Work with a due date and no slot is the work that goes late.
A planboard for HSE work — onto lanes, against shifts, on the site’s own clock. And it will not hand today’s jobs to somebody attendance says is not there.
A location is recorded at the moment of a punch, against a site that worker is permitted to clock at. Nothing is recorded between punches — the boundary, in full.

The question a roster never has to answer.
Every corrective action, inspection and investigation on this site already has an owner and a date. None of that says when, and a backlog of owned work with no hours against it is a backlog that gets discovered at the deadline.
And there is a worse version. A job planned onto somebody who is not on site today is not planned — it is a rectangle on a lane, and it will be re-planned in a hurry by whoever notices first, which is usually nobody until it is late.
In an evacuation, the roll call is a list printed this morning. The rest of the week, it is the answer to a quieter question: is the person I just gave this job to actually here?
18:49 at the Houston plant. Twelve on the roster, four on site.
The roster is a plan. The site is a fact. Most weeks nobody needs the difference, and the week somebody does, it is the only number that matters.
| Shift | Window | Rostered | On site | What the record says |
|---|---|---|---|---|
| Day shift | 07:00–16:00 | 3 | 0 on site | Punched in between 06:52 and 07:09, out between 16:00 and 16:11. Gone. |
| Office hours | 08:00–17:00 | 2 | 0 on site | Out at 17:01 and 17:06. Gone. |
| Back shift | 15:00–23:00 | 6 | 4 on site | One arrived at 15:24 and is flagged late against a ten-minute grace. One checked out at 17:40. One never checked in and was marked absent by the sweep. |
| Night shift | 23:00–07:00 | 1 | 0 on site | Their shift has not started, so they have no record yet — and that is correct, not missing. |
Illustrative data — not a customer. The roster says 12. The site says 4. The night lane’s zero is correct rather than missing — their shift has not started.
Day shift
07:00–16:00
- Paid
- 8h 15m
- Break
- 45m
- Days off
- Sat, Sun
Office hours
08:00–17:00
- Paid
- 8h 00m
- Break
- 60m
- Days off
- Sat, Sun
Back shift
15:00–23:00
- Paid
- 7h 30m
- Break
- 30m
- Days off
- Sun
Night shift
23:00–07:00
- Paid
- 7h 30m
- Break
- 30m
- Days off
- Fri, Sat
A shift that crosses midnight is one shift
This is the question to put to every vendor you are talking to, including us.
Almost every system that measures lateness compares the punch against today’s date plus the shift’s start hour. For a 07:00 start that works perfectly. For a 23:00 start it stops working the moment the clock passes midnight — the comparison is against a start twenty hours in the future, the arithmetic goes negative, and the result gets clamped to zero.
end − start
−16h 30m
What the naive comparison produces for 23:00–07:00. A negative shift length, clamped to zero on the way to the screen.
attributed to the night that started
7h 30m
The same window, read as one shift. Break removed, hours booked to the night rather than the calendar day showing on the wall.
The consequence is not an edge case. It means nobody on nights is ever late, however late they are. It usually means nobody on nights is ever marked absent either, because the cutoff lands at a time of day the clock never reaches. And it means a night worker cannot check out — at midnight the record they checked into stops being found, so the app offers them Check In again, opens a second record for the same night, and their hours are never computed at all.
The way to test it is not to read a datasheet. Ask somebody to punch in at 03:00, then ask them to punch out.
A point at the punch. Nothing in between.
An IT manager will ask this, and so will a union. The honest answer is a selling point, so it is on the page rather than in an appendix.
- 01
A worker may only clock at sites an admin has put on their own list.
- 02
The check-in button enables inside the geofence and not outside it.
- 03
The record keeps the coordinates of the punch, and the site they resolved to.
- 04
Between punches, the platform records nothing. There is no trail.
That boundary is deliberate. It is enough to know who is on which site, which is the safety question, and it is not enough to follow anybody around, which is not.
Everything with a date and no slot, in one column
Drag it onto a lane, or let the board place it. Either way the estimate arrives with the job rather than after a planning meeting.
