Another Check-In · C01

Account access

31 minutes, including guided practice · 17 slides

Lesson video coming soon. The player below contains a sample video, not this lesson. You can use the written lesson and slide guide now.

Open video on YouTube ↗

Download slide guide (PDF)17 pages · 6.6 MB

Work through the lesson

Use these explanations alongside the slide guide. Expand any section to read its full explanation.

Your goals

  • Sign in using your approved method
  • Find a task you are allowed to use
  • Get help and sign out

A successful session
Your own account
The correct task
A deliberate sign-out

Read the full explanation

There are three things we are going to practise. First, sign in using the method your organization has prepared for you. Second, find a task your account is allowed to perform. Third, find help and sign out when you finish. Success is more than seeing a welcome page. You should recognize your account and know why a particular task is available to you. If your task is missing, that is a reason to check your access with the responsible person, not a reason to borrow someone else's account. Keep these three goals in mind because our practice at the end follows the same sequence.

Account and device identity

  • Your account controls access to pages
  • Your Staff ID links attendance to you
  • Enrollment authorizes a browser for attendance

Keep these separate
Signing in does not enroll a browser.

An enrollment token is not your account password.

Read the full explanation

The application uses several kinds of identity, and it is easy to mix them up. Your account is the identity you use to sign in and open permitted pages. Your Staff ID identifies the employee whose attendance is being recorded. Browser enrollment prepares an authorized browser to provide device proof for attendance. These are related, but completing one step does not automatically complete the others. For example, you may be able to sign in and still need an enrollment token before that browser can perform a device-based check-in. The reverse is also possible: ordinary attendance from an enrolled browser does not necessarily require an account session. Staff QR workflows can require sign-in. Today, our task is account access.

Password sign-in

  • Open the approved HTTPS address
  • Enter your email and password
  • Add the authenticator code if enabled
Read the full explanation

Begin at the approved application address and choose Sign In. Check the address before entering your credentials. Enter the email associated with your issued account and your password. The form also has an authenticator-code field. Use it when two-factor authentication is enabled for your account; it is not a second password that everyone invents. Select Sign In once and read the result. If the details are rejected, check what you entered rather than repeatedly guessing. If you are directed to complete security setup before privileged work, follow your organization's setup instructions. Do not bypass a certificate warning or change security settings merely to make the sign-in demonstration work.

Passkey sign-in

  • Use a passkey already registered to your account
  • Enter your email first
  • Follow the device's sign-in prompt
Read the full explanation

A passkey is another sign-in method when your account already has one registered and your device supports the configured workflow. On this screen, enter your email first, then choose Sign In With Passkey. Your browser or device will guide you through its verification prompt. The prompt can differ between devices, so follow the approved setup for the device you are using. Clicking the passkey sign-in button does not create a new passkey for you. Registration is managed in Profile Security when you are authorized to do so. If a passkey is unavailable, use your organization's approved recovery or alternate sign-in method. Do not register a personal credential on a shared training device just to get through this exercise.

Your starting page

  • Successful sign-in opens an authorized page
  • Different roles can start in different places
  • Complete required security setup first

Default examples
Staff → Dashboard

Auditor → Audit

Account security admin → Audit

Read the full explanation

A successful sign-in does not mean everyone sees the same dashboard. The application chooses a permitted starting page. For example, a default staff account with check-in viewing permission normally reaches Dashboard. The auditor and account security administrator presets can start at Audit because they have audit permission without ordinary dashboard access. These are examples of the current default behavior, not a promise about every custom account. A valid return link can take you back to the requested workflow, and an account that needs security setup can be directed there first. The important check is that you recognize the account and can reach the work assigned to you. A different starting page is not, by itself, a failed sign-in.

