Biometrics and trusted devices
CheckBiz360 incorporates a biometric verification system that makes it possible to guarantee that the clock-in is being made by the right person from the right device. This layer of security is especially relevant in environments where the employee's physical presence and identity have to be established unambiguously.
This article explains how biometric validation works, what a trusted device is and how to manage both from the back office.
Biometric validation in CheckBiz360
Biometric validation is a verification step that CheckBiz360 can require from the employee before recording a clock-in. Depending on the employee's device, this verification is carried out through:
- Facial recognition (Face ID) — Available on compatible iOS devices and some Android models.
- Fingerprint — Available on devices with a built-in fingerprint sensor (Touch ID or Android equivalents).
When biometric validation is enabled for an employee, the application requests biometric authentication at the moment of clocking in. The entry or exit is only recorded if the verification succeeds.
Biometric verification required
Each employee profile includes the biometric verification required option, which determines whether biometric authentication is mandatory for that user when clocking in.
- Enabled — The employee must verify their biometric identity before every clock-in. This is the default value for all new employees.
- Disabled — The employee can clock in without additional biometric verification.
How to disable biometrics for a specific employee
There are situations where it may be necessary to disable biometric verification for a particular employee, for example when the employee's device has no biometric sensor or when there is a one-off technical issue.
To disable this requirement:
- Sign in to the back office with manager or owner credentials.
- Go to Employees and open the employee's profile.
- In the Security section, find the Biometric verification required control.
- Turn the switch off.
- Save the changes.
The change takes effect immediately. The employee will be able to clock in on their next access without needing biometric verification.
Trusted devices
CheckBiz360 controls which devices each employee can clock in from through a system of trusted devices. When an employee signs in and completes the verification process (including 2FA, if active), the system records the device's unique identifier (UUID).
Only devices registered as trusted can make clock-ins. If an employee tries to clock in from a device that is not registered, the application will show the error:
Untrusted deviceThis behaviour protects the integrity of time tracking, preventing a third party from impersonating the employee from an unauthorised device.
How to register a new device
If an employee changes device or needs to add a new phone as a trusted device, the process is as follows:
- The employee installs the CheckBiz360 application on their new device.
- They sign in with their credentials (email and password).
- If 2FA is active, they enter the verification code generated by their authenticator application.
- Once the authentication process is complete, the system automatically registers the new device as trusted.
From that moment on, the employee can clock in from the new device.
Managing devices from the back office
Managers and owners can consult and manage the trusted devices associated with each employee:
View the registered devices
- Go to the employee's profile in the back office.
- Go to the Security and devices section.
- The list of registered trusted devices is displayed, with information about the model, the operating system and the date of last access.
Revoke access for a lost or stolen device
If an employee loses their device or it is stolen, it is essential to revoke its access immediately to prevent fraudulent clock-ins:
- Go to the employee's profile in the back office.
- Go to the Security and devices section.
- Find the device you want to revoke and press Delete.
- Confirm the action.
The device is unlinked immediately. Any attempt to clock in from that device will be rejected with the "Untrusted device" error.
Who can manage these options
Managing biometric verification and trusted devices from the back office is available to the manager (level 3) and owner (level 4) roles.