Understand workforce records without losing context or control
Turn approved time, attendance, policy, correction, approval, integration, and evidence records into defined enterprise metrics, dashboards, reports, and governed exports — with visible quality, privacy, permissions, and limitations.
Existing customer? Open the Analytics Governance Center
Binding Commitment
Understand governed workforce records—never hidden behavior. Analytics explains what the data supports, what it does not support, and who remains responsible for interpretation.
ZoikoTime Analytics & Reporting turns approved workforce records into defined metrics, dashboards, reports, and governed exports. Each view identifies its scope, source, metric version, time zone, freshness, completeness, exclusions, privacy treatment, and limitations. Broad views default to aggregation, small groups are protected, anomalies remain neutral review prompts, and authorized people retain responsibility for interpretation, corrections, approvals, payroll, employment, legal, and compliance decisions.
What it uses
Approved workforce records and documented integration inputs, within authorized purpose and scope.
What it produces
Defined metrics, governed dashboards, reports, subscriptions, and controlled exports where released.
Who stays responsible
Authorized people interpret, investigate, correct, approve, communicate, and decide. Analytics informs review.
What it never does
Screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection — under any tier or configuration.
Hidden productivity scores, secret rankings, or opaque composite ratings.
Automatic misconduct findings.
Autonomous consequential decisions.
Shared responsibility
You remain responsible for configuration and lawful basis.
Roles, policy, and scope decisions stay with your organization.
Data quality at source, and interpretation of results.
Jurisdiction, review, and downstream use of any output.
Why Governed Analytics Matters
Seven Ways a Confident Chart Misleads
Each failure below has a specific design response. None of them is solved by a nicer visualization.
A number without a definition
It is not decision-ready, however precise it looks.
A trend that hides change
Scope, policy, or organization changes can invert the meaning of a line.
A dashboard that exposes too much
An executive view can reveal individual detail nobody authorized.
An anomaly read as wrongdoing
A statistical outlier is not a finding about a person.
A correction that leaves reports stale
Old numbers keep circulating after the underlying record changes.
An export that escapes governance
A spreadsheet leaves the platform and the controls stay behind.
A polished chart over incomplete data
Visual quality implies data quality. It shouldn't.
Governed Analytics Lifecycle
Nine Stages From Question to
Preserved Evidence
A metric does not begin with data. It begins with a stated question and a stated prohibited inference.
Define the question
Purpose
State the business question — and the inference that is prohibited.
Required Proof
Owner, purpose, audience, decision boundary.
Select governed scope
Purpose
Choose population, record states, dates, jurisdiction, organization, and the minimum necessary grain.
Required Proof
Scope preview, permission, small-group treatment.
Validate data
Purpose
Check freshness, completeness, source health, corrections, exclusions, reconciliation.
Required Proof
Quality status, excluded records, owner.
Apply metric definition
Purpose
Use the approved numerator, denominator, formula, time zone, inclusion rules, and version.
Required Proof
Metric catalog link, test evidence.
Aggregate and protect
Purpose
Apply aggregation, suppression, masking, and purpose limits.
Required Proof
Privacy treatment, minimum group, drill-down rule.
Review quality
Purpose
Confirm validity, comparability, policy versions, and known limitations.
Required Proof
Review checklist, warning state, approval.
Interpret and annotate
Purpose
Authorized people add context, questions, explanation, and follow-up.
Required Proof
Author, timestamp, neutral language, escalation.
Publish or export
Purpose
Share a dashboard or report, or create a controlled export or schedule.
Required Proof
Audience, delivery, expiry and retention, authorization.
Preserve evidence
Purpose
Store definition, scope, source snapshot, calculation, approvals, delivery, corrections, changes.
Required Proof
A reproducible evidence package.
Analytics Governance Center
Quality, Privacy,
and Provenance
Sit Next to
the Number
Governance is not a settings page you visit once. Freshness, completeness, metric version, suppression state, and export approval appear alongside every result.
