endefrit

Specification · Time tracking module

Time tracking: clear records, reviewable decisions

Factory, sales and office journeys, app access and accounts without email, followed by time capture, Swiss holiday calendars, configurable credits and review. Current behavior and proposed delivery criteria are distinguished throughout.

In development

This module is in development. The details below describe its current scope and direction, including work that is not yet generally available.

Version
1.3
As at
11 September 2026
Status
Module in development
Scope
Switzerland
A consultant arriving at a studio courtyard with her bicycle.

Who uses this, and how they get access

Factory, sales and office workers use one employee identity for time and expenses. The journeys below define the target experience. Mobile, email-free access, shared terminals and offline capture are requirements in development, not a statement of release availability.

Factory workers

At the start of a shift, identify yourself at an employer-provided terminal or on the mobile app, then start work. Record breaks and the end of the shift, including overnight work. A personal phone or email must not be required. The terminal returns to its locked start screen after each action; it must never expose another worker’s hours, receipts or account.

For an occasional purchase such as approved equipment or travel, use the app or a private session on a company device to attach the receipt. If assistance is needed, an authorized colleague records who paid, who entered the claim and why; the worker confirms it before submission. A supervisor cannot claim a worker’s reimbursement as their own. Assisted capture is proposed work.

Sales and field workers

Use the iOS or Android app between customer visits: start or correct time, choose a project, distinguish working travel from private travel, and photograph a receipt immediately. Review the amount, currency, category and who paid before submitting. A visit or a GPS position must not automatically become approved work. Travel-time eligibility follows the employer’s agreed policy.

Without reception, retain time events and receipt drafts securely on the device and label them “not yet synced”. Reconnection must not duplicate hours or claims. Upload failure keeps the draft available for retry; submission waits for server confirmation and any required attachment. No offline item may appear approved or reimbursed.

Office workers

Use the web app on a computer for daily time entry, project allocation, weekly review and receipt upload. The mobile app is optional for capturing receipts or time away from the desk. Company email is convenient, but having a desk must not determine which identity or access rights a worker receives. Employee time confirmation and expense submission remain separate actions.

Account creation without company email

Current source behavior: registration, invitations and password recovery depend on an email identity. A personal email can satisfy the address field; a company-domain address is not required by the registration schema. The invitation form may omit the email field because the invitation already supplies it. This is not email-free registration. Phone-only, employee-number and kiosk sign-in are not implemented.

Target requirement: an administrator creates or imports the worker into the correct organization, assigns a manager, work location, schedule and enabled modules, then gives them a single-use activation code in person or through an approved channel. The worker activates their own account, chooses their language and sets a private credential. No invented email, shared supervisor account, personal phone or employee purchase of a subscription is required. A code must never let someone choose their own employer or role.

Recovery, shared devices and leaving the company

Proposed sign-in: organization code, employee identifier and a private credential. A short PIN is restricted to an enrolled company terminal with attempt limits and a locked-down session; an employee number or badge alone is not proof of identity. Activation codes expire after 48 hours and one use. After identity verification, an authorized administrator can issue a replacement and revoke old sessions; every recovery is logged. Never display or email the old credential.

A lost device can be revoked without deleting the worker’s records. On departure, revoke organization access and prevent queued mobile actions from being accepted; route unsettled time and expenses to the named manager and finance owner. Define how former workers obtain their own statements through HR. A worker moving to another employer must never inherit access to the previous organization’s data.

App scope and rollout acceptance

The existing delivery direction is a React Native app for iOS and Android, alongside the web app. Proposed first employee release: activation and sign-in, time and breaks, corrections, weekly review, receipt capture, expense submission and status. Managers and administrators start on the web. Installation on a personal device is optional; the employer supplies a usable alternative. Native release, email-free access and terminal operation each need their own acceptance test.

