What the AI Actually Does — and Where It Stops
Face matching, geofencing, roster drafting and anomaly detection explained without the marketing layer: what is measured, what threshold it is compared against, and which decisions a human still has to make.
Human-in-the-loop · No black-box decisions · PDPL-aligned biometric handling
Most AI claims describe an outcome. This page describes the mechanism.
Vendors are happy to tell you that AI verifies attendance. Fewer will tell you what is stored at enrolment, what number the system compares at check-in, what happens when that number falls in the middle, or which decisions the software is not allowed to make on its own. Those answers determine whether the output survives a payroll dispute — so they are the ones worth reading. If you want the capability list instead, that is on the platform overview.
Enrolment stores a template, not a photo album
At enrolment the staff member captures a reference image. What is retained for matching is a mathematical representation of that face — a vector of numbers — not a browsable picture library. The vector cannot be reversed into the original photograph.
Matching produces a score, not a yes/no
Each check-in selfie is converted the same way and compared against the enrolled template. The comparison yields a similarity score. A configurable threshold splits that score into accept, reject, and a middle band that is routed to a human rather than guessed at.
The middle band is the important one
Poor light, a new beard, a mask, a scratched lens — all push a genuine match downward. Systems that force a binary decision either lock out real staff or wave through impostors. The band exists so the ambiguous cases become a supervisor task, with the evidence attached.
Geofencing compares two numbers, and both can lie
A check-in carries a coordinate and an accuracy radius the handset reports. A phone claiming to be on site with a 500-metre accuracy radius is not evidence of anything. Both values are recorded, so a location can be judged on its precision rather than its bare coordinates.
The scheduler solves constraints, it does not invent shifts
A roster draft is a constraint problem: coverage per post, rest between shifts, contracted hours, prayer and break windows, and staff who cannot be scheduled together or apart. AI proposes an assignment that satisfies the hard rules and minimises breaches of the soft ones.
Anomaly detection needs a baseline before it means anything
An anomaly is a departure from an established pattern, so the system learns each person and site rhythm first. Until enough history exists, it says so rather than flagging normal variation. What it surfaces is a deviation for review — never an accusation.
Every AI output is a draft with an owner
A drafted roster is unpublished until a manager approves it. A flagged check-in is a queue item until someone resolves it. Nothing the model produces reaches a payroll export without a named human having accepted it.
Your data is not the training set
Staff biometric templates are used to verify the person they belong to, within your account. They are not pooled to train a general model, and they are not shared between accounts.
One check-in, end to end
Capture
The staff app takes a live selfie and reads the device coordinate plus the accuracy radius the operating system reports.
Convert and compare
The selfie becomes a vector and is compared with the enrolled template for that employee ID. The result is a similarity score.
Apply thresholds
Score and location are each tested. Clear pass on both is recorded. A failure on either, or a score inside the review band, routes to a human queue.
Attach the evidence
Whichever way it resolves, the record keeps the score, the coordinate, the accuracy radius and the device. That is what makes it defensible months later.
Human resolves the remainder
A supervisor accepts, corrects or rejects the queued items. The decision and the person who made it are written to the audit trail.
What this means for compliance
Consent is captured before enrolment, not after
Biometric processing under the UAE PDPL rests on explicit consent. Enrolment asks for it, records when it was given, and staff can review what is held about them through the app.
A score is auditable; a verdict is not
Retaining the comparison score and location precision means a disputed shift can be re-examined on evidence. A system that stores only pass or fail leaves you arguing from assertion.
Retention is bounded and configurable
Check-in imagery and templates follow a retention window you set, rather than accumulating indefinitely by default.
The human-in-the-loop boundary is a design rule, not a setting
No model output alters pay, discipline or employment status on its own. That constraint is deliberate — automation that acts unilaterally on an employment record is a liability, not a feature.
Frequently asked questions
Is a photo of my face stored?▾
What happens if the face match is borderline?▾
Can someone check in from home with a fake location?▾
Does the AI decide whether someone gets paid?▾
Is our staff data used to train your models?▾
How long before anomaly detection is useful?▾
Explore further
The platform overview
What the product does, module by module — the capability view rather than the mechanism.
Read more →The 2026 shortlist
How we compare with the other UAE platforms, and who each one suits.
Read more →Operating in Dubai
Mainland, free zone and multi-emirate considerations.
Read more →Book a Demo
See a live check-in, including a deliberately borderline one.
Read more →Ask us the awkward version of these questions
In a 20-minute demo we will run a good check-in, a borderline one and a rejected one, and show you the record each leaves behind.
