Skip to content

Cloud reporting overview

This page explains what cloud reporting is, how it works, and what it sends. Read it before you decide whether to turn it on, or before you talk to the person who will commission it for your organisation.

Cloud reporting is an optional feature. When it is on, BioTrack sends a copy of your attendance records to your organisation’s cloud service. It lives in Settings → Cloud reporting, which describes it this way: optional, sends attendance to your organisation’s cloud service, and saves attendance on this computer first so a cloud outage never loses scans.

BioTrack works fully without it. If you never turn it on, nothing is sent anywhere.

Optional

Off by default. An administrator turns it on for one installation at a time.

This computer stays authoritative

Every scan is saved to the encrypted database on this computer first. The cloud copy never replaces it.

Outages lose nothing

If the cloud or the internet is unavailable, records wait on this computer and are sent when delivery works again.

Signed by this installation

Each delivery is signed with a key that is created on this computer and never leaves it.

Limited data

Only a fixed list of attendance fields is sent. Passwords, terminal credentials and biometric data are never sent.

Retention you choose

Your organisation’s cloud data is kept for 1, 3, 5 or 7 years, then deleted automatically.

Two people are usually involved:

  • A BioTrack administrator at your site. Only an administrator can change cloud reporting. Other users can open the page and see the delivery state, but they see the note Only an administrator can change cloud reporting.
  • Your commissioner. This is the person who runs your organisation’s cloud service, often an Alcra engineer. They register your organisation and site in the cloud and give you a one-time activation code.

The administrator’s steps are in Connect and activate. The commissioner’s steps are in Commissioning the cloud service.

Cloud reporting has three parts.

  1. An outbox on this computer. Whenever BioTrack saves something that belongs in the cloud copy, such as a scan or a leave record, it also writes an entry to a waiting list inside the local database, in the same step. This happens whether cloud reporting is on or not, so nothing is missed.
  2. Signed batches. The BioTrack collector service checks the outbox every 30 seconds. It sends waiting entries in small batches, each signed with this installation’s private key. An entry is marked as sent only when the cloud confirms it received the whole batch.
  3. Your organisation’s cloud service. A Cloudflare Worker checks the signature, checks every field, and stores the records in a Cloudflare D1 database that belongs to your organisation’s cloud account. It works out which organisation and site the records belong to from the installation’s registration, not from anything the computer claims.

Because the collector does the sending, delivery carries on while the BioTrack window is closed.

RecordWhat it contains
Attendance eventsEach employee scan: the ID on the terminal, the employee’s name, the event type, when it happened and when BioTrack received it, and the terminal name if known.
Calendar overridesA date marked as a working day or a non-working day, with its name.
Leave and leave revocationsLeave entered for an employee, and leave that was later withdrawn, with the reason.
Attendance correctionsAn audited change to a day’s attendance, with the reason and the day’s result before and after. Original scans are never changed.

Records made by a BioTrack user, such as corrections or leave, carry that user’s local numeric ID so the cloud has an audit trail.

  • Fingerprint, face or other biometric templates, images or media
  • BioTrack user passwords, password hashes or sessions
  • Terminal usernames and passwords
  • Recovery passphrases or other recovery secrets
  • The raw requests the terminal sends to BioTrack
  • This installation’s private signing key

The cloud service rejects any batch that contains unexpected fields or field names that look like credentials or biometric data. See Data and retention for details.