Before rollout, demonstrate three complete journeys: a factory worker with no email or phone finishes a shift and submits a receipt; a salesperson records a visit and receipt offline and syncs exactly once; an office worker corrects a week and follows a reimbursement. Verify all four interface languages, readable errors, keyboard and screen-reader access, no cross-worker data after terminal handover, and visible review outcomes without email notifications. These are release gates, not completed tests.

What each working day must prove

Required factory example: a 06:00–14:00 shift with an unpaid 30-minute break records 450 worked minutes and 30 break minutes, without counting the break twice or inventing a deduction. Paid breaks must follow an explicit policy and remain distinguishable. Missed clock-out prompts a correction; the system must not silently replace actual work with the scheduled shift. Overnight shifts retain their shift context while daily totals follow local calendar days.

Required sales example: record 60 minutes of eligible work travel and a 90-minute visit as 150 worked minutes with their project context. An expense for the same trip is a separate claim and does not add working time. Private travel does not become work automatically. Changing time zone while travelling must preserve actual elapsed time and explain which work-location calendar and reporting zone apply.

Required office example: an employee scheduled for four eight-hour days has a 32-hour weekly target, not 40. A half-day absence on one scheduled day reduces the target by four hours; an absence on the unscheduled day does not reduce it. The employee checks the week, corrects missing or misallocated work and submits confirmation. Changes after review need renewed review; reminders remain visible in the app for people without email. Individual schedules, absence adjustments and weekly confirmation are proposed extensions.

Read the detailed expense specification

Purpose and boundaries

The module records working time per employee, credits it according to the organization's rules, and puts what stands out in front of a manager.

The core flow is capture → evaluate → review → report. Employees own their entries; managers review exceptions; administrators maintain the organization’s policy and holiday calendar. Optional AI starts with private suggestions that an employee can accept, edit or dismiss.

Holiday matching uses the employee’s work canton, with the organization’s canton as fallback. Full-day national and cantonal records are supported; municipal and partial-day rules remain a delivery decision. A local event must not be advertised as a holiday for an entire canton.

Recorded time measures work; credited time applies an internal factor; accepted time reflects review; billable time depends on the client agreement. These concepts must stay separate. This module does not calculate wages, establish legal entitlement or issue invoices.

Principles

Principles for capture and review:

  1. 1 Review follows recording. No pre-approval is required in the module. Current manual-entry limits can still block a save; preserving actual work beyond a policy ceiling is an open core requirement.
  2. 2 Rules apply at the moment of recording. What was credited stays credited.
  3. 3 Rates do not stack. The day type selects a base factor; overtime uses the higher of that factor and the configured overtime factor.
  4. 4 Validation must be consistent. Manual capture and timer stop currently differ. The delivery criteria below define the required behavior for every capture route.
  5. 5 The timer is system state, not browser state. It survives a reload, a logout and a change of device.

Recording time

Timer

One click on start opens a time entry with no end. While it is open the timer runs — visible on every device the employee signs in on. Description and project can be changed while it runs.

Stop sets the end, evaluates the entry and saves it. Discard deletes the running entry. Starting a new timer first stops the previous one. Concurrent starts and retried requests must satisfy the delivery criteria below.

Manual entries

Time can be entered through a date/start/end form or parsed shorthand such as 2h 30m client call. Shorthand is a structured convenience, not an AI assistant. Manual saves use the time-credit evaluation and reject policy violations.

Day boundaries

Evaluation splits elapsed time at local midnight (Europe/Zurich by default). Friday 22:00 to Saturday 02:00 gives two workday hours and two weekend hours, assuming no holiday or earlier overtime. The entry remains one record; current daily reports group it by its start date. Reporting each segment on its own day is a delivery requirement.

Day types and rates

Each segment of time is given a day type based on its calendar day. The day type sets the factor that turns recorded minutes into credited minutes.

Workday
1.0×

Monday to Friday, no public holiday at the place of work.

Weekend
1.5×

Saturday and Sunday. Factor configurable per organization.

Public holiday
2.0×

A holiday in the employee's work canton. Beats the weekend.