Data quality — source status, freshness, exclusions, correction lag, reconciliation, owner
Metric governance — version, effective date, last review, pending change, impacted reports
Privacy and access — default aggregation, minimum group, suppression, drill-down permission
Evidence — last published report, export manifest, calculation record, correction lineage
KPI Row — Counts, not a composite score
Approved records
18.4k
Completeness
96.4%
Pending corrections
27
Open exceptions
38
Reports due
5
Stale definitions
2
Export reviews
3
Access reviews
1
| Item | Reason | Owner | Status |
|---|---|---|---|
| Definition review | MT-014 review overdue by 12 days | Analytics admin | Needs review |
| Data gap | Attendance feed stale — 41h vs 24h expected | Data admin | Stale |
| Report owner missing | Regional readiness report unassigned | Unassigned | Needs owner |
| Schedule failure | Run held — recipient eligibility revoked | Report author | Held, not sent |
| Export approval | Payroll readiness export awaiting authority | Privacy reviewer | Pending |
| Recalculation pending | Correction batch C-2211 affects 3 reports | System | Recalculating |
Attention queue, synthetic. Every item is a workflow condition with an owner—never a judgment about a person.
The mockup is implementation-aware but implies no metric family, data scale, accuracy, freshness, prediction, format, provider, region, plan, or customer outcome.
Metric Catalog & Definition Cards
Every Metric Is Explainable, or It Doesn't
Ship
Ten required fields per metric. If a field is unknown, the metric stays in draft — it does not appear on a dashboard with a caveat.
Record completeness· MT-014
Question answered: for a given operating period and population, what share of required workforce records is present and in an accepted state?
Prohibited use
This metric must not be used to assess an individual worker's diligence, reliability, or performance. It describes record conditions, not people.
Formula
numerator: records in accepted state
denominator: required records in scope
units: percentage · rounding: 1 dp · null: excluded
Scope and grain
Organization, entity, team, and period. Worker grain requires a documented purpose and an authorized role.
Sources
Approved time records and schedule expectation objects. Reconciliation status: matched.
Inclusion / exclusion
Excludes withdrawn records and populations outside the effective policy. Late-arriving records update the period and mark it revised.
Time treatment
Location time zone with DST applied. Reporting calendar: fiscal weekly. Period close locks the denominator.
Privacy treatment
Aggregate by default. Minimum group of 5. Below threshold, values are suppressed with a stated reason.
Quality
Freshness 6h. Completeness 96.4%. Test status: passing. Known limitation — excludes records pending reconciliation.
Version and governance
v3, approved by Analytics Governance Board. Change reason: denominator clarified. Impacted reports: 4. Not retired.
Controls That Prevent an Invalid Comparison
Filters are not just convenience. Each one changes what a number means, so scope, record state, time zone, and policy context stay visible while you work.

Quality, Provenance, Freshness & Corrections
Trust Conditions, Shown
Beside the Result
Quality severity is based on reporting impact, never on worker blame. Unavailable data is excluded or blocked with an explanation—it is never silently imputed.
Freshness
Last successful source acknowledgement, calculation time, expected cadence, stale threshold.
Completeness
Included versus expected basis, exclusions, unresolved gaps, denominator treatment.
Provenance
Source object, source system, integration and mapping version, policy version, transformation chain.
Reconciliation
Matched, unmatched, duplicate, conflicting, quarantined, or pending, each with an owner.
Corrections
Effective time, impacted metrics and reports, recalculation status, downstream acknowledgement.
Late-arriving data
Pending or updated status remains visible while the previous report snapshot stays reproducible.

Aggregate First. Protect Small Groups Justify Every Drill-Down.
Enterprise views default to the least granular result that answers the stated question. Individual-level detail appears only for a documented purpose and an authorized role.

Masking and rounding
Method and effect are disclosed. We do not create false precision to make a chart look authoritative.
Drill-down
Requires role, purpose, scope, and evidence. Hidden populations and counts are not leaked through empty states or error messages.
Sensitive dimensions
Absent or restricted unless a documented lawful purpose, authorization, and privacy or legal approval exist.
Cross-filter leakage
Prevents inference through repeated filtering, subtraction, export, or small cohort combinations.
Export protection
The same or stricter privacy rules apply to downloads, scheduled delivery, APIs, and shared links.
Site analytics
Public-site telemetry never captures chart values, report contents, worker IDs, filter values, or organization scope.
