The system drafts. The teacher confirms.

Point a camera at a room. Faces are detected, aligned, and embedded in this browser — no image ever leaves the machine — then matched against the section's gallery. What comes back is a draft attendance sheet, not a verdict.

Record the authorization

Start here. Face capture is refused until the institution's approval is on record — the approver, the reviewed consent form, the retention date, and who destroys the data.

Import a roster

Paste or upload a CSV. Every row is previewed before anything is written, matching is on student id, and re-importing the same file changes nothing.

Enter students one at a time

Search, correct, archive. A duplicate student id is refused with the name of whoever already holds it.

Courses and sections

A section owns a roster and a gallery. Matching is per section, never institution-wide.

Enroll faces

Capture 5–6 shots. Bad ones are rejected at capture time with a specific reason, while the person is still in front of you.

Take attendance

Photograph the room. Get matched, uncertain, and not-recognised rows. Fix anything wrong, then confirm.

Three things worth watching for

Amber rows are the point.
Scores between two thresholds are uncertain and go to you. A single threshold would turn those into confident, silent mistakes.
Walk a stranger into frame.
They come back “not recognised”, not marked present as the nearest student. The assignment step is allowed to decline.
Nothing is saved until you confirm.
Absences are written explicitly, attributed to you — never inferred from a missing row.