Recorded minutes and credited minutes are kept and reported separately. Four hours of Sunday work are four recorded and six credited hours.

Overtime

Where the time recorded on a calendar day exceeds the daily threshold (8 hours by default), the excess is credited at an overtime factor of 1.25×.

Rates do not stack. The excess is credited at the higher of the two values — day factor or overtime factor — never at their product.

The ninth hour on a Tuesday counts 1.25×. The ninth hour on a public holiday counts 2×, not 2.5×.

The daily threshold applies to all entries of the calendar day together, not to the individual entry. Five hours in the morning and four in the afternoon make one hour of overtime.

The snapshot rule

On save, the entry keeps the result of the evaluation permanently: day type, name of the holiday, factor applied, recorded minutes, credited minutes, overtime minutes.

A later policy or calendar change leaves existing snapshots unchanged. Editing an old entry uses the policy available at the time of the edit. This preserves stored results, but does not provide period locking or a policy history by effective date; those are proposed requirements.

Editing an entry re-evaluates it as of now and clears any approval already given. An approved entry cannot be changed unnoticed.

Limits

Manual saves reject the checks below and show the reason. Timer stop currently calculates violations but still saves the entry. This inconsistency must be resolved before validation can be described as uniform; see Delivery criteria.

Check Default Reason
Daily maximum 720 min Sum of all entries on a calendar day
Weekly maximum 2700 min Sum of the ISO calendar week
Single duration 24 h One entry cannot last longer than a day
Overlap No entry may overlap an existing one of the same employee
Future Time cannot be recorded in advance

The daily and weekly maximums are configurable per organization. The checks on overlap, future and single duration are fixed.

Holiday calendar

The calendar is imported one year at a time from a public source (OpenHolidays) and held per organization. A holiday is either nationwide or bound to one canton.

The employee’s work canton takes precedence over the organization’s default. Without either, only nationwide holidays match. Administrators must verify the applicable calendar; municipality-specific and half-day observances are not represented by the current full-day canton model.

Import and manual additions

An administrator triggers the import per year. Re-importing replaces imported rows only. Days entered by hand — company holidays, local customs, bridge days — are left untouched and can be maintained individually.

Holidays spanning several days are expanded into single calendar days on import, so that evaluation stays exact to the day.

Approval

Approval is after the fact. An entry is recorded and credited whether or not anyone later confirms it.

An entry is put forward for review when a corresponding organization-level approval switch is enabled and at least one of these conditions applies:

  • work at the weekend
  • work on a public holiday
  • overtime past the daily threshold

Entries without an enabled review trigger are marked as not requiring approval. Others are pending until an organization manager or administrator approves or rejects them; a review note is optional today. Rejection retains the entry and its calculated credits. Current totals do not exclude rejected entries, so credited time must not be presented as accepted time.

Reporting

The week view shows the employee, for the current ISO week:

  • recorded time against target (standard workday × 5)
  • credited time including premiums
  • the overtime share
  • time awaiting approval
  • a breakdown across seven days, with weekends and public holidays marked by name

The current target is the organization’s standard workday multiplied by five, without individual schedules or absence deductions. Cross-midnight entries are grouped under their start date. Separate accepted totals, per-day reconciliation and employment-specific targets are delivery requirements below.

Roles and configuration

Role Permissions
Employees Record, edit and delete their own time; see their own figures
Managers In addition: confirm or reject entries put forward
Administration In addition: maintain the policy, import and hand-maintain holidays, assign work cantons

Values configurable per organization

Parameter Default
Standard workday 480 min
Overtime threshold per day 480 min
Overtime factor 1.25×
Weekend factor 1.5×
Public-holiday factor 2.0×
Maximum per day 720 min
Maximum per week 2700 min
Time zone Europe/Zurich
Default canton

An organization without its own configuration runs on these values; the policy is created on first access.

