ZoikoDigital
Worker Record View

The person in the record can see it — and question it

ZoikoTime can give workers a role-appropriate view of their own workforce record: the recorded time or attendance context, current state, source summary, applicable policy explanation, review status, correction history, and available next action.

Workers can request correction or provide permitted context where configured, and consequential decisions remain with authorized people. ZoikoTime does not collect screenshots, keystroke content, URL history, application-name monitoring, or clipboard data, and it does not create an individual productivity score.

A worker reviewing their own record, with routes to ask a question, raise an issue, and follow the response

A worker's own record

One synthetic record in a state that needs attention — because a record that is already approved demonstrates nothing about how a worker is treated when something is wrong.

Illustrative synthetic record — not real worker data
Wednesday 6 August 2026Site survey · Northgate · 6h 45m recorded · break 45m · times in Europe/Berlin
Needs context
What this means

A required project reference is missing from this record, so it needs context before review can complete. This is a missing detail — it is not a finding about you, and it does not affect any other record.

Next decision: unit reviewer, Field Services North · not an automated decision

Where this came from
Source
Site terminal check-in and check-out
Recorded
Check-in 06:58, check-out 14:12, both received at the time
Freshness
Current — no delay affecting this record
Known limitation
The site register feed was delayed on this date, so project references were not attached automatically

The delay is a system condition, not a worker condition. It explains why the reference is absent.

Which rules applied
Policy used
Field North Working Time, version 3 — the version effective on 6 August
Plain explanation
Your shift was within the standard threshold and your break met the minimum for a shift of this length, so it classified as a standard field shift.
Newer policy
A newer policy version exists. This record used version 3 and was not reclassified under it.

This explains how the record was categorized. It is not legal advice and does not state any pay entitlement.

Your rights on this record

You can add context, request a correction, see who reviewed it and why, follow the status, and escalate if you disagree with the outcome. Using any of these does not waive a privacy, grievance, appeal, legal, or contractual right — and no action here is required before you can ask a question.

Requesting a correction

Before submitting, a worker sees exactly what will be shared and with whom. Nothing is sent quietly, and a draft can be saved without submitting.

The flow shows

  • Which field is affected, and its current value
  • The proposed value or context being added
  • A sharing preview — who will see this and what they will see
  • The option to save a draft rather than submit
  • Confirmation of what happens next, and who decides
Never asked of a worker

“Prove that you worked.” No correction flow demands justification of a person's honesty, and none frames a request as a dispute or a complaint. A request is a request.

Ten correction states

Including two that a worker deserves to see named plainly.

NoneDraftSubmittedWithdrawnInformation requestedAcceptedPartially acceptedNo change approvedSupersededReopened

“No change approved” and “Partially accepted”

Both are real outcomes, and both are stated neutrally with the reviewer's reason. Neither is “your claim was rejected” or “excuse denied” — a reviewer deciding the record was already correct is a legitimate result, and it does not imply the worker was wrong to ask.

Every outcome shows the authorized role that decided, the reason, any conditions, the resulting version, and the escalation route if the worker disagrees.

What an acknowledgement means

This is the single most abusable control in a worker-facing product. Where acknowledgement is enabled, the interface must say exactly what it means — and exactly what it does not.

“Acknowledged: you have seen this notice.”

That is the default and only meaning. It is stated on the control itself, not buried in a policy.

It means

  • You have seen this notice or record
  • The organization can show the notice reached you

It never silently means

  • Consent
  • Agreement with the record
  • Admission of anything
  • Waiver of any right
  • Withdrawal of a correction request
  • Acceptance of a consequential decision

Generated

A notice was created for an event.

Not yet sent to anyone.

Sent & delivered

Handed to a channel, and confirmed where the channel reports it.

Delivery is not reading.

Acknowledged

The worker confirmed they have seen it, where the feature is configured.

Seeing is not agreeing.

Failed

Delivery did not succeed. Explicit and owned by the organization.

A failed notice never counts against the worker.

The words a worker actually reads

Left column is what a workforce product usually says. Right column is what this one says instead. Microcopy is where dignity is either preserved or lost.

