Who uses this, and how they get access
Factory, sales and office workers use one employee identity for time and expenses. The journeys below define the target experience. Mobile, email-free access, shared terminals and offline capture are requirements in development, not a statement of release availability.
Factory workers
At the start of a shift, identify yourself at an employer-provided terminal or on the mobile app, then start work. Record breaks and the end of the shift, including overnight work. A personal phone or email must not be required. The terminal returns to its locked start screen after each action; it must never expose another worker’s hours, receipts or account.
For an occasional purchase such as approved equipment or travel, use the app or a private session on a company device to attach the receipt. If assistance is needed, an authorized colleague records who paid, who entered the claim and why; the worker confirms it before submission. A supervisor cannot claim a worker’s reimbursement as their own. Assisted capture is proposed work.
Sales and field workers
Use the iOS or Android app between customer visits: start or correct time, choose a project, distinguish working travel from private travel, and photograph a receipt immediately. Review the amount, currency, category and who paid before submitting. A visit or a GPS position must not automatically become approved work. Travel-time eligibility follows the employer’s agreed policy.
Without reception, retain time events and receipt drafts securely on the device and label them “not yet synced”. Reconnection must not duplicate hours or claims. Upload failure keeps the draft available for retry; submission waits for server confirmation and any required attachment. No offline item may appear approved or reimbursed.
Office workers
Use the web app on a computer for daily time entry, project allocation, weekly review and receipt upload. The mobile app is optional for capturing receipts or time away from the desk. Company email is convenient, but having a desk must not determine which identity or access rights a worker receives. Employee time confirmation and expense submission remain separate actions.
Account creation without company email
Current source behavior: registration, invitations and password recovery depend on an email identity. A personal email can satisfy the address field; a company-domain address is not required by the registration schema. The invitation form may omit the email field because the invitation already supplies it. This is not email-free registration. Phone-only, employee-number and kiosk sign-in are not implemented.
Target requirement: an administrator creates or imports the worker into the correct organization, assigns a manager, work location, schedule and enabled modules, then gives them a single-use activation code in person or through an approved channel. The worker activates their own account, chooses their language and sets a private credential. No invented email, shared supervisor account, personal phone or employee purchase of a subscription is required. A code must never let someone choose their own employer or role.
Recovery, shared devices and leaving the company
Proposed sign-in: organization code, employee identifier and a private credential. A short PIN is restricted to an enrolled company terminal with attempt limits and a locked-down session; an employee number or badge alone is not proof of identity. Activation codes expire after 48 hours and one use. After identity verification, an authorized administrator can issue a replacement and revoke old sessions; every recovery is logged. Never display or email the old credential.
A lost device can be revoked without deleting the worker’s records. On departure, revoke organization access and prevent queued mobile actions from being accepted; route unsettled time and expenses to the named manager and finance owner. Define how former workers obtain their own statements through HR. A worker moving to another employer must never inherit access to the previous organization’s data.
App scope and rollout acceptance
The existing delivery direction is a React Native app for iOS and Android, alongside the web app. Proposed first employee release: activation and sign-in, time and breaks, corrections, weekly review, receipt capture, expense submission and status. Managers and administrators start on the web. Installation on a personal device is optional; the employer supplies a usable alternative. Native release, email-free access and terminal operation each need their own acceptance test.
Before rollout, demonstrate three complete journeys: a factory worker with no email or phone finishes a shift and submits a receipt; a salesperson records a visit and receipt offline and syncs exactly once; an office worker corrects a week and follows a reimbursement. Verify all four interface languages, readable errors, keyboard and screen-reader access, no cross-worker data after terminal handover, and visible review outcomes without email notifications. These are release gates, not completed tests.