Delivery criteria and known gaps

These are requirements for the next core revision, not claims that the current implementation passes them. Resolve them before enabling an AI writer or treating the module as a complete working-time record. Each scenario must be demonstrated with persisted entries and the resulting reports.

Preserve actual work

A 13-hour day must remain recordable as actual work with a visible policy exception, without silently truncating it or granting approval. Invalid intervals and overlaps still require correction. Apply the same rules to manual entry, timer stop, future offline sync and AI-confirmed entries. Retrying a stop or starting from two devices must produce one consistent timer state and no duplicate hours. Current gap: manual limits reject while timer stop saves violations.

Make every day reconcile

With default factors, no holiday and no earlier work, Friday 22:00–Saturday 02:00 must report 120 recorded/120 credited minutes on Friday and 120 recorded/180 credited minutes on Saturday. Split Sunday–Monday across ISO weeks. Count elapsed time through both daylight-saving transitions and disclose rounding. Adding, editing or deleting earlier work must re-evaluate affected daily overtime in open periods. Current gaps: reports and neighbouring-entry totals use the start date; related snapshots are not recalculated.

Separate review from totals

For a four-hour Sunday entry at 1.5×, show 240 recorded and 360 credited minutes. While pending or rejected, its accepted contribution is zero; after approval it is 360 credited minutes. Preserve the rejection reason and let the employee correct and resubmit. An edit resets review. Define reviewer scope and prohibit self-approval of exceptions. Current gaps: totals include every review status, review notes are optional and approvers operate organization-wide.

Close and correct a period

An approved period becomes read-only. A correction records the original, replacement, reason, author and reviewer without overwriting an exported result. Record the applicable policy version and calendar context. An export identifies its period, included approval states, employee/project references and units; repeated handover must not charge twice. Reconcile exported totals to accepted entries and show failures. Period locks and finance handover are proposed extensions, not current guarantees.

Handle real working patterns

Proposed target model: an effective-dated schedule per employee and weekday, with approved absences and applicable holidays reducing that day’s target at most to zero. Count an overlapping holiday and absence only once. Keep breaks explicit; never invent a break deduction to make a day fit a limit. Flag rest exceptions for review. Current gaps: the target is standard day × five, with no individual schedule or break/rest model.

Verify calendars and missing data

Preview the imported year, source and canton coverage before activation. Show missing years or missing work locations; absence of calendar data must not imply a verified ordinary workday. Re-import without duplicates and preserve manual additions. Municipal and partial-day holidays need an explicit applicability model. Test missing cantons, repeated imports and local exceptions before claiming location-specific coverage.

Optional · Proposed, not yet available

Less timesheet admin, with an AI assistant

An assistant could assemble the day, suggest project allocations and surface entries that need attention. You would review the evidence and decide what becomes a time record. Each option below can be enabled separately; the timer and manual entry remain available.

Draft my day

Turn selected calendar events and project activity into a private draft, with suggested project, duration and description.

Candidate sources: Outlook or Google Calendar and selected project tools. Show the source, proposed time range, project match and uncertainty for each suggestion. A scheduled meeting is not proof of attendance; a commit is not a duration. Cancelled events and overlapping signals must not create duplicate time. Missing evidence stays a gap for the employee to resolve.

Log time by asking

“Log 45 minutes for the Acme design review yesterday.” Preview the date, project and duration before saving.

Optional text or voice input can create a draft, start or stop a timer, or answer questions about your own week. Resolve relative dates in the displayed time zone and ask for missing start times or ambiguous projects. An external assistant connection is a later option after an internal pilot. Every write needs a preview and explicit confirmation; retries must not duplicate it. Existing access and validation rules apply.

Check my timesheet

Flag possible overlaps, forgotten timers, unassigned work and missing details before review. Explain each flag and offer a correction.

The assistant may prepare a review queue and a reminder draft; sending reminders requires an enabled schedule or a confirmed action, with quiet hours and a frequency limit. Rule checks determine limits and credits. AI may explain them, but cannot approve, reject, change factors or close a period. Employees can dismiss suggestions with a reason; a gap must never be filled with invented work.

