Discover powerful Dolibarr extensions designed to automate your business processes

HR Badge, Time & Attendance Management turns Dolibarr into a complete badge, time and attendance platform. It manages the full attendance chain — from access badges and clocking terminals, through employees, sites, zones, work schedules and shift planning, to real-time punches, anomaly detection, correction workflows, overtime, time counters, timesheets and payroll exports — so workforce time management runs natively inside Dolibarr without a separate specialised application. The module ships with 28 business objects, a purpose-built "Smart Attendance Gate Center" dashboard, decision reporting, an employee self-service portal, a secured REST API, webhooks and a complete demonstration dataset. It is designed for SMEs, large enterprises, multi-site groups, industrial plants and public bodies.
Give HR, operations and payroll teams a single, auditable system to collect attendance events from heterogeneous clocking hardware, reconcile them against contractual work schedules, surface and correct anomalies, compute worked, overtime, night, Sunday and public-holiday hours under configurable rules, and feed clean, validated timesheets to payroll — while steering the whole operation in real time from a single dashboard with presence, punctuality and anomaly KPIs.
Multi-site SMEs and large enterprises, industrial and logistics sites with shift work, retail and hospitality chains, healthcare and facility operators, public authorities and any Dolibarr user needing traceable, hardware-agnostic time & attendance tightly integrated with their existing ERP.
Time & attendance administrators, HR managers, site and shift managers, team leaders validating timesheets, payroll officers consuming the exports, IT administrators configuring terminals and connectors, and — through the self-service portal — every employee consulting their punches, counters and requesting corrections.
One integrated system for hardware, badges, people and time; a hardware-agnostic connector architecture so no protocol is hard-coded; real-time visibility of who is on-site; a configurable, auditable work-time calculation engine; a controlled correction and validation workflow; parametrable payroll exports; five languages; a secured REST API and webhooks; and a one-click, realistic demonstration dataset.
Badges are technology-agnostic. Each badge records its physical technology, encoding format, unique UID and printed number, and can be issued, activated, suspended, lost, stolen, replaced or returned. Supported identification methods include:
· RFID contactless cards and fobs (125 kHz / 13.56 MHz)
· NFC — smartphones and NFC-enabled credentials
· MIFARE (Classic / DESFire) encoded cards
· QR Code badges and dynamic QR tokens
· PIN codes (hashed) for keypad terminals
· Virtual / mobile badges and fallback identification methods
Clocking terminals (badgeuses) are inventoried with manufacturer, model, serial number, firmware, IP/MAC address, capacities (users, events), and are attached to a site, a zone and a connector. Each terminal tracks its type and technology, installation and maintenance dates, last communication and last synchronisation timestamps and an operational status, so the fleet health is visible at a glance and a sync can be triggered per device (also from the REST API).
An extensible connector layer decouples the module from any specific device or protocol. Each connector declares its type, manufacturer, version, endpoint, authentication mode, secret reference, synchronisation frequency and a field-mapping definition. Supported integration styles include REST API, SOAP, vendor SDK, TCP/IP, SFTP and file drops (CSV, XML, JSON) plus outbound webhooks — new hardware is added by configuring a connector, never by changing the core.
· REST API and SOAP web-service connectors
· Vendor SDK and native TCP/IP device polling
· SFTP and file drops — CSV, XML, JSON batch imports
· Outbound webhooks for near-real-time event push
· Per-connector field mapping, auth mode, secret reference and sync frequency
Badges follow a full lifecycle: creation, assignment to an employee, activation, suspension, declaration of loss or theft, replacement and return. Every assignment is recorded as a dated badge-assignment row with its reason and the user who performed it, keeping a complete, auditable history of who held which badge and when. Assignment and deactivation are also exposed as dedicated REST actions.
Each employee record carries the attendance-relevant context: matricule, identity, linked Dolibarr user and third party, site, zone, department, service, team, job position and manager, a default work schedule and cycle, a main badge, and fallback identification (PIN hash, QR token, fallback method). Contract type and hire date complete the profile that drives punch reconciliation and rule application.
The "Smart Attendance Gate Center" computes, from the latest punch of the day per employee, who is currently on-site. The REST /presences endpoint returns the live present headcount and each person's last punch, filterable by site, feeding the dashboard's five gates — Entries, Presences, Breaks, Exits and Anomalies — and the central presence & punctuality index.
Schedules define the contractual working pattern: type (fixed, flexible, shifted), work days, start/end times, break minutes, daily and weekly hours, entry and exit tolerances, minimum duration and maximum amplitude, rounding rule, night-window boundaries and validity dates. They are the reference against which punches are checked and worked time is computed.
Cycles describe multi-week rotation patterns built on a base schedule, and plannings assign a concrete planned start, end and hours to an employee or a team for a given day and site. Together they cover fixed, flexible, shifted and rotating organisations and provide the planned baseline compared against actual punches.
