Device enrollment (PWA devices)#

An installer’s phone is paired to the PWA biometrically. Starting the pairing and managing devices is done from the desktop (work.elt.systems): a lost phone cannot enrol or revoke itself, so creating a code and revoking a device are deliberately desktop‑only.

Where to open it#

  • From the installer’s card: HR → Employees (or the FSM person card) → open the installer → the “Device code / PWA” button (mobile icon) in the top button box. Visible only if the card has a user.
  • From the planning calendar: the “Create device code” button in the toolbar. From the calendar an installer enrols themselves; a foreman can target another installer via the person card.

This opens the Device enrollment dialog.

Creating a code#

  1. (Foreman) pick the installer from the Installer dropdown. An installer sees their own name fixed.
  2. Click “Create device code”.
  3. The dialog shows a QR code, an address and a 9‑character code (XXX‑XXX‑XXX) plus a countdown “Valid 15:00”.
  4. Give these to the installer: they scan the QR with the phone or type the address + code manually. The installer side: Device setup and login.
The code is **single‑use** and valid for **15 minutes**. The code value is not stored, so the same code can't be shown again — if it expires, click **"Create new code"** (revokes the old one and mints a fresh one). Only one code is active at a time. **"Revoke code"** cancels the active code without creating a new one.

Managing devices#

The “Registered devices” section shows the installer’s devices and an N / 3 counter (max 3 active devices per user).

  • Rename: click the pencil icon next to the device name.
  • Revoke: an active device’s “Revoke” invalidates the key immediately — use this when a phone is lost or stolen. Confirmation: “Revoke device …? The key is invalidated immediately and the device stops working.”
  • Remove: an already‑revoked device can be cleared from the list with “Remove”.
  • If the installer already has 3/3 devices, code creation is blocked — revoke one first.

Abuse protection#

The dialog shows the live security state of enrollment:

  • ⚠️ Wrong code attempts: how many wrong codes were entered and after how many more the open codes are wiped.
  • 🔒 Code creation locked for N min — too many wrong attempts.
  • N IP addresses blocked (15 min).

These are automatic safeguards. If creation is locked, wait for the lock to expire and create the code after that.

Troubleshooting#

The installer doesn’t see the registration screen on the phone
Direct the installer to `mobile.work.elt.systems`. If the device is already paired, they see **"Unlock"** (biometric); otherwise **"Register this device"**.
The code expired
The code is valid for 15 minutes. Click **"Create new code"** — the old one is revoked and you get a fresh code to show/scan.
3/3 — I can’t create a code
The user already has the maximum number of active devices. **Revoke** the old or lost device first, then create a new code.
The installer changed phones
**Revoke** the old device from the list and **create a code** for the new phone.