Kiosk PIN vs Admin Sign-In: Who Gets Which
· 5 min read
Picture the tablet taped to the wall by the volunteer check-in table. Forty people tap their name on it over a shift. Now picture your phone, where you pull the hours report at the end of the week to send to payroll or a grant officer. Those are two different jobs, and they need two different keys. One is the kiosk PIN. The other is the admin sign-in. Mixing them up is how a shared tablet ends up able to edit everyone's hours.
What each key unlocks
The kiosk PIN does one thing: it opens the kiosk screen so people can clock in and out. That is the screen where a worker taps their name, or scans a posted QR code, or opens their personal link. The PIN gates the front door of attendance, nothing else. Workers themselves never enter it and never have accounts. The PIN is for the device, so the kiosk can sit unattended without someone wandering into your reports. You can read exactly how the kiosk PIN works if you want the full behavior.
The admin sign-in unlocks everything else. The live dashboard that shows who is on the clock right now. The CSV export you hand to payroll. The ability to add or edit a time entry, fix a missed clock-out, create tags and worker groups, and change billing. Admins sign in by magic link, not a password you have to remember. You enter your email, you get a link, you click it, you are in.
So the split is clean. The PIN gets you into the room where hours are recorded. The admin sign-in gets you into the room where hours are read, corrected, and exported.
Who holds each one
The kiosk PIN is meant to be shared and semi-public. It lives on a device that many people touch. A front-desk volunteer might type it in to wake the kiosk at the start of a shift. That is fine. It is a low-trust key by design, because the only thing it protects is the clock-in screen, and clock-in is the thing you want to be easy.
The admin sign-in is personal and should stay that way. It is tied to an email address, and clicking the magic link gives that person the dashboard and the exports. You do not want that floating around on a tablet by the door. If two coordinators both need the dashboard, you do not share one login. You add each person as an admin under their own email, so each has their own sign-in. That also keeps the kiosk PIN out of it entirely, which is the point.
A quick way to decide
| Question | Kiosk PIN | Admin sign-in |
|---|---|---|
| Who uses it | Anyone running the check-in device | You and your coordinators |
| What it opens | The clock-in / clock-out screen | Dashboard, exports, edits, billing |
| Where it lives | A shared tablet or posted QR | A coordinator's phone or laptop |
| How you get in | Type the PIN | Magic link sent to your email |
What happens if each one leaks
Be honest about the risk, because it is different for each key. If the kiosk PIN leaks, someone could open your clock-in screen and tap names or clock a person in or out. That can create a junk entry. It is annoying, and you would fix it in the dashboard. What it cannot do is read your reports, pull a worker list, or change your billing. The blast radius is one shift's attendance, and it is all visible and editable after the fact. If you are worried the PIN has gotten around, you change it, and the old one stops working.
If an admin sign-in leaks, the stakes are higher. That person could see every worker, export the full hours history, edit past entries, and reach billing. Because the magic link goes to an email, protecting the admin side is mostly about protecting that inbox. This is the key you guard. It is also why you never write it on the back of the tablet.
There is one more comfort worth naming, and it has nothing to do with either key. A forgotten clock-out never quietly inflates hours, because auto-close caps a stale entry at its start time plus a cutoff rather than running to the current moment. So even a chaotic kiosk does not produce a 14-hour phantom shift in your report.
Matching the key to the device
The rule of thumb writes itself once you look at the devices. A shared tablet by the door, or a QR poster on the wall, gets the kiosk PIN and only the kiosk PIN. That device should never be able to open a report. Set it up, enter the PIN, and leave it on the clock-in screen all shift. If you run on QR instead of a tablet, the QR sign-in poster generator gives you something to print and tape up.
Your phone, or your coordinator's phone, gets the admin sign-in. That is where you watch who is on the clock and pull the numbers later. Keep those two worlds separate and the whole thing stays boring in the good way: the door is easy to use, and the reports stay in trusted hands.
If you are setting this up for the first time, the fastest way to see the split is to start a free workspace, prop a tablet in kiosk mode, and keep the dashboard open on your phone. The first 500 recorded hours are free, so you can run a real event before anyone asks for a card.
Tags: kiosk, admin, security, time tracking
See it in your own setup
No signup needed. Add a few names, share a kiosk URL, watch hours land.