inflate hours?#

It never invents hours beyond the schedule: by schedule the shift closes at the scheduled end even if the check ran later, and by cap exactly the configured number of hours after clock-in. But it does not know when the person actually left: someone who left early is credited until the scheduled end, someone who stayed late only until it. That is why an auto-closed shift is marked “⏱ auto-closed”, the employee is notified and requests a correction if the time is wrong, and the manager confirms it. If the manager then reopens the shift (removes a wrong clock-out), the automation leaves it alone.

I forgot to clock out yesterday — today “I’m in” does not work#

An employee can have only one open shift. The cabinet and the terminal tell you which one is still running (“an open shift from 17 September”): press “I’m out” — it closes at the current time — then clock in and request a correction for yesterday’s clock-out. Enable auto clock-out so it does not happen again.


Was this article helpful?