# How to choose where your team can clock in

**For:** Admin
**You'll need:** Owner or Admin role.

There are two places a punch can come from: the **kiosk** — a shared tablet fixed at the worksite — and the **phone** an employee carries and is signed in on. You'll decide which of the two your company allows, and narrow the phone down per location if some worksites need people at the door.

This is a separate question from *how* the kiosk checks who's punching. For that, see {doc}`kiosk/turn-on-punch-photos`.

## Set the two company-wide switches

1. Open the account dropdown (top-right) and click **'Settings'**.
2. In the right column, find the **'Time clock'** section.
3. Turn **'Kiosk'** on or off. On means employees may punch on a shared tablet or computer at the worksite.
4. Turn **'Phone (own device)'** on or off. On means employees may punch from their own signed-in phone.
5. Click **'Save'**.

Both are on by default.

```{note}
Turning **both** off is a valid setup, not a mistake — it's the manual-entry-only company, where managers type the times on the timesheet. Manager entries and the automatic clock-out backstop are never affected by these switches.
```

Typical choices:

- Bought tablets so the door proves who was on-site? Turn **'Phone (own device)'** off.
- No hardware at all, everyone works from their own phone? Turn **'Kiosk'** off.

## Turn the phone off for one location

Some worksites need people to sign in at the door even when phones are fine everywhere else.

1. In the header, go to **Company → Locations** and open the location.
2. Turn off the **'Phone punching at this location'** toggle.
3. Click **'Save'**.

Shifts **at that location** can no longer be punched from a phone; the kiosk is the way in. This is keyed off where the shift is, not where the phone is — {{ app_name }} never looks at anyone's position.

```{note}
The location toggle can only narrow, never widen. If **'Phone (own device)'** is off company-wide, no location can switch it back on. There's no kiosk equivalent, because a kiosk is already tied to a location — the tablet paired to it *is* the enrolment.
```

## Take a single tablet out of service

For a repair, a renovation, or a room that's closed for the week, take the device out of service instead of deleting it.

1. In the header, go to **Planning → Management → Kiosk** and open the device.
2. Turn off the **'Active'** toggle.
3. Click **'Save'**.

The tablet shows *'This kiosk is currently disabled'* and refuses punches, retrying by itself until you switch it back on. Its pairing, credentials, and history are all kept, so switching it back on is a single click. Deleting the device stays the permanent option — see {doc}`kiosk/rotate-or-replace-a-device`.

## A policy change never strands an open shift

If you change any of this in the middle of a working day, nobody gets stuck clocked in. Somebody who clocked in on a tablet can always clock out and start a break on that same tablet, and somebody who clocked in on their phone can always finish on their phone — even if you just turned that surface off. Ending a break is never blocked at all. The new policy applies to the *next* punch that starts something, not to the one already running.

Correcting a time on the timesheet isn't a punch either, so it's never affected.

## Verify it worked

If you turned the phone off, open the mobile app as an affected employee: instead of an armed clock-in button they see that they need to punch at the kiosk. If you turned a kiosk off, its tablet shows the disabled notice within moments. Either way, the **'Time clock'** section reflects your choices after a reload.

## Related

- {doc}`kiosk/index`
- {doc}`kiosk/turn-on-punch-photos`
- {doc}`kiosk/rotate-or-replace-a-device`
- {doc}`/set-up-your-company/locations/edit-a-location`