ProhibitedRequired
Suspicious / failed / noncompliant workerNeeds context
Under investigationPending review
Worker disputed the systemCorrection requested
Your claim was rejectedNo change approved
You were absent / did not workThe source is unavailable, so this record needs review
Prove that you workedRequest a correction or provide context
AI decided · system verdictYour request was reviewed by an authorized role
Current policy replaces the old ruleA newer policy exists; this record used version 3
You accept this record / waive further reviewAcknowledged: you have seen this notice
Payroll correctedDownstream update pending
Hidden evidence proves the outcomeSome details are restricted for privacy or security
Contact Sales for worker supportContact Help, Privacy, or Accessibility

“Under investigation” is permitted only where an actual authorized investigation exists. “Payroll corrected” is permitted only where target acceptance and reconciliation are genuinely confirmed. Neither is a default label.

Twelve independent state dimensions

Do not collapse record truth, correction workflow, review, source health, notification, sync, permission, downstream, support, and accessibility into one ambiguous status chip. A worker seeing a single amber dot learns nothing actionable.

Record lifecycle

Source received · classified · review required · approved · corrected or superseded · retention-limited.

What the record itself is.

Worker action

No action · review available · context requested · correction draft · submitted · acknowledgement available · escalation available.

What the worker can do right now.

Correction

None · draft · submitted · withdrawn · information requested · accepted · partially accepted · no change approved · superseded · reopened.

Separate from review state.

Review

Unassigned · assigned · pending · information requested · decision recorded · escalated · reassigned · closed · reopened.

Who holds it, not what they concluded.

Source quality

Current · delayed · stale · missing · unavailable · conflicting · imported · partial · unknown.

A system condition, never a worker condition.

Policy / evaluation

Applicable · historical · superseded · missing · conflicting · revalidation required · restricted.

Historical stays historical.

Notification

Not required · generated · sent · delivered where known · failed · corrected · acknowledged where configured.

Four separate facts, not one.

Sync

Online · saved draft · offline · pending sync · synced · failed · unknown result · conflict.

A record never silently disappears.

Permission

Allowed · restricted field · action unavailable · permission denied · role changed · session expired.

Server-checked, and explained when it blocks.

Downstream

Not applicable · not released · release pending · sent · target received · reconciled · rejected · unknown.

Sent is not received is not reconciled.

Support

No case · help viewed · support requested · response pending · resolved · escalation required.

A worker can always reach a person.

Accessibility alternative

Standard flow available · alternative requested · alternative provided · barrier unresolved.

An unresolved barrier is visible, not hidden.

What is recorded, and who decides

A worker-facing record is only trustworthy if the collection boundary and the decision boundary are both legible from inside it.

Recorded

Time events, work or project context you enter, breaks, your comments and correction requests, and disclosed authentication and audit events.

Never collected

Screenshots, keystroke content, URL history, application names, clipboard data — and no individual productivity score, at any tier or configuration.

Who decides

Deterministic rules organize configured context. Authorized people decide consequential outcomes. There is no AI verdict and no system judgment.

Getting help

Help Center, Privacy, and Accessibility routes — plus an accessible alternative if the standard flow is a barrier. Never a sales route.

Downstream and payroll boundary

Current

Objective: never let a worker read “corrected” as “paid.”

Record vs payroll
ZoikoTime may prepare, approve, and export governed time records. It does not claim to perform gross-to-net payroll.
Corrected vs delivered
A corrected record is not the same as a downstream system receiving the update
Delivered vs reconciled
A receipt is not proof the target accepted the expected value
Worker-visible wording
“Downstream update pending” — never “payroll corrected” unless acceptance and reconciliation are genuinely confirmed

Professional boundary: no worker-facing message declares statutory pay entitlement, legal compliance, or an employment-law conclusion. Technical identifiers, secrets, and system topology stay hidden.

Errors, cutoffs & no coercion

Current

Objective: keep urgency honest and blame absent.

External errors
Shown as a system or integration state. Blame is never assigned to the worker.
Missing source
Missing calendar, access, device, or integration context is not automatic evidence of absence or non-work
Cutoff risk
Shown where configured — but it never bypasses required review, notice, or approval
No coercion
A deadline never pressures a worker into a response, and no interface makes accepting faster than asking

Limitations: downstream detail appears only where it is understandable, permitted, and useful to the worker. Where it is not, the record says so rather than showing a technical state nobody can act on.

Rights-preserving by design

A record its subject can read, question, and challenge

See how state, source, policy explanation, correction, decision visibility, and escalation work together — without surveillance, scoring, or a demand that the worker accept anything unexplained.

Get Demo
A worker reading their own record with review history, decision visibility, and an escalation route

Worker record questions

A role-appropriate view of their own record: the recorded time or attendance context, current state, source summary, applicable policy explanation, review status, correction history, and the available next action — plus who is responsible for the next decision. Exact fields depend on the organization's configuration and applicable law.