# Kiosk

A kiosk is a shared tablet at a location that lets staff clock in and out without each person signing into their own account. Workers pick their name from a grid, type a 4-digit PIN, and tap **'Clock in'**, **'Clock out'**, **'Start break'**, or **'End break'**. The punch lands on the same timesheet row as a manual entry — the manager workflow afterwards is unchanged.

```{note}
Kiosk is a setup-once feature. Once a device is paired to a location and signed in, day-to-day use is on the tablet — managers don't need to touch the device admin pages.
```

The typical setup-and-go flow:

1. An owner or admin creates a **kiosk device** in {{ app_name }} (one row per physical tablet) — this provisions a dedicated login for the tablet and shows the password once.
2. The tablet is signed in once using that email and password. It stays signed in.
3. Workers receive their personal **4-digit PIN** when they're invited to the company (or get a new one from a manager later).
4. At the start of a shift, the worker walks up to the tablet, taps their name, types their PIN, and clocks in. End of shift — same thing, **'Clock out'**.

The rest of this section covers each step.

## PIN, or PIN and a photo

A PIN says who's punching; the bolted-down tablet says where. That pairing is enough for most companies, and it's what {{ app_name }} does out of the box. If you have a documented reason to prove identity more strongly, you can switch the whole company to **PIN + photo**: a photo is stored with every punch and a manager reviews it. It's off by default, it comes with legal preconditions you own, and photos delete themselves after the period you set. Start at {doc}`turn-on-punch-photos`.

```{toctree}
:maxdepth: 1
:hidden:

add-a-device
sign-in-the-tablet
daily-use
manage-pins
rotate-or-replace-a-device
turn-on-punch-photos
punch-photos-at-the-tablet
review-punch-photos
the-camera-stopped-working
how-long-punch-photos-are-kept
```