Finding your work

  • Open the menu for your assigned task
  • Use your account menu for Profile Security
  • Ask about missing access; do not share accounts

Menu examples
Work: My Check-ins

Admin: permitted administration

Account: Profile Security

Read the full explanation

Once you are signed in, look for the task rather than trying to memorize every menu item. The Work menu can include My Check-ins and other duties your account permits. Administrative choices appear only for the relevant permissions. Your account menu contains Profile Security when it is available to your account, and it also provides Sign Out. Some menus are grouped differently on a phone, so open the mobile menu if you do not see the desktop arrangement. If a colleague has a button that you do not have, first confirm that you are using your own account and that the task belongs to your role. Ask the responsible administrator to review access. Do not use another person's sign-in or request blanket administrator access as a shortcut.

Profile Security

  • Review the security options available to you
  • Protect passwords, setup secrets and codes
  • Follow the approved device-replacement process

Account controls
Password
Passkeys
Two-Factor Authentication

Device history and replacement

Read the full explanation

Profile Security brings together several account and device controls. You will see sections for passwords, passkeys and two-factor authentication, along with device information and replacement requests. Available actions can depend on your account permissions and the deployment. Learn where these controls are before you need recovery. When setting up an authenticator or registering a passkey, follow the approved instructions and keep the secret material private. A photograph of an authenticator setup screen can expose information that should never appear in a lesson recording. If a phone or browser is lost or replaced, use the proper replacement process instead of treating another person's device as your own. We will practise the enrollment and replacement workflow in the next lesson.

Authenticator setup

  • Profile Security opens the required setup tab
  • Start 2FA Setup prepares your key
  • Scan the QR or use the manual key

Keep setup private
Use your own authenticator.

Keep the QR and setup key off recordings.

Read the full explanation

Some privileged accounts must complete security setup before administrative work. The current application takes you to the Two-Factor Authentication tab in Profile Security. Start 2FA Setup prepares a QR code and manual setup key. Use your own approved authenticator to scan the QR, or enter the manual key if scanning is unavailable. Treat both forms as a credential. Anyone who obtains that key can reproduce its codes. Keep the screen private during setup and do not send the key to a trainer or put it in a lesson recording. Starting setup alone does not enable two-factor authentication.

Setup confirmation

  • Enter the current six-digit code
  • Choose Enable 2FA
  • Check the enabled status

A rejected code
Check the account and current code.

Restarting setup invalidates the unconfirmed key.

Read the full explanation

After adding the account to your authenticator, use its current six-digit code and choose Enable 2FA. Read the result and check that the application says authentication is enabled. If the code is invalid, check that you selected the correct authenticator account and entered its current code. The manual key is different from the six-digit code. Restart with a New Key creates a different pending setup, so the earlier unconfirmed key and QR no longer complete that setup. If you restart, use the newly displayed setup information in your authenticator. Ask support when you cannot complete the approved process instead of disabling security to continue.

Authenticator replacement

  • Set Up a Replacement starts the change
  • The current authenticator stays active
  • Confirm Replacement verifies the new one

Before you retire the old app
Verify the replacement first.

Follow your organization’s recovery procedure if the old authenticator is lost.

Read the full explanation

When authentication is already enabled, Profile Security offers Set Up a Replacement. The current authenticator remains active while you prepare and verify the replacement. Add the new setup privately and use its code with Confirm Replacement. Check the result before retiring the old authenticator. This protects continuity during a planned change, but it does not provide a way around sign-in when the only working authenticator has been lost. In that situation, follow the organization’s account recovery process. Do not share a colleague’s code or disable two-factor authentication just to complete a demonstration.

Password recovery

  • Choose Forgot password? on the sign-in page
  • Enter your account email
  • Use the reset instructions or contact support

Read the response carefully
A generic confirmation does not confirm that an account exists.

Keep reset links private.