Nine View Families, Each With Its Limit
Written Down
The limit is part of the capability. It is stated on the card, not buried in documentation.
Approved time records
Volume, status, period readiness, corrections, exceptions, evidence.
Not a productivity score.
Timesheet & approval operations
Submission, review, and approval status, aging, correction flow, bottlenecks.
No automatic blame.
Attendance & presence states
Configured record-state patterns and unresolved cases.
No hidden location surveillance.
Break & rest context
Configured policy support, review states, exceptions.
Not legal compliance certification.
Shift integrity
Released rule outcomes, conflicts, reviews, corrections.
An anomaly remains a prompt.
Deterministic classification
Classification distribution, policy version, review and correction, explainability.
Not branded or described as AI.
Evidence readiness
Records with required evidence, gaps, pending acknowledgements, export status.
Integration health impact
Source freshness, reconciliation, correction propagation, reporting exclusions.
Administration & access
Policy, role, and report ownership plus review status — at aggregate governance level only.
A view family appears only when the underlying capability, metric definition, permissions, privacy controls, documentation, and QA are all current and approved.
A Series Break Is Not a
Footnote
Policy changes, reorganizations, source changes, metric versions, outages, period closes, and recalculations are marked directly on the series itself because a reader who misses them can easily draw the wrong conclusion.
Cohort
Membership rule, entry and exit, minimum group, time basis, permitted purpose.
Period comparison
Aligned calendars, time zones, workdays, policy versions, comparable populations.
Organization comparison
Consistent metric, scope, and privacy threshold. Leaderboard design is avoided deliberately.
Target / threshold
Labeled contractual, policy, operational, or illustrative. Never presented as a legal standard.
Narrative
States the observed pattern and its limitations. No causal, disciplinary, medical, legal, or performance conclusions.
Benchmarks require a documented cohort, lawful basis, methodology, freshness, minimum sample, owner, and approval. Forecasts require methodology, uncertainty, intended use, monitoring, and a human-review boundary. Neither appears by default.
Record Completeness — MT-014, Weekly
Synthetic. Two comparability breaks marked.
Values either side of a comparability break are not directly comparable. The series is intentionally shown with marked breaks so changes in policy or metric definitions are visible instead of being hidden in documentation.
Accessible data table — generated with every chart, not on request.
| Week | Completeness | Comparability |
|---|---|---|
| W26 | 88.2% | Baseline · policy v3, metric v2 |
| W27 | 89.4% | Comparable to W26 |
| W28 | 90.1% | Comparable to W26 |
| W29 | 91.4% | Break — policy v4 effective |
| W30 | 92.5% | Comparable to W29 |
| W31 | 93.6% | Comparable to W29 |
| W32 | 95.1% | Break — metric definition v3 |
| W33 | 96.4% | Comparable to W32 |
An Anomaly Is a Review Signal, Not a
Finding
The interface must not imply guilt, intent, poor performance, payroll error, legal breach, or a disciplinary outcome. The vocabulary is deliberately narrow.
Approved labels
Never Used
Reason code
Explains the rule, comparison basis, source, metric version, and affected scope.
Evidence
Relevant records and provenance, visible only to authorized roles.
Available actions
Review, request context, correct, reconcile, dismiss with a reason, escalate, document the outcome.
Worker rights
Where relevant, visibility, correction, response, and escalation paths are preserved.
Notification
A purpose-limited recipient list. No public leaderboard and no shame-oriented alert.
Telemetry
Workflow events are counted. Anomaly values, names, and case text never enter telemetry.
Self-Service Within Governance,
Not Around It
Authors compose from the approved catalog, see the privacy preview before publishing, and cannot reach a publish action without passing review.
