Tap your card. Your own workspace opens.
One tablet by the door, a card on it for everyone. Tap yours, type your PIN, and what loads is your workspace — your modules, in your language, with the shift you are on already counting. This is the screen Structa was built around, and it is why nobody has to be trained on it.
Staff, Scheduling and Time clock are modules the owner switches on. The announcements board and team chat are not modules — there is nothing to enable and nothing extra to pay.
The screen a shift starts on
The owner activates a tablet once. From then on, whenever that device is signed out, the card screen stands where the password form used to be — and with the time clock on, the card screen is the clock as well.
- 01
The owner activates the device
Manage business → Devices & security, one tap on the tablet itself. That device keeps a token; the database keeps only a hash of it. Revoke it from anywhere and that tablet stops working the moment anyone touches it — the tap, the PIN and the badge scan all carry the token and the server refuses them — while the card screen itself falls back to the password form at its next check, which it makes every sixty seconds. Every activated device is listed with the name of whoever activated it.
- 02
Every active employee gets a card
What opens it is a four-to-six digit PIN each person sets in My account; a manager can set a temporary one to get somebody started, and that card then says so on its face. Five wrong PINs in ten minutes lock that one card while the rest of the team keeps working, and every attempt is recorded, right or wrong.
- 03
A tap opens the workspace, or the clock
With the clock on, tapping a card asks which of the two you meant; with it off, a tap goes straight to signing in. Clocking never signs the tablet in — the card lights up, a line says since when, and the screen stays put for the next person. Signing in loads that person’s own workspace and nobody else’s.
However you clock in, the timesheet writes itself
Every punch records how the person proved who they were, and the export carries that as a column — so payroll can tell a typed PIN from a scanned badge from a signed-in tap from a manager’s correction.
A PIN at the door
Tap your card, type your PIN on a pad built for a thumb. The card lights and reads “on shift since 9:02”; tap again to clock out and it tells you how long you worked. The same screen lives inside the workspace, for a tablet that stays signed in.
A QR badge on your own phone
Your badge is a QR code in My account that re-mints itself every minute, so a photograph of it is dead before it can travel. Show it to the tablet’s camera and the punch lands without typing. Lost the phone: re-issue the badge yourself, and every copy of the old one stops scanning.
The badge in Apple Wallet
The same badge goes into Apple Wallet, so an iPhone can show it without opening Structa at all. Nobody can reach into a phone and delete a pass, so re-issuing is what kills it: the old pass fails at the next scan, on every device at once.
One tap from your own screen
Already signed in? Your dashboard clocks you in and out with one tap and no PIN — the session is already proof of who you are. It then shows the shift running: “on shift since 9:04 · 3h 12m”.
The timesheet nobody types
A manager’s week, built from the punches, with open shifts counting up live. Export it as a CSV: one row per punch, decimal hours, and a cost column once hourly wages are set. The team’s hours stay manager-only; your own screen shows the shift you are on.
- Late
- The first punch came more than five minutes after the shift was due to start. The cell carries the number of minutes.
- No-show
- A scheduled shift with no punch anywhere near it. Raised only for somebody who used the clock elsewhere that week, so a business that tracks hours off-clock never lights up red.
- Overtime
- The week ran past forty hours. It is a mark on a total, not a pay calculation — overtime rules differ by state and by employee, and inventing one would be worse than saying nothing.
- Forgotten clock-out
- A shift still open after sixteen hours gets a list of its own and is never closed automatically. Auto-closing writes a leave time nobody witnessed, and that number goes to payroll. A manager types the real one.
- Corrected
- A manager can fix a wrong time, add a shift that was never punched, or delete a bogus one. Each row stays tagged — hand-entered, edited, or clocked with a manager’s temporary PIN — and each tag is a column in the export.
A week is a draft until you say otherwise
A grid of people against Monday to Sunday. Managers write it; anyone can read their own shifts, whether or not they carry the module.
Publish, and only then is it real
An unpublished week reads “Draft — the team hasn’t been told yet”, in everyone’s copy and not only the manager’s. Publishing stamps the date. Change something and publish again, and the week counts its revisions out loud, so nobody argues about which version they saw.
The people it concerns are told
Publishing sends a notification — on the phone and in the browser — to the people who actually work that week, and to nobody else. Two managers pressing Publish in the same minute still page the team once.
Time off asks, and gets an answer
An employee requests days off with a note; a manager approves or denies with a note of their own, and neither decision can be quietly rewritten afterwards. Approved days grey out in the grid, and the database then refuses a booking for that person on those days — including one a guest tries to make on your public page.
A role is what a person can reach
Roles are not ours to define. Each business writes its own — Chair, Reception, Bench, Dispatch, whatever you already call them: a name, a colour, the set of modules it carries, and whether it can manage.
A person sees a module only if the owner turned it on for the business AND their role carries it. That intersection is the whole permission model, and it is enforced in the database rather than in the menu.
The owner edits them
Add a role, rename one, move a module in or out — everyone on that role sees the change the next time they open their workspace. The owner sees every enabled module, whatever their own role says.
The role decides what opens first
Pick the module this job reaches for first, and the order its dashboard tiles start in. Anyone who disagrees can drag their own tiles, and their arrangement always wins over the role’s.
