Setting Up Kiosk Time Clock in 2.0

Modified on Wed, 23 Sep at 2:17 PM

Some clients want clocking in to happen at the site, on a device they control — not on each Crew member’s own phone. The Kiosk time clock turns a tablet or computer already sitting at the client’s location into that station.

Summary

The Kiosk is a web page, not an app. Any tablet or computer with a browser and internet can run it, so there is no hardware to buy and nothing to install.

Its security comes from one thing: the client’s public IP address. You add that address to the client’s record, and the Kiosk page only works when it is opened from that address. Anywhere else, it does nothing.

Clock-ins from the Kiosk land on the Crew member’s timesheet the same way a phone clock-in does. Nobody retypes anything.

The thing that goes wrong is the IP changing. Most business internet accounts hand out a new address from time to time unless the client pays for a static one. When it changes the Kiosk stops working, and nothing warns you — the Crew just cannot see their jobs. Ask the client whether their address is static before you rely on this.

How to do it

1Put a tablet or computer at the client’s site, on the client’s internet connection.

2Open the time clock page on that device. It shows you the address the device is coming from.

3In NextCrew, go to CRM > Clients, open the client, and click the Configuration tab.

4Find White-list of IPs for Time Clock, click Add, enter the address, and confirm.

5Reload the page on the kiosk device and have somebody scheduled there clock in. That is the only real test.

6Ask the client whether that address is static, and write the answer on the client record. If it is not, this will break and you will want to know why.

▶ Watch a Kiosk time clock being set up

Prefer to click through it yourself? Open the interactive walkthrough.

When you would use one

Nobody has to use the Kiosk. Phone clock-in already works. These are the situations where a fixed station at the site is the better answer.

Phones do not come onto the floor. Warehouses, food production, clean rooms and plenty of manufacturing sites make Crew leave phones in a locker. A tablet at the door is the only way clocking in happens at all.

The client does not trust phone clock-ins. A phone can be clocked from the parking lot, or from home. The Kiosk only answers from the client’s own connection, so the record says the person was on the premises. That is often the whole reason a client asks for it.

Forty people arrive through one door. Large events and shift changes go faster through one station than through forty separate phone screens, and the line itself becomes your headcount.

Some of the Crew have no usable phone. Not everyone has a current smartphone or data. The Kiosk gives them a way to clock in without making it a conversation.

You do not have to choose. The Kiosk and the Crew mobile app work at the same client, on the same job. Some people can clock in at the tablet while others use their phone.

That is the Kiosk live. Everything below is for when the address moves, the page will not load, or somebody asks who is allowed to change this.


Who this applies to

  • Account managers — the client asks you for this, and you are the one who has to ask them for the address.
  • Operations and schedulers — you find out first when it stops, because the Crew calls you.
  • Administrators — the permission that lets somebody edit this is yours to hand out.

Before you start

What you needWhere it comes from
A device at the client’s siteAny tablet or computer with a browser. iOS, Android or desktop. Often the client already has one.
Internet at that locationThe client’s own connection. The device has to be on it, not on a cell hotspot, or the address will be wrong.
The client’s public IP addressStep 2 reads it off the device for you. You do not need to ask their IT team for it.
Permission to edit client configurationSettings > Staff > Roles > Edit, then enable Client Configuration. Manager or Administrator role.

What the white-list actually protects

It is worth being precise about this, because clients ask.

The white-list checks where the clock-in came from, not who did it. If the page is opened from an address you have not listed, it will not let anyone clock in. If it is opened from an address you have listed, it works — for anyone scheduled at that client.

So it answers the question “was this person on site?” It does not, on its own, answer “is this the right person?” Photo capture is the part that helps with the second question.

An address covers a location, not a building you can see. Anyone on that client’s network — including their guest Wi‑Fi, if it shares the same connection — is inside the white-list. If that matters to the client, have them put the kiosk device on a network that visitors cannot reach.

You can list as many addresses as you need on one client. A client with four warehouses gets four entries, one per site.


Steps

1. Put a device at the site

A tablet or a computer, somewhere Crew pass on the way in. It needs a browser and the client’s internet. That is all.

Put it on the client’s wired or Wi‑Fi network, not on a cell hotspot. A hotspot has its own address, which changes, and the white-list you build will stop matching within days.

2. Find the address the device is using

On the kiosk device, open the time clock page for your company:

https://<yourcompany>.nextcrew.com/app/time-clock

Replace <yourcompany> with the name in your own NextCrew address — the same one you sign in at.

Until the address is whitelisted, nobody can clock in from that page. But it will still show you the address the device is coming from. That is the number you need.

3. Open the client’s Configuration tab

Back in NextCrew, go to CRM > Clients and open the client this kiosk belongs to. Click the Configuration tab.

If you do not see the tab, you do not have the Client Configuration permission. That is an Administrator change, not a NextCrew one — see the screen level permissions guide.

4. Add the address to the white-list

Scroll to White-list of IPs for Time Clock and click Add. Enter the address from step 2 and confirm.

Paste it rather than typing it. A single wrong digit produces exactly the same symptom as no entry at all, and it is a hard mistake to spot by eye.

