GPS check in and out from a phone, booked holidays read straight from Exelsys, an alert to the right person when somebody does not turn up, and a live map of the whole workforce.
McConnell scoped it, named it and deliberately parked it. Module 6 works out whether somebody is ready and what they are allowed to do. This records whether they arrived, where they are, and tells someone when they did not. The two share one worker record, and Module 6 already describes the interface between them.
Nothing here is a maybe. Each line below is a thing the system does on day one.
The operative gets something they can use with one thumb in the rain. The office gets something worth putting on a screen.
Added to the home screen from a link. No app store, no review queue, no separate iPhone and Android builds. Updates itself.
An empty property with thick walls is the normal case, not the edge case. The check in saves on the phone and sends itself later. The operative never waits and never loses a record.
Phone GPS indoors is often 30 to 100 metres out. The map draws a circle, not a dot, so nobody is ever accused on the strength of a bad fix.
Everyone at their last check in point. Properties as soft zones underneath, so a person who is where they should be sits inside their zone, and a person who is not sits at the end of a line pointing back to it.
Photo from Microsoft 365, name, site, how long they have been there, accuracy, and their last few days. On a phone it becomes a card you tap.
Drag the slider and watch the day happen. Who arrived, when, where, and who never appeared. Useful for a query on a Friday afternoon, and it settles most of them in a minute.
Not a slide deck and not a mockup. It is the real interface running on invented data across a real Glasgow map. It takes about a minute and it answers most of the questions this page raises.
Open the demo → It is password protected. The password is in the email.
The holiday sync was the one part of your brief that could have been a problem. It is not. Your Exelsys web service already publishes everything the alert engine needs.
There is an operation on your Exelsys interface called GetVacationPlan. Given a date range it returns every booked absence across McConnell, with the person, the dates, the absence type, and whether it has actually been approved.
Two things follow from that. First, only approved leave stops an alert, because those status fields let us tell the difference between a holiday and a request. Second, if McConnell already keep shifts in Exelsys, that is where the system learns who should be working on any given day, which is both cheaper to build and more accurate than a rota we hold separately.
One caveat, so that this is not oversold. We have read the interface, not your data. The operations are published on your Exelsys service and the field lists are quoted above, but we have not called them. What remains to confirm is that your Exelsys licence has the absence module enabled and that the account we already hold is permitted to read it. That is a single read only call, and it is the first thing we do in Discovery, before anything is built against it.
It stays read only either way. We only ever read from Exelsys, on every system we build for you. Nothing is written back, and the code physically refuses to send anything that looks like a change.
The reason to spell this out is that a wrong alert costs more trust than a month of right ones earns. Every decision is written down, so when somebody asks why they got an alert, the answer takes ten seconds.
Before go live the engine works out exactly what it would have sent, every day, and you read that in the portal. Not one email leaves the building until you are happy with what you see. Turning it on afterwards takes about thirty seconds and can be turned straight back off.
These are the limits of the technology, not of the build. You should hear them from us before the project starts rather than from someone else halfway through it.
Location is only available while the app is open on screen. That is true on iPhone and Android alike, and there is no way round it. So checking in and out has to be a deliberate tap, which is exactly what you described. What the system cannot do is notice on its own that somebody has arrived somewhere. If that is what you need, it is a native app and a different conversation, and we would tell you that rather than build the wrong thing.
The system will reliably spot that somebody checked in five hours ago and never checked out, and tell the right person. It is not a monitored alarm with a receiving centre and a duress button behind it, and it should not be relied on as one. If McConnell need that, it is a separate product with a monitoring contract attached.
No web app can prove a phone was not fed a false position. We do catch the obvious cases, an impossible journey between two check ins, a suspiciously perfect location, a check in from a desktop, a device that changes every day, and we flag them for a human to look at. What the policy should say is that a flag starts a conversation and never an automatic sanction. That protects McConnell as much as it protects the operative.
The design does most of the heavy lifting here. The system records two points a day that the person chooses to send, at the moment they send them. It is not a trail, it does not run in the background, and it goes quiet outside working hours. That is a far easier position to defend than continuous tracking, and it is a deliberate choice rather than a limitation.
