Skip to content
Inside the Boundary

All notes  /  Running it

Turning It Off

Ending a deployment, changing vendor, or someone leaving. The app and the data both outlive the arrangement unless someone handles it.

Running it · Procedure

A clock-in deployment ends more often than most systems, because the product is cheap and easily replaced. The endings are handled badly.

When someone leaves

Remove the app from their personal device, and confirm with them that it is gone.

An app left installed continues requesting location permission and may continue reporting, which is a serious problem and it happens.

Revoke their account.

Their attendance records remain, subject to payroll retention, and they may request them.

Coordinates go on the short schedule, which for a leaver usually means immediately.

Changing vendor

Export before termination, not after, while there is still an account.

Check what the export contains: punches, flags, corrections and approvals — or only a summary.

Confirm deletion in writing, including backups, with a date.

Do not migrate coordinate history into the new system. A vendor change is the cheapest opportunity you will have to reduce what you hold.

Tell the workforce that the old app should be deleted, and follow up.

Ending the deployment entirely

Decide what the payroll retention actually requires and export that.

Instruct deletion of everything else.

Tell people it has stopped, which is a courtesy and makes the next announcement credible.

And remove the app, which is the step that gets forgotten and leaves permission grants in place on dozens of personal phones.

The checklist

Accounts revoked.

App removed from personal devices, confirmed individually.

Export taken of what retention requires.

Deletion instructed and confirmed, including backups and the vendor's copy.

Exports on shared drives found and dealt with.

Workforce told.

Six items, owned by someone, because each fails silently.

The one that matters most

The app on personal phones.

It is the only part of this system that lives on property you do not control, and the only one where an oversight means continuing to hold a permission over someone who no longer works for you.

Ask people to confirm removal, and accept that some will not — which is an argument for company devices or a terminal in the first place.

Confirm app removal individually

The step that gets skipped.

Ask each person to confirm the app is gone from their phone.

Some will not, which is a permission grant persisting over someone who no longer works for you.

Follow up once, then record who did not respond.

And treat it as an argument for company devices or a terminal in the next deployment.

Connect policy to configuration

The practical choices behind this note can be compared with browse the integration directory. Keep the written purpose in control and enable only the data needed for it.