Punches (pointages) capture each clocking event: employee/matricule, badge and UID, terminal, site, zone, exact datetime, punch type (entry, exit, break start/end, mission, telework, exceptional entry), punch method and origin, with a link to the import lot and to any anomaly raised. Punches are collected live from terminals or imported in batches, and each carries its own processing status.
An anomaly engine flags irregular situations — missing punch, duplicate, lateness, early departure, off-site, outside-schedule and more — with a type, severity, triggering rule, the employee and punch concerned, an owner and a resolution status. Anomalies are isolated from clean time until resolved and drive the dashboard's Anomalies gate and the reporting by severity.
Corrections provide a traceable request/approval trail: for a given punch or anomaly, a correction records the type, old value, requested value, reason, request date, validator and decision date, and a status from requested to approved or rejected. Corrections can be opened directly from an anomaly via the REST API, keeping who-changed-what fully auditable.
Overtime entries record the date, overtime type, hours, rate multiplier and an estimated cost per employee, with a validator and an approval status. Overtime is derived from worked hours against the schedule and calculation rules, then validated before it flows into counters, timesheets and payroll exports.
Counters accumulate time balances per employee and period — worked value, running balance and carried-over hours — for counter types such as overtime, night, or time-savings accounts, giving each employee and manager a clear running position with carry-over between periods.
Timesheets consolidate, per employee (or team) and period, planned versus worked hours, split into normal, overtime, night and absence hours, with an anomaly count and a lock flag. They move through a validation workflow and, once locked, become the trusted basis for payroll exports.
Validations attach to a timesheet a validation level, the validator, a decision (approved/rejected), a date and a comment, supporting multi-level sign-off (e.g. team leader then HR). Only validated, locked timesheets are eligible for export, ensuring payroll receives controlled figures.
Calculation rules define, by scope, the night rate, Sunday rate, public-holiday rate, overtime threshold and the first and second overtime rates, plus the rounding rule and validity date. Combined with each schedule's night window and tolerances, they let the module compute normal, overtime, complementary, night, Sunday and holiday hours in an auditable, configurable way.
A public-holiday calendar (date, type, calendar, rate multiplier, optional site) parametrises holiday premiums, while leaves record per employee the leave type, date range, day count, justification and status. Both feed the work-time computation and the absence figures on timesheets and the dashboard.
Payroll exports package, per period and export model, the aggregated hours (total normal and overtime), line count, target format and a lock flag, with an export status. Exports are parametrable to match the downstream payroll software and are the clean hand-off point between attendance and payroll.
The "Smart Attendance Gate Center" dashboard organises attendance around five gates — Entries, Presences, Breaks, Exits and Anomalies — headlined by a global presence & punctuality index, with live present-now headcount, today's punches and anomalies, overtime hours, alerts, interactive DolGraph analytics and quick-action buttons, in both light and dark themes.
Decision reporting covers attendance and punctuality, worked and overtime hours by site, team and period, anomalies by type and severity, terminal and connector activity, counters and timesheet status, and payroll export summaries — each exportable to CSV for downstream analysis.
The employee portal (portal.php) lets employees consult their own punches, counters, timesheets and badge status, and submit correction or leave requests without going through HR, reducing back-office load while keeping every request traceable.
The module builds on native Dolibarr objects — Users, Third parties, Employees/HR, Leave, Agenda, Projects, Interventions, Products, Stocks, Contracts and Documents — to attach employees, reconcile calendars, archive documents and hand time data to HR and payroll, all without any core modification.
Input validation via GETPOST, output escaping (htmlspecialchars, dol_escape_htmltag), CSRF protection through Dolibarr, escaped/parameterised SQL, entity filtering for multi-company setups, fine-grained per-group permissions (gbrCan / hasRight), confirmed and administrator-only demo-data removal, secret references instead of inline credentials on connectors and webhooks, and no hardcoded secrets anywhere in the module or the distribution ZIP.
A dedicated audit log records sensitive actions — action code, object type and id, acting user, timestamp, old and new values and source IP. Side-effecting API actions (terminal sync, badge assign/deactivate, punch import, correction request) write audit rows automatically, giving a complete traceability trail.
A secured REST API under /api/index.php/gestionbadgeuserh/ (class Gestionbadgeuserh, @access protected) exposes sites, zones, terminals (with a per-device sync action), connectors, badges (with assign/deactivate actions), badge assignments, employees, teams, schedules, punches (list, get and import), import lots, breaks, live presences, anomalies (with a correction action), corrections, timesheets, counters and overtimes — with pagination, sort/filter fields whitelisted against SHOW COLUMNS, and per-group read/write/delete permission checks on every route.
Outbound webhooks let external systems react to attendance events: each webhook declares an event type, target URL, a secret reference for signing, an active flag and its last-fired timestamp — so anomalies, punches or validations can be pushed to third-party systems in near real time.
