How do I set up the terminal and how is time clocked on it?
The device signs in with a short code, and management or HR confirms the pairing in the browser. After that every person is assigned a card. At the device, holding the card up is enough: an arrival and a departure produce a time entry in the same time account as the browser and the app. The device reads no biometric data.
As at:September 2026
Pairing the device
Pairing deliberately runs in two steps and across two devices. When signing in, the terminal names no business, it only names a short code. The affiliation only comes about when someone confirms it in the browser. A device switched on somewhere therefore belongs to nobody.
- Switch the device on. It signs in and shows a short code on the screen.
- In the browser, under the terminal settings, confirm the pending pairing with that short code. Management and HR are allowed to do this.
- The device polls periodically and receives its credentials with the confirmation. From then on it may send bookings.
- Set the reader variant of the device. The same card is read differently depending on the reader design installed, and without the right setting the numbers do not match up.
- If needed, set the idle behaviour and the appearance: after how long the screen dims and when it switches off entirely.
Assigning cards
A card belongs to exactly one person. Two routes lead there, and the second saves typing.
- Either enter the card number in the card overview and assign it to the person.
- Or hold the card up at the device once. It then appears among the unknown read attempts and is assigned to a person from there.
- Check the assignment. The overview shows all cards of the business, the cards per person, and the people who can still be assigned one.
- A lost card is blocked. After that it no longer clocks and gives no balance information either.
- An assignment can be removed entirely; the card is then unknown to the business.
- Unknown read attempts collect with a counter in their own tab and deliberately trigger no notification. They are already where they get dealt with.
How clocking works at the device
Hold the card up, done. The device sends arrivals and departures to the server as a signed, consecutively chained sequence, and the server checks the signature, the sequence number and the link to the previous booking before saving. A booking inserted or altered after the fact therefore stands out.
As soon as a departure closes a segment, a time entry is created in time tracking. The terminal route therefore feeds the same time accounts as the browser and the app; there is no second set of books alongside.
Anyone holding up their card sees their first name and their own time account balance at the device. The device shows no other people's balances.
When a booking does not work out
Not every booking produces recorded time by itself. Anyone who forgets to clock out leaves an open segment. A daily run writes up closed pairs that do not yet have a time entry, and reports the open segments.
Open segments are expressly not closed automatically. An invented end time would look like a measurement, and that is exactly what time tracking must not produce. Such cases collect as cases needing clarification instead: the booking is saved, it needs a decision.
The number of open cases needing clarification is reported at most once a day to management and HR, and only on the bell inside the application, without push and without email.
The steps here describe a running system. Anyone who does not have one yet sets it up during the trial and keeps everything created along the way.
Keeping devices running
The device checks in regularly. Its state in the device list comes out of that, and that is how it is recognised when it stays silent for too long. The notification about it names the number of silent devices, not the individual device, and it is the only terminal finding that additionally triggers an email.
The server classifies anomalies itself: invalid signature, a gap or a jump backwards in the sequence number, a broken chain, a foreign affiliation, a time deviation, an unknown, blocked or ambiguous card. Of those, only what somebody can fix and what would not reach them by any other route is reported.
Three operations that are easily confused. They do different things.
| Operation | What applies afterwards | When it fits |
|---|---|---|
| Block the device | The device accepts no more bookings but stays in the list with its history. | Suspicion, repair, temporary shutdown. |
| Unpair | The binding to the business is lifted and the device can be paired again. | Moving to another site, or a fresh setup. |
| Archive the device | It disappears from the active list, and its bookings are preserved. | Decommissioning. Old times have to stay traceable. |
Block the device
- What applies afterwards
- The device accepts no more bookings but stays in the list with its history.
- When it fits
- Suspicion, repair, temporary shutdown.
Unpair
- What applies afterwards
- The binding to the business is lifted and the device can be paired again.
- When it fits
- Moving to another site, or a fresh setup.
Archive the device
- What applies afterwards
- It disappears from the active list, and its bookings are preserved.
- When it fits
- Decommissioning. Old times have to stay traceable.
Maintenance at the device
The maintenance area at the device only opens with two things at once: a card whose person carries the matching role, and the stored PIN. The list of roles for it is the same as in administration in the browser, so that the two do not drift apart. Administration can see how many cards can open this access.
If a device is without a network, there is a second route via support: a dedicated page generates an eight-digit code from a first name and a one-time password. That page shows no business data and opens no access to the application.
What the terminal does not do
It reads no biometric data. No fingerprint, no facial image. The card is a means of recognition and not proof of identity, which is why nothing hangs on it beyond clocking and one's own balance information.
It does not replace the other routes. Browser, app and terminal can be mixed within the same business, and nobody has to use a private device in order to have their time recorded.
Follow-up questions
- Do we need a separate card for every person?
- Yes, a card belongs to exactly one person. It can be assigned via the card number or, more conveniently, by holding it up at the device once and then assigning it from the unknown read attempts.
- What happens if the device has no network?
- The device fetches the card inventory in advance, so that it can decide which card is known even without a connection. For the case where a device has to be unlocked without a network, there is a code available via support.
- Somebody forgot to clock out. What now?
- The segment stays open and is reported as a case needing clarification. It is not closed automatically, because a set end time would look like a genuine measurement. Administration makes the decision, and the correction then runs through time tracking.
- Can anyone see other people's times at the device?
- No. Anyone holding up their card sees their first name and their own time account balance. Who is currently on site is something management and HR see in the application, not at the device.
- How many devices can a business pair?
- The number is not limited. Every device is paired individually, carries its own reader variant and appears with its state in the device list.
Describes the state of the application onSeptember 2026. What changes in the product is in the product updates.
Published by: AMNAU GmbH
Editorial responsibility: Ugur Aydogan, Product development.
Last reviewed: September 2026
Reading up is one thing. Setting it up yourself takes an afternoon.
MetronHR records working time at the terminal, in the app and in the browser, keeps holiday and overtime up to date and files the month ready to go. Try it free for 14 days.
No credit card, cancel at any time