All documentation

Biometric attendance

The fingerprint, face or card machine at your gate sends every punch here by itself. Children are marked in on the daily register, parents are told, staff attendance fills itself in, and names and cards go back to the machine.

Institutions9 min read
Where to find it
Biometric in the sidebar, under Campus. Three tabs: Register, Machines and People.

Overview

Your machine records each punch with the person's number and the time. Connected to tuition.in, it sends each punch as it happens (and resends anything it couldn't send while the internet was down; nothing is counted twice). You tell us once which number is which student or staff member, and the rest follows.

Which machines work

Most fingerprint, face and card machines sold to Indian schools are eSSL or ZKTeco, or rebadged versions of them (Realtime, BioMax and Identix among them). Those with a Cloud Server or ADMS setting in their communication menu can push to us directly, with no software on a computer. Cheaper "non-push" models don't have it; you can still import their punch log as a file (below).

Young children's fingerprints often don't read reliably, which is why most schools give students an RFID card or use face recognition, and keep fingerprints for staff. All three work the same way here.

Connecting a machine

  1. On the Machines tab, press Add machine. Give it a name (Main gate) and its serial number, which is on a sticker on the back and under Menu, System info, Device info.
  2. On the machine, open Menu, Comm., Cloud Server Setting (called ADMS on some models).
  3. Switch on Enable domain name, set the server address shown on the Machines tab and port 80, and leave the proxy off. If the machine has an HTTPS switch, you can turn it on and use port 443 instead.
  4. Save and restart the machine. Within a minute it shows as Connected, and its punches start arriving. The machine's card shows its last call: what it sent and what we answered, which is the first thing to look at if it doesn't connect.
Set the machine's clock to Indian time
The machine's own clock is the time we record. Check its date and time are right (Menu, System, Date/Time).

Hikvision, Matrix and the QR kiosk

When you add a machine, choose its kind first. The setup steps, with the address and secret to type in, appear once the machine is added; copy them then, because the secret isn't shown again (a new one can be made from the machine's card).

  • Hikvision face and card terminals: on the terminal's web page, under Network, Advanced, HTTP Listening, enter our address, port 80 and the URL we show. Each successful face or card match arrives as it happens; failed matches are ignored, and the photo the terminal attaches is never read or kept. A person's Employee No. on the terminal is their machine number here.
  • Matrix COSEC (beta): on the device's web page, set our address as its third-party server, with User ID tuition and the password we show. Add it by its MAC address. Each allowed entry is a punch. This is new; if it doesn't connect, the machine's last call shows what it sent.
  • QR kiosk: no machine to buy. Any Android phone or tablet at the gate opens the pairing link (or scans its QR), and students hold up the QR on their ID card. The camera reads it, or a USB or Bluetooth barcode scanner can type into it. The same card twice within two minutes counts once, and scans made while the internet is down wait on the device and are sent when it's back. A student scanned this way is given a machine number automatically.

Who each number is

Each person is enrolled on the machine under a number (its User ID). On the People tab, match each number to a student on your register or someone on your staff roster. A match applies to every punch, past and future.

  • If you enrolled students under their admission numbers, press Match by admission number and they are all matched at once (leading zeros don't matter).
  • A number punching that isn't matched yet shows on the Register tab as a machine number we don't know; click it to match it.
  • One person has one number; the same number is used on all your machines.
  • For a machine that's connected, Who's on it reads the list of people enrolled on it and suggests who each one is: a number equal to an admission number, or a name that fits exactly one person. Tick the right ones and match them in one go.
  • Starting fresh? Give everyone a number numbers every active student and staff member who has none: their admission number's digits where those are free, otherwise the next free number. A number someone already has on a machine is never handed out.
  • Each person can carry an RFID card number. Type it in the People table, or Import card numbers from the list your card vendor gave you (a spreadsheet with the card number and the admission number or machine number).

Names and cards to the machine

Send names to machines (Machines tab) puts every matched student and staff member on each connected machine, with their name and card number, so nobody types them on the keypad. Each person then only puts their finger or face on the machine once to enrol. The machine collects the names within seconds; its card shows how many are still waiting.

  • A number the machine already holds under someone else's name is left alone and reported, never overwritten, so one person's fingerprint can never start counting for another.
  • Nobody's admin rights on the machine are changed, and a card enrolled at the machine is never wiped.
  • Students and staff who have left (a TC issued, staff relieved) are listed under Who's on it; Take them off removes them, so their finger or card no longer opens the gate. Their past punches stay on record.
  • Fingerprints and faces are never copied between machines or to us: with two gates, each person enrols on each machine (or use the vendor's own copy tool).

What each machine is for

Used forWhat its punches do
Gate (the default)Mark students in on the daily register, tell parents, and count for staff
Staff onlyStaff attendance only; students aren't sent to it
Log onlyKept on record and nothing more: a library, hostel or bus machine

The day's register

The Register tab shows a day (today, or any day before):

  • Students in order of arrival with their first punch, marked late if after your start time plus grace, and a list of those with no punch yet.
  • Staff with their first punch in, last punch out, hours between, and whether that is a full or half day.
  • Totals: students in, late, staff in, and the number of punches.

