What a Working Deployment Looks Like
A description of the end state, assembled from everything here, as a checklist to measure a proposal against.
Reference · Reference
Rather than a summary, a description of the arrangement these notes point toward.
The collection
A position checked once, when the worker taps to clock in.
Nothing between punches. Location permission granted only while the app is in use, and verifiable.
Accuracy figure stored with every punch, successful or not.
Refusals logged with their causes.
No automatic clock-out, no punch photographs, no continuous tracking — or each separately decided and recorded.
The configuration
Radii set per site, from measurements taken at that site.
A punch window either side of shift start, so a few seconds of fix delay is not lateness.
A second method where satellites do not work indoors: wifi visibility, a beacon, a terminal.
Accept-with-flag rather than hard refusal.
A non-phone route for anyone without a working device.
The pay side
Work performed is paid, whatever the system recorded.
Corrections submitted by the worker, approved by a named person before the period closes.
No deduction for a system failure.
The full chain recorded: attempt, refusal, correction, approval, paid time.
The governance
An impact assessment written before deployment that changed the design.
Consultation completed, with a written response published.
A notice in plain sentences stating what is checked and what is not.
Coordinates deleted early; the attendance record kept for the payroll period.
Access to coordinates behind a recorded reason, with reads logged.
The operation
Refusal rate tracked per site, per week, and published.
Accuracy distribution watched, split by phone platform.
Fallback usage and correction turnaround measured.
A twenty-minute check after every vendor release and every phone platform update.
A named owner with allocated time.
What it produces
An attendance record people do not work around, because it does not punish them for its own failures.
A defensible position: one point, worker-initiated, deleted early, with the alternatives considered and documented.
And a deployment that costs less than the intrusive version, because collecting less is cheaper to store, to secure and to disclose.
Reviewing it annually
Six questions that describe whether it still works.
Is the refusal rate falling as sites get fixed?
Are corrections cleared before payroll, every period?
Is the collection still what was agreed?
Has the notice stayed true after updates?
Can a worker see their own punches and flags?
Would you deploy it the same way again?
An implementation prompt
During configuration, open the workflow reference can prompt questions about fields, ownership and output. Confirm current capabilities and document each plan, integration or policy assumption.