Unplanned · 7 jobs · 10h 30m to place
- #54Sprinkler head damaged by a raised forklift mastFire120m estSLA 10% spentHigh
- #52Panel door opened on a live starter cabinetElectrical / Arc Flash120m estSLA 10% spentHigh
- #55Delivery driver entered the yard without a hi-visProperty Damage90m estSLA 14% spentMedium
- #50Eye irritation after grinding without a face shieldOccupational Health90m estSLA 14% spentMedium
- #51Diesel sheen observed on the yard drainEnvironmental Release90m estSLA 14% spentMedium
- #53Emergency SOS raised in error from the field appEmergency SOS60m estSLA 21% spentLow
- #49Overfilled skip released debris in the yardProperty Damage60m estSLA 21% spentLow
Illustrative data — not a customer. The estimate ladders with severity, and the Lows have spent the most of their window because their window is the longest. Both of those are easy to get the wrong way round.
The slot has to fit inside their shift
Opening #53 on a lane shows that person’s next ten working days, and inside the chosen day, the hours they are actually available — with everything already booked, and everything outside their shift, drawn as unavailable rather than merely discouraged.
Emergency SOS raised in error from the field app is estimated at 60 minutes, so the board offers Tue, Aug 11, 18:30 → 19:30. One click places it, and the lane, the person’s phone and the capacity figures all move together.

One board, three questions
Who does what, when it happens, and whether the week was possible in the first place.
Board
Columns per person, cards per job, and an Unplanned column at the left holding everything with a date and no slot. This is the view for deciding who does what.
Timeline
Lanes against a clock, with each person’s shift drawn behind their jobs. Day off, annual leave and business trip are painted on the lane, so a slot cannot be argued into a day somebody is not working.
Reports
Assigned against unassigned, SLA status, and worked time against capacity — with the idle gaps named per person rather than averaged into a number nobody can act on.


Screenshots from a working build. Illustrative records — not a customer.
Three settings, and one that is not a setting
How far the planner trusts attendance when it hands out today’s work.
| Setting | What the planner does |
|---|---|
| Ignore attendance | Plans against the roster only. |
| Skip absent and checked outdefault | Refuses today’s work to anyone with a record saying absent, or a check-out that has already happened. |
| Require check-in | Also refuses anyone who has not punched in — but only once their shift has started. |
And one that is not a setting: approved leave always blocks
In every mode, including Ignore attendance. Leave is a decision your managers made after weighing who carries the gap; it is not a planner preference and the board does not get a vote on it.
The default refuses only on positive evidence
Skip absent and checked out means a record that says absent, or a check-out that has already happened. No record at all is a question, not a verdict — treating silence as absence would stop the board dead on any site that has shifts configured and has not finished rolling check-in out.
And a refusal says which
- Can’t schedule — Nicole Hayes is marked absent today.
- Can’t schedule — Emily Carver has already checked out today.
- Can’t schedule — Derek Coleman is on approved leave that day.
Approving leave gives the work back
A request routes to the managers of the groups the requester belongs to. It is approved only when every approver agrees, rejected the moment one declines, and nobody approves their own — whatever their role.
Then the part most systems skip. Leave is requested after the week is planned, because that is the order things happen in. So on approval, the HSE work already booked inside that window is released back to Unplanned — keeping its owner, so nothing loses custody — and the planner is told how much came back. Approving time off should not quietly leave four jobs standing on an empty lane.
Arrives, to recorded
Eight steps, and two of them are the ones where somebody does not turn up.
- 01
Arrives
Opens the app inside the geofence and checks in. The punch keeps a point and the site it resolved to — nothing before it, nothing after it.
- 02
Measured
Lateness against their own shift and their own grace window, not a single site-wide start time that suits nobody on back shift.
- 03
Visible
Their lane shows them on shift, and the live per-location list shows them present. That list is the roll call, kept live rather than printed at 07:00.
- 04
Given work
The planner can hand them today’s jobs, because they are here. Somebody who is not here is refused, with the reason named.
- 05
Leaves
Checks out, and minutes worked are computed from their own check-in — across midnight if that is when their shift ran.
- 06
Or does not arrive
A sweep raises Absent at shift start plus the cutoff you choose. Not at a fixed hour, and not from silence alone before the cutoff.