One line about the job
The owner can write a sentence that sits at the top of that role’s dashboard: what this shift is for, where to start. Structa does not know what a front-desk morning looks like at your business; the owner does, and it costs one line, once. Left empty it renders nothing at all.
One permission without the whole set
Ticking “can manage” hands over the roster, the wages, everyone’s schedule and the money screens in one go, which is rarely what was meant. A role can carry a single named operation instead, and none of the rest: today those are the shipping ones — see the queue of jobs waiting, take the next one — and each is offered only once the role already carries the module it belongs to. Seeing who else is on shift is not one of them, because it needs no granting at all: anyone whose role carries Staff sees names, job titles and who is on right now, and nothing behind them.
The board, and a message to one person
Two different jobs, deliberately kept apart. One is the business speaking to everyone on shift and keeping a record of who read it. The other is a colleague asking a colleague.
Announcements and tasks
A manager posts either one, aimed at the whole business, at one role, or at one person. Everybody marks it read, or done; the manager sees the roster split into who has and who has not, and can edit the post in place. Anyone who can see a post can reply on it. The board sits on everybody’s dashboard, so there is no module to switch on.
Team chat
Message one colleague from the top bar instead of putting the question on the board in front of everybody. Messages arrive on their own. No module to switch on and nothing extra to pay — asking a colleague a question is not something a business should have to buy.
The assistant cannot read it
Nothing structural stops it: the AI assistant runs as you, and the database would hand over the threads you are in. The forbidding is a test in our build that fails if any assistant tool so much as names those tables. A chat somebody might be summarising is a chat people take somewhere else.
What’s actually true today
The limits as well as what works. Anything you would otherwise find out on your third day is here instead.
- Card sign-in works only on a device the owner activated. A PIN on its own, from anywhere else, opens nothing.
- A PIN a manager sets will clock that person in, but will not open their workspace — they set their own PIN first.
- Clocking in needs a connection, because the PIN is checked on the server. Offline, the cards go quiet and say so instead of pretending.
- Scanning your badge to sign in only finds your card. The PIN pad still opens, because a badge is identity and the PIN is the proof.
- A shift still open after sixteen hours is flagged and never closed automatically. A manager enters the real leave time by hand.
- The overtime mark is the forty-hour US default. It is a flag on a total, not a pay calculation: Structa does not run payroll.
- Time off is whole days. There is no half-day request.
- A post aimed at one person is addressed, not sealed — the board’s read rule is business-wide. Team chat is the opposite: being in the conversation is what the database checks.
- A sent message cannot be edited by anyone, its author included. You can delete your own.
- The team’s timesheet and hourly wages are manager-only. Your own screen shows the shift you are on, counting up.
- Your language lives on your account and follows you to any device. On a shared tablet, a language switched by hand there is what the next person lands in, until they switch it back.
- A shared tablet can sign itself out after an idle period — five minutes up to an hour, or never. It is a per-device setting in the toolbar, and it is off until somebody turns it on.
Questions owners ask about their team
How long does it take to train somebody?
The design answer is that there is nothing to train. A new hire’s role carries four or five modules, so their workspace has four or five things in it and the rest of the product is not on their screen at all. The owner can also write one line at the top of that role’s dashboard saying what the shift is for — which is the part a person would otherwise be told out loud on day one.
Can two people share one tablet?
That is what it is for. The card screen is the resting state; a tap plus a PIN opens one person’s workspace, and the tablet can sign itself back out after an idle period so nobody inherits somebody else’s session. Language belongs to the account rather than to the tablet, so it travels with the person from one device to the next.
What stops somebody clocking in a friend who is running late?
A PIN is personal, a badge re-mints every minute on its owner’s phone, and five wrong PINs lock that card for ten minutes. Every punch records how identity arrived, and the export carries it as a column, so a manager can see a typed PIN apart from a scanned badge apart from a hand-entered row. What no screen can do is see who is standing in front of it: Structa records the method, it does not identify a face.
Do I need the time clock to use card sign-in?
No. Card sign-in belongs to the device and works with the Time clock module off. Turn Time clock on and the same card screen becomes the clock as well: tapping a card then asks whether you meant to punch in or to open your workspace.
What happens when somebody forgets to clock out?
It appears in its own list after sixteen hours and stays open until a person deals with it. Structa will not close it for you, because the time it would write is a time nobody witnessed and that number goes to payroll. A manager types the real leave time; the correction is tagged, and it appears tagged in the export.
Can an employee see everyone’s hours?
No. The timesheet and hourly wages are manager-only in the database, not merely behind a hidden button. An employee sees the shift they are on. What they also see, if their role carries Staff, is who is on shift right now — name, job title, and whether each person is on. That comes with the module rather than with a permission, there is no way to switch it off, and it stops there: not the hours, not the wages, not anybody’s schedule.
Does the schedule reach people who never open Structa?
Publishing a week notifies the people who work it, on their phone and in the browser. Until it is published, the week reads as a draft to everybody, so nobody plans around a version you were still editing.
Is team chat a separate product we pay for?
No. It is a panel in the top bar of the workspace everyone already signs into: no module to enable, no separate charge. It carries direct conversations between two colleagues, the AI assistant never reads them, and a test in our build is what holds that line.
Which languages does the workspace speak?
English, Spanish and Russian, chosen per person rather than per business and saved to the account so it follows them to the next device. Only the interface is translated — your own data is never rewritten.