Recall work privately

An optional personal activity timeline could help recover forgotten work, with pause, exclusions and deletion under the employee’s control.

Defer desktop capture until customers demonstrate a need. Require explicit opt-in, a visible capture indicator, work-hour controls and app/site exclusions. Raw activity is private to the employee, including from managers and organization administrators; only confirmed entry fields are shared. No screenshots, keystroke capture, covert monitoring or productivity ranking. Raw activity is never treated as proof of hours worked.

Explain project time

Ask where a project’s time went, which entries await review, or how accepted hours compare with a stated budget.

Answers must link to authorized entries, state the date range and separate recorded, accepted and billable hours. Use approved aggregates for budget comparisons and disclose missing budgets or rates. Forecasts are estimates with stated assumptions. The assistant cannot infer profitability from credited hours, expose private activity or rank people by apparent busyness.

Separate human and agent work

Keep human effort, unattended AI runs and provider costs separate when a project uses AI agents.

Experimental option: attach agent run duration, tool/provider, available usage cost and a result reference to a project. Record prompting, supervision, review and integration as human work only when performed. A two-hour unattended run plus 20 minutes of human review means 20 human minutes and a separate two-hour run. Parallel agents must not multiply employee hours; any client charge follows an explicit billing agreement.

What every AI option must guarantee

Suggestions stay outside time totals until the employee confirms them. Store source references, the proposed fields, uncertainty, edits and confirmation history. Revalidate access, overlaps, current entry version and period locks at save time; refuse stale or duplicate writes. Connected content is evidence, never authority to call tools or change records. Revoking a connection stops new access and pending jobs; manual capture must keep working during an outage.

Data boundaries before a pilot

Choose a provider, permitted data fields and processing region before activation. Request only the sources the employee selects, with no model training on customer content. Proposed raw-signal retention: seven days, configurable downwards; delete dismissed drafts and their raw evidence on request. Confirmed time records follow a separate organization retention policy. Show connection health, last sync and deletion status; document deletion timing for backups and providers.

Start small and measure the result

Recommended sequence: core delivery criteria first; then calendar drafts and conversational entry; then review assistance and project questions. Desktop capture and agent-cost records require separate customer demand. Pilot with 5–10 volunteers for two weeks after measuring one manual baseline week. Proposed gates: median daily review under two minutes, at least 80% of suggested project assignments accepted unchanged, at least 30% less timesheet administration, and zero unauthorized disclosures or writes. Measure missing work and false suggestions as well as acceptance; reject a pilot that merely inflates hours.

These are evaluation targets, not product performance claims. Before the pilot, its owner must set a per-user monthly cost ceiling and a stop condition for exceeded spend, repeated errors or privacy failures. Expand only after reviewing results and the correction log with participants.

Business decisions

These questions define who the module serves, which responsibilities it supports and what belongs in the first release. Recommendations are proposals for agreement. Implementation choices are handled separately.

Confirmed mobile direction

Mobile delivery will be a React Native app for iOS and Android. The app is in development. The business decision is which employee and manager workflows belong in its first release.

01

First mobile release

Who needs to complete their work on a phone from day one?

  • Employees first: record and correct time, choose a project, review the week and respond to reminders. Managers review on the web initially. Recommended
  • Employees and managers together: include mobile approvals and team exceptions in the first release, with a broader launch scope.
02

Work away from a reliable connection

Must the first release support people working on sites, travelling or visiting customers with poor reception?

  • Yes. Employees can keep a record when disconnected and confirm it when back online. Include this in the mobile launch requirements. Recommended
  • Start with teams that have reliable connectivity. People record missed time afterwards until field use is included.
03

Approval responsibility

Who is accountable for accepting a person’s time and resolving exceptions?