Each punch at a gate machine also marks the student in on the daily class register (Daily Attendance under Campus) as it arrives: present, or late after your start time plus grace. A mark a teacher made by hand is never changed. Mark attendance from the gate re-runs this for a past day or after a punch file.

No punch is not the same as absent
A student may have come in when the machine was busy, or through another gate. The register shows who punched; class teachers still mark the rest. The machine never marks anyone absent unless you set an absence cut-off (Day rules).

Parents' messages

When a child punches in at a gate machine, their linked parents are told in the app: "Aarav reached school", came in through the gate at 7:52 am. When they go out, "Aarav left school": a punch after the time school ends (Day rules), or on the machine's check-out key, at least half an hour after arriving.

  • Once each per child per day, however often they tap or the machine resends its log.
  • Only for punches that arrive as they happen: a machine catching up after a power cut tells nobody anything.
  • Parents reach their child through the child's account; a child without one has no linked parent yet. Parents can mute these messages.
  • Switch them off for the whole school under Day rules and parents' messages.

WhatsApp or SMS for families not in the app. A child with no account, or no parent linked to it, can still be covered: switch on WhatsApp or SMS for families not in the app and the guardian's phone on the student register gets the same messages. Choose which ones (reached school, left school, marked absent) and a monthly limit. Each message is charged to the school, the screen shows how many have gone this month, and nothing more is sent once the limit is reached. A family that can be reached in the app never gets a paid message.

Staff attendance

As punches arrive, each matched staff member's day on the Staff attendance register fills itself in, with a note like Biometric: in 07:58, out 16:40:

PunchesMarked
In and out at least your full-day hours apart (6 by default)Present
In and out, fewer hoursHalf day
A single punch (arrived, didn't punch out)Present
No punchNothing: left for you to mark

A day you marked by hand (leave, say) is never overwritten by the machine. Update staff attendance on the Register tab brings a past day up to date if you matched numbers afterwards.

Class attendance from the gate

Mark class attendance from the gate uses the day's punches to mark attendance in that day's classes: each student who punched in is marked present in their batches' classes, or late for a class that had already started (plus your grace) when they punched. Classes that ended before they arrived are left alone, as are classes a teacher has already marked for them. Students with no punch stay unmarked. This needs the student to have an account and be enrolled in the batch; students without an account are counted and skipped.

Day rules

Under Day rules and parents' messages on the Register tab: when the school day starts (08:00 by default), the grace minutes before a student counts as late (10), when school ends (for "left school" messages; empty means only the check-out key counts), the hours for a full staff day (6), and whether parents are told at all.

Absent if no punch by (empty by default): set a time, say 09:30, and after it every student with a machine number who hasn't punched and isn't yet marked is marked absent, and their family is told. Families who can't be reached come back as a list to phone. It does nothing on Sundays, and nothing for a school whose gate machines sent no punch at all that day: a dead machine isn't a school full of absentees. It runs by itself every 15 minutes in the morning; Run it now does it at once.

When something's wrong

  • Silent: a gate or staff machine not heard from for 15 minutes during the school day is flagged on its card, on the daily register and on the Group Dashboard. Usually the power or the internet; nothing is lost, and the machine sends its log when it's back.
  • Clock: if a machine's clock has drifted, its card says by how much ("7 min fast, so punches read 7 min late"). Set it right on the machine (Menu, System, Date/Time). Punches dated more than 30 minutes ahead are refused, so a wrong clock can't put them on the wrong day.
  • Wrong protocol: if the last call says the machine asked for "registry", it's set to ZKTeco's access-control protocol; switch it to attendance push (ADMS) in its Cloud Server settings.

Other machines and files

  • Import a punch file (Machines tab): the attendance log exported from eSSL eTimeTrack, ZKTeco ZKTime or a spreadsheet, as a CSV with a person-number column and either a date/time column or separate date and time columns (12- or 24-hour). Punches already here are skipped, so importing the same file twice is harmless.
  • Webhook: for other machines, RFID gate software or your own system, add a machine of the kind Other (webhook) and send punches as JSON with its token. Each punch names the person by machine number, RFID card number, or the QR code on their ID card. The token is shown once; a new one replaces it.

Security

eSSL and ZKTeco machines identify themselves only by their serial number; their protocol has no password. We accept punches only from serial numbers you have added, only for your account, and a serial number can belong to one account only. Hikvision terminals, Matrix devices, kiosks and webhooks prove who they are with a secret that is shown once and stored only as a fingerprint; making a new one stops the old one working. ID-card QR codes are signed, so a made-up or altered code is refused. You can switch a machine off, and its punches are ignored.

Questions

Do you store fingerprints or faces? No. The machine keeps its fingerprint and face templates; we never ask for them, and if a machine sends them anyway they are dropped unread. We keep the person's number, name and card number, and the time of each punch.

We have two gates. Add both machines. Punches from either count for the same person.

The machine shows "last seen" hours ago. It has lost its internet connection or its server setting. Its punches are kept on the machine and arrive when it reconnects.


Header Logo