- 07
Or is on leave
No absence flag, no new work, and the work already booked in that window comes back to Unplanned keeping its owner.
- 08
Recorded
One row per person per day — in, out, minutes worked, lateness, the site the punch resolved to, and a note. Exportable, and in the audit trail on the site’s clock.

The same slots, on the phone that does the work
A supervisor does not open a planboard. They open their own list, and it carries what the planner placed — same jobs, same times, same order — so nobody has to translate a lane into a day.
Their own shift and their own attendance history sit beside it. That matters more than it sounds: a worker who can see their own lateness record is a worker who can dispute it, which is the difference between a measurement and a rumour.
What an auditor asks, and what you hand them
Clause by clause, the record this module produces — not a claim that it makes you compliant.
| Clause | What it asks for | What the schedule hands over |
|---|---|---|
| 5.4 | Consultation & participation of workers | Leave requested and decided in the app the worker already carries |
| 7.2 / 7.3 | Competence & awareness | Work restricted to rostered staff, permitted for the site they are standing on |
| 7.5 | Documented information | One attributed record per person per day, exportable |
| 8.1.4 | Procurement & contractors | Contractors clock only at the sites their own allow-list permits |
| 8.2 | Emergency preparedness & response | A live, per-location list of who is checked in — the roll call, not this morning’s printout |
| 9.1 | Monitoring, measurement & analysis | Lateness and absence carried as leading indicators, with their base |
5.4
Consultation & participation of workers
What the schedule hands over
Leave requested and decided in the app the worker already carries
7.2 / 7.3
Competence & awareness
What the schedule hands over
Work restricted to rostered staff, permitted for the site they are standing on
7.5
Documented information
What the schedule hands over
One attributed record per person per day, exportable
8.1.4
Procurement & contractors
What the schedule hands over
Contractors clock only at the sites their own allow-list permits
8.2
Emergency preparedness & response
What the schedule hands over
A live, per-location list of who is checked in — the roll call, not this morning’s printout
9.1
Monitoring, measurement & analysis
What the schedule hands over
Lateness and absence carried as leading indicators, with their base
Sentinel supports evidencing these requirements. Certification is an audit of your organisation, not of software — no product can be bought to pass one. And this is not a payroll system: it records presence for safety, and the record exports if payroll wants it.
The eight things you are already thinking
No. It records presence for safety — who is on which site, and whether the person you just handed a job to is actually there. The record exports if payroll wants it, and plenty of sites do exactly that, but nothing here computes pay and nothing here should be bought as if it did.
A GPS point at the punch, and the site that point resolved to. Nothing between punches — there is no trail, because none is recorded. That boundary is deliberate: it is enough to know who is on which site, which is the safety question, and not enough to follow anybody around, which is not.
A 23:00–07:00 shift is one shift, and the hours after midnight are attributed to the night that started rather than the calendar day showing. Put this to every vendor you are talking to, including us, and test it the same way: ask somebody to punch in at 03:00 and see whether they can punch out.
The record stays open and shows that it is open, rather than guessing an end time. They can check back in after a mistaken check-out, but only while the shift is still running — after that it is a correction with a name against it, not a silent edit.
They clock on their own device, against the sites you have permitted them — the same per-worker allow-list everybody else uses. A contractor who is not on the list for that site cannot clock at it, which is the point.
No. The default is on and cautious — skip absent and checked out — and you can set it to ignore attendance entirely. What you cannot switch off is approved leave, which blocks in every mode, because that is a decision your managers made rather than a planner preference.
Then the board carries on. No record at all is a question, not a verdict — treating silence as absence would stop planning dead on any site that has shifts configured and has not finished rolling check-in out. The default refuses only on positive evidence: a record that says absent, or a check-out that has already happened.
Yes, including on your own infrastructure. Permissions are granular — view, create, update and delete — and every change is attributed in the audit trail on the site’s own clock.
See it on your own shift pattern.
Send us your shifts — windows, breaks, days off — and your sites. We will set them up and show you what your roll call looks like at 3 AM.
Forty-five minutes, your scenarios, no slides.