| Stage | Required Components & Behavior |
|---|---|
| Start | Approved template or blank report, with purpose, owner, audience, and data classification stated up front. |
| Metric selection | Catalog search with definition preview, compatibility check, permissions, and version. |
| Scope and filters | Population, record state, period, time zone, policy or jurisdiction context, and a privacy preview. |
| Visualization | Approved chart and table options based on data type. An accessible text summary and data table are generated automatically. |
| Layout | Grid with keyboard move and reorder controls. Drag with a pointer is never the only way to arrange a report. |
| Quality panel | Freshness, completeness, exclusions, comparability, corrections, and warnings. |
| Access | Viewer, editor, export, and share roles — with inherited and direct grants both visible. |
| Review | Preview as the recipient, validate privacy, run an accessibility check, request approval where required. |
| Publish | Versioned publication with owner, audience, effective date, and evidence. |
| Change | Draft a new version, preserve the prior published snapshot, and show impacted subscriptions and exports. |
Recurring Delivery Is the
Easiest Place to Leak Data
Recipient eligibility is revalidated before every run. A schedule whose owner has left, or whose report has been retired, is disabled rather than left quietly sending.
A failed run is never sent partially or stale. It is queued, labeled, retried, or held for review.
Unsubscribe and stop controls are clear and authorized. No dark patterns, and no hidden recurring delivery.
Schedule
Cadence, time zone, business calendar, start and end, missed-run behavior, owner.
Audience
Named roles, groups, or controlled destinations — revalidated before each run.
Delivery
In-product first where possible. Email, link, file, or API only when current and approved.
Scope snapshot
The exact metric versions, filters, privacy treatment, and report version used.
Change impact
The owner is notified when a definition, permission, policy, source, or population change affects output.
Evidence
Run, data snapshot, recipients, status, failure, retry, and acknowledgement where supported.
Controlled Exports & Evidence Packages
Eight Steps Between a Request and a File
An export is the moment governance either travels with the data or is left behind. Every step below produces a record.
Step 01
Select export
An approved report, table, evidence package, or documented data object only.
Step 02
Preview scope
Record basis, metrics, dimensions, period, privacy treatment, classification, estimated size.
Step 03
Authorize
Role, purpose, destination, approval, and step-up authentication where required.
Step 04
Generate
Versioned definitions, source snapshot, calculation time, exclusions, integrity check.
Step 05
Deliver
Controlled destination, expiry, access, retry, acknowledgement where supported.
Step 06
Record evidence
Requester, approver, scope, reason, format, time, destination, outcome, revocation.
Step 07
Correct or supersede
Link the recalculation. The prior export is preserved as historical, never silently overwritten.
Step 08
Retain or dispose
Approved retention and secure disposal. You remain responsible for downstream copies.
⊗Export boundary
- ×No promised format, encryption method, or watermark
- ×No download limit, API, or destination claim
- ×No retention or revocation capability
- ×…unless it is current, documented, owned, and approved
◉Reproducibility
- ✓Metric and report version
- ✓Scope, filters, and time zone
- ✓Source snapshot and calculation record
- ✓Approvals, delivery, and correction lineage
Role-Based Access & Sharing
Separation of Duties, Written as Permissions
Ten role patterns. Note where authority stops — a report author cannot rewrite a canonical definition, and a data admin gets no automatic path to worker-level detail.
| Role | Typical permission boundary |
|---|---|
| Organization owner | Full commercial and governance visibility. High-impact export and retention actions may still require separation of duties. |
| Analytics administrator | Manage metric catalog, reports, dashboards, quality rules, schedules, and access within approved scope. |
| Report author | Create and edit reports from permitted metrics and populations. Cannot alter canonical definitions without separate authority. |
| Executive viewer | View approved aggregated dashboards and annotations. No unrestricted drill-down and no export. |
| HR / people analyst | Authorized workforce-record analysis within purpose, policy, privacy, and scope. |
| Payroll / finance reviewer | Approved period readiness, corrections, reconciliation, and controlled exports. |
| Privacy / compliance reviewer | Review purpose, privacy treatment, access, retention, exports, evidence, and exceptions. |
| Data / integration admin | Source health, lineage, mapping, quality, and delivery. No automatic access to worker-level analytical detail. |
| Auditor / viewer | Read-only evidence and approved reports. Export only where explicitly granted. |
| Worker / representative | Relevant worker-facing records, correction status, and transparent use information where supported. No access to restricted organization analytics. |
Analytics Questions Answered
Eight Answers, No Accuracy Guarantee
Defined, governed metrics, dashboards, reports, and exports based on approved workforce records — with provenance, quality, privacy, permissions, human interpretation, and preserved evidence.