Read the full explanation

If you have forgotten your password, use Forgot password on the sign-in page and enter your account email. The application gives a generic confirmation so that the response does not reveal whether an email address belongs to an account. That message is not proof that a message reached your inbox. Check the approved mailbox and junk folder, and follow the instructions if they arrive. Delivery depends on the organization's mail setup. If the message does not arrive, or a link is invalid or expired, contact the designated support person. Keep the reset link private and do not forward it to a trainer. After a successful reset, sign in using the new password. This workflow does not promise an SMS message.

Help and support

  • Open Help and search for the task
  • Read the guidance available to your account
  • Report the problem without sharing secrets

A useful support report
Task you were attempting
Time and device/browser
Exact error message
A safe, cropped screenshot

Read the full explanation

Help is available from the application navigation. The current Help page lets you search the guidance available to your account, so start with a short task word such as passkey or password. Restricted topics and links are filtered, which means another role can see different help content. If you still need assistance, explain what you were trying to do, when it happened, which browser or device you used, and the exact message you saw. A carefully cropped screenshot can help, provided it does not expose a password, code, reset link or another person's information. For attendance problems, do not clear browser data as a first troubleshooting step: pending evidence may still be stored there. Ask support for the correct recovery path.

Sign out when finished

  • Open your account menu
  • Select Sign Out
  • Confirm the session has ended

Before you leave
Closing a tab is not a reliable sign-out procedure.

Use Sign Out on shared devices.

Read the full explanation

When you have finished, open your account menu and choose Sign Out. Do not rely on closing a browser tab as your sign-out procedure, especially on a shared device. After signing out, confirm that the application is no longer showing an active account session. For our practice, we will confirm that returning to a protected page requires sign-in. Signing out of the account should not be confused with revoking an enrolled attendance device. Likewise, clearing the browser's data is not a substitute for Sign Out and can interfere with stored attendance information. If the session does not appear to end as expected, stop using the shared device for further work and report the problem through the approved support channel.

Guided practice

  • Sign in with your training account
  • Find your assigned task and Help
  • Locate Profile Security, then sign out

Show your result
Name the task you can use.

Name one task outside your role.

Confirm sign-out.

Read the full explanation

Now it is your turn. Use the approved training account and application address. Sign in using the method that has already been prepared for you. Find one task assigned to your role and explain why it is relevant to your work. Next, open Help and locate guidance for an account question. Find Profile Security if your account is permitted to use it, but do not change credentials or device settings for this exercise. Before finishing, identify one task outside your role and tell me who you would contact if your duties required it. Finally, sign out and confirm the result. I am looking for correct access and safe decisions, not for speed. If your environment is not ready, talk me through the steps using these slides.

Check your understanding

  • You signed in. Is your browser now enrolled?
  • Your colleague sees more menu items. What next?
  • No reset email arrives. What should you do?

Explain your next step
Keep your own identity.

Respect the role boundary.

Use approved recovery.

Read the full explanation

Let us check the three decisions most likely to cause confusion. First, you have signed in successfully. Does that prove the browser is enrolled for attendance? No. Account sign-in and browser enrollment are separate processes. Second, your colleague has more menu items. What should you do? Confirm your own account and assigned task, then ask for an access review if the task is part of your duties. Do not borrow their account. Third, you request a password reset but receive no email. What is the safe response? Check the approved mailbox and junk folder, then contact support. The generic confirmation does not guarantee delivery or reveal whether the account exists. Explain these answers in your own words before moving on.

Ready for your next task

  • Use your own approved sign-in method
  • Work within your assigned permissions
  • Find help and sign out deliberately

Next lesson · C02
Enroll the correct browser
and request a replacement

Read the full explanation

You now have a repeatable account-access routine. Use your own approved sign-in method, check that you can reach your assigned work, and know where Help and Profile Security are located. When you finish, sign out deliberately. If something differs from the example, look at your actual account, permissions and deployment rather than assuming every person should see the same screen. In the next lesson, we will move from account access to browser enrollment. That is where we will examine the enrollment token, confirm the correct employee and browser, and explain the replacement request when a device changes. Keep the distinction between account identity and device identity clear as we continue.