Revocable devices
Enrollment exchanges a one-time code for a hashed, revocable credential bound to a device.
Understand JoFlee tenant isolation, device credentials, role-based access, audit trails, captured data, excluded data, and company-device policy.
In short: JoFlee uses organization-scoped data, strict row-level security, revocable device credentials, server-side authorization, immutable audit trails, and explicit capture boundaries. It is designed for disclosed use on company-owned computers.
Define the purpose, capture boundary, access roles, retention, employee rights, and correction process before deployment—then keep those controls visible in daily operation.
Every tenant-owned record carries organization identity. Portal access is enforced on the server and in the database.
Enrollment exchanges a one-time code for a hashed, revocable credential bound to a device.
Supabase service credentials never reach the browser or desktop agent.
Historical manager reporting remains correct after team changes.
JoFlee may capture foreground app identity, accessible window title, supported browser URL, input-idle state, lifecycle events, and device health on company-owned computers.
Keystrokes, clipboard contents, screenshots, screen recordings, microphone, camera, and file contents.
Employees can inspect their timeline, captured context, review states, corrections, and calculation inputs.
Employers must provide appropriate notice and complete jurisdiction-specific legal review before deployment.
Account, role, salary, configuration, timesheet, correction, support, and export actions produce audit evidence.
Adjustments point back to the source interval or snapshot.
Operational logs use masked identifiers and never include captured window-title content.
Tenant deletion follows retention and recovery steps rather than immediate destructive removal.
JoFlee complements the PMS, HRMS, payroll, and billing tools a company already uses. It quietly prepares the accurate record those systems need, so employees do not have to recreate a week or month from memory.
Attendance, active work, breaks, working-away time, project hours, timesheets, and salary progress are assembled from the normal workday—not another timer employees must remember to maintain.
Employees can inspect the record, classify or split idle time, assign uncategorized activity to projects, review period totals, and request corrections before submission.
HR gets scoped charts and exports, managers get review queues and project totals, and Finance gets transparent payable-hour and salary inputs—all from the same reviewed record.
JoFlee is designed as a visible company-device work-record system with explicit capture boundaries, employee access to their records, and disclosed organizational policy. It is not designed for hidden installation.
No. Keystrokes and clipboard contents are explicitly excluded.
No. Monitoring law varies by jurisdiction. Employers need appropriate notice, policy, consultation, consent, or legal review as applicable.
Organization identifiers, server-side authorization, and database row-level security enforce tenant and role scope.
The macOS and Windows agents install an update only after checking its size and SHA-256 digest against the registered release and verifying the publisher signature. macOS updates must also be notarized by Apple. Updates install without employee action.
No. JoFlee is an autonomous workday record that complements existing PMS, HRMS, payroll, and billing systems. It helps employees remember and verify their work, gives them visibility and review rights, and deliberately excludes screenshots, keystrokes, productivity scores, and employee ranking.