In-app and channel notifications alert managers and employees to events — anomalies, missing punches, pending validations — with a type, label, severity, channel, target role and read flag, keeping the right people informed without leaving Dolibarr.
One click generates a realistic, FK-coherent dataset spanning all 28 tables — sites, zones, connectors, terminals, badges and assignments, employees and teams, schedules, cycles and plannings, thousands of punches with breaks, anomalies and corrections, overtimes, counters, timesheets and validations, holidays, leaves, payroll exports, report definitions, webhooks, notifications and audit logs — with 12+ months of history and forced non-zero current-day KPIs. Rows are tagged import_key GBRDEMO; a confirmed, administrator-only action safely removes only the demonstration data, guarded by a DATASET_VERSION check.
Gestion Badgeuse RH is an external Dolibarr module (no core modification) following an MVC layout. A module descriptor (modGestionBadgeuseRh, numero 1024000, HR family) declares menus, permissions, boxes and dependencies and creates the 28 tables. 28 generated CommonObject classes (class/gbr*.class.php) are driven by an object registry (lib/gestionbadgeuserh_objects.php) and a generic list/card engine (objectlist.inc.php, objectcard.inc.php, objectlist_render.php). A shared library (lib/gestionbadgeuserh.lib.php) provides permissions, the 372-code multilingual vocabulary, KPI cards and the gbrForceLabels anti-collision helper. Every visible string is translatable — no user-facing French is hardcoded in PHP.
The domain is modelled as 28 tables prefixed llx_gbr_, each carrying rowid, entity (multi-company), status, date_creation, tms, fk_user_creat/modif and import_key, with indexes on entity and every foreign key. The objects, by functional area, are: Topology (sites, zones); Hardware (connectors, terminals, badges, badge assignments); People (employees, teams); Time model (schedules, cycles, plannings); Events (punches, import lots, breaks); Exceptions (anomalies, corrections); Work time (overtimes, counters, timesheets, validations); Rules & reference (calc rules, holidays, leaves); Output (payroll exports, report definitions, webhooks, notifications, audit logs).
Copy the gestionbadgeuserh folder into htdocs/custom (or install the distribution ZIP from Home > Setup > Modules > Deploy external module), then enable the module in the module list. Activation creates the 28 tables and their indexes, the menu entries, the 40 permissions and — on request — the demonstration dataset. Requirements: Dolibarr 16.0+ and PHP 7.1+.
Permissions are organised into 13 functional right groups (topology, hardware, badge, employee, schedule, punch, anomaly, worktime, reference, payexport, reporting, admin, audit) each with Read, Create/modify and Delete columns, plus a dedicated module-administration right — 40 permissions in total. Read and write are granted by default so the module is usable immediately after activation, while delete and administration stay restricted.
· topology — Sites & zones
· hardware — Terminals & connectors
· badge — Badges
· employee — Employees & teams
· schedule — Schedules, cycles & plannings
· punch — Punches, imports & breaks
· anomaly — Anomalies & corrections
· worktime — Overtime, counters, timesheets & validations
· reference — Calc rules, holidays & leaves
· payexport — Payroll exports
· reporting — Reporting & report definitions
· admin — Webhooks & notifications
· audit — Audit logs
· admin_module — Administer the Gestion Badgeuse RH module
Delivered in French, English, Spanish, Italian and German. Every menu, form, status, dictionary code, message, report and dashboard label is translatable, including 372 vocabulary codes across 52 groups, with real UTF-8 accents and no literal % characters. The gbrForceLabels helper reasserts the module's own vocabulary on every page to prevent collisions with other installed modules.
The distribution includes screenshots of: the Smart Attendance Gate Center dashboard, the terminal/badgeuse list and card, the badge list and lifecycle, the real-time presences view, a work schedule, the punches list, the anomalies list and a correction workflow, a timesheet with its validation, an overtime list, the reporting views and the employee self-service portal — all captured on the eldy theme with translated labels (no raw language keys).
28 business objects across topology (sites, zones), hardware (connectors, terminals, badges, badge assignments), people (employees, teams), the time model (schedules, cycles, plannings), events (punches, import lots, breaks), exceptions (anomalies, corrections), work time (overtimes, counters, timesheets, validations), rules & reference (calc rules, holidays, leaves) and output (payroll exports, report definitions, webhooks, notifications, audit logs); a "Smart Attendance Gate Center" dashboard with five gates and a global presence & punctuality index; decision reporting with CSV export; 40 permissions across 13 functional groups plus administration; a secured REST API and webhooks; an employee self-service portal; five languages with 372 vocabulary codes; and a full demonstration dataset with safe removal.
© 2026 DoliResources. All rights reserved. Website: https://www.doliresources.com. Module gestionbadgeuserh, version 1.0.0, numero 1024000, Human Resources family, distributed under the GNU GPL v3+. All files, classes, SQL scripts, language files and documents are produced under the DoliResources copyright.