Add a Coordinator Admin Without Sharing the PIN
· 5 min read
You hired a new coordinator and you want them running reports and fixing clock-outs by Monday. What you do not want is to text them the kiosk PIN, because that PIN is for the tablet on the wall, not for the dashboard. These are two different doors. Mix them up and you either hand a worker the keys to your records or make a coordinator wait on you for every export.
Here is the clean version, in the order you do it, so the new coordinator gets their own sign-in and the workers never notice a thing.
Why the kiosk PIN is not admin access
In Kangaroo Clock, workers never sign in. They tap their name on a shared tablet, scan a posted QR code, or open a personal link. No accounts, no passwords. The kiosk PIN exists for one narrow job: it stops a worker from backing out of the clock-in screen on the shared tablet and poking around in settings. It guards the tablet. It does not grant any access to your records. If you want the full picture of what that PIN does and does not cover, see how the kiosk PIN works.
Admin access is a separate thing entirely. Only admins sign in, and they do it by magic link, not a password or a PIN. So giving someone admin rights never means handing over the kiosk PIN, and changing the kiosk PIN never touches who can sign in. Keep those two facts straight and the rest is easy.
Before you invite anyone: decide what they need to touch
Write down, in one line, what the new coordinator is actually responsible for. A few common cases:
- They run one program and only need its numbers. Set up a worker group or a tag for that program first, so they can filter to exactly their people and entries.
- They cover the whole site while you are out. They need the live dashboard and the export.
- They only pull hours at month end. They mostly need the CSV export and nothing else day to day.
Naming your tags and groups before you add a second admin matters, because now two people are reading the same reports and you want them to mean the same thing to both of you. A tag called saturday-market should mean the same shift whether you pull it or they do.
Step by step: give the coordinator their own sign-in
- Sign in to your admin dashboard with your own magic link.
- Open your workspace settings and find the admins or team section.
- Add the coordinator by email address. Use the real address they check, because that is where the magic link lands.
- Tell them to watch their inbox. They click the link in the email and they are in. No password to create, nothing to remember, nothing for you to reset later.
- Have them confirm they can see the clock in activity and the live view of who is on the clock right now. If they can see that, their access is working.
That is the whole handoff. The coordinator now signs in as themselves, on their own device, with their own link. You did not share the kiosk PIN, you did not share your login, and the tablet on the wall kept running the entire time.
What the coordinator can do once they are in
With their own access, a coordinator can watch the live dashboard during an event, fix a missed clock-out, filter reports by tag or worker group, and export a CSV for payroll or a grant report. The CSV column schema stays stable, so a report they pull matches the format you have always used, including the distinct-worker count that grant funders tend to ask for.
Worth flagging so they are not surprised: a forgotten clock-out does not inflate the hours. If someone leaves without tapping out, auto-close ends the stale entry at its start time plus your cutoff, never at the current moment. So when the new coordinator opens the report Monday morning, a Friday-night miss shows a sane number, not a 60-hour shift.
One thing the coordinator cannot do, and this is by design: Kangaroo Clock is not a monitoring tool. No screenshots, no GPS, no location tracking. Admin access lets them manage time records, not watch people. Tell them that up front and it sets the right expectation with the crew too.
If the kiosk PIN leaked, rotate it separately
Say the old coordinator wrote the kiosk PIN on a sticky note and it is now floating around. Rotating it is a separate, quick job from managing admins. Change the PIN in settings, post the new one by the tablet, and done. Because the PIN only guards the shared-tablet screen, changing it does not log anyone out of the dashboard and does not break clock-in. Workers keep tapping their name as usual.
The reverse is also true. When a coordinator leaves, remove their admin access from the same team settings where you added them. Their magic link stops working. You do not need to touch the kiosk PIN at all, because they never had it as an admin to begin with.
A quick sanity check before you call it done
Walk the new coordinator through three things on their first login: pull one CSV export and confirm the columns look right, filter to their program by tag or group, and open the live view during an active shift. If all three work, they are fully set up. If you have not opened a workspace yet and you are planning this out ahead of hiring, you can start a free workspace and test the admin invite with your own second email address before anyone real needs it. The first 500 recorded hours are free, so you can get the whole access setup squared away at no cost.
Tags: admin, kiosk, access, how-to
See it in your own setup
No signup needed. Add a few names, share a kiosk URL, watch hours land.