A short legitimate interests assessment, and most likely a data protection impact assessment, because monitoring staff location sits on the regulator's higher risk list.
Consent is the wrong basis for this. Staff consent is not freely given and it collapses the first time somebody says no, which would leave you with a system you cannot use.
We write the technical half of both documents. McConnell own them and sign them. It is about a page each, and it is included in the price rather than being an extra. The one thing worth insisting on is that the workforce is told before go live rather than after.
Priced as six pieces of work, each signed off on its own. It is seven days rather than seven weeks because almost none of this starts from nothing: the Microsoft sign in, the scheduling, the alerting and the Exelsys connection already run on your training system, and the operations map is already built. You have just clicked it.
| # | Work | What you get | Days | Price |
|---|---|---|---|---|
| 0 | Discovery | The open questions below, and one read only check against your live Exelsys data so the holiday sync is built against what is actually there | - | Included |
| 1 | Cloudflare foundation | The app on your own Cloudflare account, M365 sign in, roles and permissions, database and storage, the scheduled job | 1 | £450 |
| 2 | The phone app | Check in and out with GPS, works with no signal and sends when it finds one, installs on iPhone and Android, the operative's own history and privacy screen | 2 | £900 |
| 3 | Properties and patterns | Property import with postcodes turned into map positions, geofence per property, working patterns, and the college day screen | 1 | £450 |
| 4 | Holidays and alerts | Nightly read only Exelsys sync, bank holidays including the Scottish calendar, the missed check in alert with its silent shadow week, and the overdue check out sweep | 1 | £450 |
| 5 | The map | The operations map you have just used, on your real properties and your real people, plus the exceptions screen | 1 | £450 |
| 6 | Data protection and rollout | Technical sections of the impact assessment, input to the legitimate interests assessment, retention rules, the workforce notice, pilot and go live | 1 | £375 |
| Total | 7 | £3,075 |
Discovery is not charged. Live in around three weeks. Estimates are confirmed at the end of Discovery, and the seven days assume the seven questions below are answered, because at this size there is no slack for a surprise.
It sits on the Cloudflare account McConnell already have, alongside the training system. No new licences and no per user fee.
We host the map data ourselves. Google and Mapbox bill you per view, which is exactly the wrong model for a screen left open all day. Ours costs nothing per view, and no outside company is ever told where your staff are.
Same sign in, same hosting, same read only Exelsys connection as your training system. Not a fourth supplier and a fourth password.
A fixed price is only worth having if both sides know what is inside it. These are real and useful, they are simply not in the £3,075, and none of them stops the system working on day one. Prices are at the same rates, and any of them can be added later without rework.
| Later, if you want it | Why it is not in the seven | Days | Price |
|---|---|---|---|
| Routed and escalating alerts | In the seven days the alert goes to one named person per team. Routing by property and region, and chasing it up the line when nobody acknowledges, is real work on its own | 1 | £450 |
| Text messages as well as email | Email is included. A text needs a supplier decision and carries a cost per message | 1 | £450 |
| Rounds of several properties | The seven days assume roughly one property per person per day. Treating a day as a route rather than a point changes the app, the map and the alert logic | 2 | £900 |
| Photo evidence on check out | Useful for disputes and for job records, but it is a separate capture, storage and viewing job | 1 | £450 |
| Reporting and payroll export | Hours on site by person, by property and by week, exported | 1 | £450 |
| The impact assessment written for you | The seven days include the technical sections and the retention rules. Writing and owning the whole document is a different job, and it is properly McConnell's | 1 | £375 |
A tidy spreadsheet of properties with postcodes is half a day and it is inside the seven. Property names spread across contracts with no postcodes is not, and it is the single most likely thing to push this over. It is question 3 below, and it is the one worth checking before you commit the budget.
These are the things that genuinely move the number. Everything else we can decide as we go.
The training and competency system is live on your own domain behind your Microsoft sign in, reading from Exelsys, sending scheduled digests to managers. The project microsites are live. The SHEQ platform demo runs offline on a phone.
This project reuses the sign in, the scheduling, the alerting and the Exelsys connection from those systems. That is why the foundation is one day rather than three weeks, and it is why seven days is a real number rather than an optimistic one.
Everything is built on infrastructure McConnell own, in the UK, with the source code yours.