Repeat for each site. One client can hold as many addresses as it has locations.

5. Test it with a real clock-in

Reload the time clock page on the kiosk device. Have somebody who is actually scheduled at that client clock in, then check that the punch appears on their timesheet.

Do not stop at “the page loaded”. The page loading only proves the device has internet. The clock-in is what proves the white-list entry is right.

6. Find out whether the address is static

Ask the client, or their IT contact, one question: is this a static IP address? Then write the answer in a note on the client record.

If it is static, this setup will hold. If it is not, the address will change when their provider changes it, or when the router is replaced or restarted. The kiosk then stops the next morning, with no warning.

This is the step people skip, and it is the reason most kiosk tickets get raised. Two minutes now saves a scramble during a shift change.

Photo capture at clock-in

The Kiosk can take a photo when someone clocks in or out, using the device’s camera. It is optional, and it is what turns “somebody clocked in from this site” into “this person clocked in from this site”.

Clients who want it usually want it for one reason: they are paying by the hour and they want to see who showed up.

[verify] before publishing — where photo capture is switched on. The article being replaced said only “adjust settings in the Kiosk module”, which names no screen and no control. Needed: the exact path, whether it is set per client or company‑wide, and where the captured photos are then viewed. Without those three answers this section should be cut rather than published vague.


Running the Kiosk alongside the mobile app

The Kiosk is an extra way to clock in, not a replacement. At the same client, on the same job, some Crew can punch at the tablet while others use the NextCrew mobile app on their phone. Both end up on the same timesheet.

That matters in practice. A client can install a kiosk without you retraining every Crew member first. You can move people over gradually.

A supervisor clocking a group in from their own phone also still works. See How to Assign a Supervisor for Clock-In/Out.


If it’s not working

The Crew can’t see their jobs

Symptom. The page opens on the kiosk, but nobody can find a shift to clock into.

Almost always the address. Work through these in order:

  1. Re-read the address on the device. Open the time clock page again and compare what it shows with what is on the client record, digit by digit.
  2. Check the device is on the client’s network. A tablet that has quietly fallen back to a cell connection, or joined a guest network on a different line, reports a different address.
  3. Check it is on the right client. The white-list is per client. Whitelisting the parent does not cover a child site, and the other way around.
  4. Check the Crew member is actually scheduled there. The Kiosk shows the jobs they are assigned to at that client. No assignment, nothing to clock into — and that has nothing to do with the kiosk.

It worked last week and stopped

The address changed. This is the normal failure, not a rare one. It usually follows a router restart, an equipment swap, or an internet provider change at the client’s site.

The fix is the same each time: read the new address on the device, add it to the client’s white-list, and test with a real clock-in. Leave the old entry or remove it — an address that no longer belongs to the client is worth removing.

If it keeps happening at the same client, that is the answer to step 6 arriving late. A static address from their provider ends it.

There is no White-list section on the client

You are on the client record but the Configuration tab or the white-list is not there. This is a permission, not a setting: your role needs Client Configuration enabled under Settings > Staff > Roles > Edit.

Whoever administers roles at your agency can turn it on. If that is you, do it for the role rather than for one person — the next account manager will hit the same wall.


How to know it’s complete

  • ✅ The device sits where Crew actually walk past it, on the client’s own connection.
  • ✅ The address on the client record matches what the device reports, exactly.
  • ✅ Somebody scheduled at that client has clocked in from the kiosk, and the punch is on their timesheet.
  • ✅ Every site that has a kiosk has its own entry on the white-list.
  • ✅ A note on the client record says whether the address is static, and who told you.

Your own obligations

NextCrew records the time of each punch, the address it came from, and a photo if photo capture is turned on. What you may collect, how long you may keep it, and what you must tell people first are set by the rules where the work happens. Those differ by state.

Some states have specific laws about collecting images of workers. Before you switch photo capture on for a client, check with your own legal or HR advisor what notice you owe the Crew. NextCrew cannot make that call for you.



FAQ

Q: Does the client have to buy anything?

A: No. The Kiosk is a web page, so any tablet or computer they already have will run it. No app to install, no reader, no terminal.

Q: Can we whitelist more than one address?

A: Yes. Add as many as the client has locations with a kiosk. They all sit on the same client record.

Q: Does it work in any browser?

A: Yes, on a current browser with internet. What decides whether it works is the address it is opened from, not which browser is used.

Q: Can some Crew use the kiosk while others use their phone?

A: Yes. The two run together on the same job, and both write to the same timesheet.

Q: Why can the Crew suddenly not see their jobs?

A: Check the address first. If the client’s internet equipment changed or restarted, the address probably changed with it, and the white-list entry no longer matches.

Q: Can somebody clock in from home?

A: Not through the Kiosk. It only responds to addresses you have listed. That is the point of it.

Q: Does the Kiosk prove who clocked in?

A: On its own it proves the punch came from the client’s site. Photo capture is the part that ties it to a face.

Q: Who can add or change a white-list entry?

A: Anyone whose role has Client Configuration enabled, normally a Manager or Administrator. It is not limited to the person who set it up.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article