  • The line manager, with a named deputy for absences and escalation to HR. Nobody approves their own exceptions. Recommended
  • A central operations or HR team reviews all time, with managers providing context when needed. Self-approval remains excluded.
04

Sign-off cadence

When should employees confirm their records and managers finish reviewing them?

  • Weekly employee sign-off and manager review, followed by a monthly finance close. Resolve mistakes while the work is still fresh. Recommended
  • Monthly sign-off and review aligned with payroll, with urgent exceptions handled during the month. Fewer review cycles, more work at closing.
05

Overdue reviews

Who follows up when a manager has not reviewed time by the agreed deadline?

  • Remind the manager and escalate to the deputy, then HR if still unresolved. Keep the record pending until a person decides. Recommended
  • Give HR a regular review of overdue items and responsibility for assigning a replacement approver. Records remain pending during follow-up.
06

Working patterns and absences

How much of employee availability should the first release manage?

  • Support individual weekday targets and reflect absences approved by HR. Leave requests and leave balances remain in the existing HR process initially. Recommended
  • Include leave requests, balances and absence approvals alongside time management from launch. This expands the first release into absence management.
07

Who resolves working-time exceptions

Who acts on excessive hours, missing breaks or repeated corrections, while preserving the actual work record?

  • The manager resolves ordinary exceptions with the employee; HR handles repeated or serious cases and records the follow-up. Recommended
  • HR reviews every working-time exception before the period can close, with managers supplying the explanation. More central oversight, more review work.
08

Period close and corrections

When should time become read-only, and who can authorize a correction afterwards?

  • Close a month after employee confirmation and manager review. HR authorizes traceable corrections, preserving the original result and the reason. Recommended
  • Close each approved week, with the same controlled correction process. This reduces late changes but requires more frequent review.
09

Access for workers without email

Which employer-provided devices and onboarding support are needed at the first factory site?

  • Include employer-issued activation and a shared terminal in the factory pilot, with private receipt capture on a company device and an HR recovery contact. Recommended
  • Start with individually assigned company devices. Email-free activation still applies; shared terminals follow only after their privacy and handover checks pass.
10

Launch markets

Which employment locations must the initial offer cover?

  • Launch with Swiss employers and explicitly agreed work locations. Add another country when customer demand and policy ownership are established. Recommended
  • Commit to a multinational launch for named customers, with each country’s working arrangements reviewed before release. This widens the launch obligations.
11

How to offer AI assistance

If the AI pilot meets its quality and cost targets, how should customers buy and adopt it?

  • Offer it as an optional add-on, enabled for participating employees. Set pricing after measuring review time saved and cost per active user. Recommended
  • Include an agreed AI allowance in the time-management package, with voluntary employee use and a margin target before broader rollout.
12

First customer pilot

Which group should prove the workflow before wider release?

  • One customer’s project team, its manager and finance contact. Confirm capture, weekly review, corrections and period handover before expanding. Recommended
  • One field team with frequent travel and weak reception. Prove mobile use and capture away from the office first, then expand to office-based teams.

Out of scope

Deliberately excluded, to keep the scope small:

  • payroll calculation and payment
  • shift and deployment planning in advance
  • pre-authorisation of weekend or holiday work
  • a time account carried across years
  • client invoicing from recorded time

Time Tracking Specification · Version 1.3 · Updated 11 September 2026. Current behavior is based on source review, not a deployment certification. Delivery criteria and AI options are proposed work. Factors are configurable product defaults; applicable employment rules must be configured separately.

Research behind the options

Primary product and guidance pages reviewed on 11 September 2026. These examples inform the proposals; they are not integrations, endorsements or evidence that Flipp already provides these capabilities.

  • Timely — Private activity timelines and employee review of AI drafts.
  • Billables AI — Draft time entries, client attribution and editable descriptions.
  • Jibble — Conversational time tracking through an assistant connection (MCP).
  • Rize — AI-tool usage and project-cost visibility; inspiration for separate agent records.
  • SECO — Working-time recording guidance: actual work and breaks need a reliable record.