Section 3 of 13
Panel: sign-in and accounts
Two accounts with different rights, password rules, lockout after failed attempts and the second factor.
Two accounts
- admin
- Full access: settings, network, relay, updates, attendance records. Always active.
- biuro
- The office account: reports, the employee list and correcting punches. No access to device settings. DISABLED out of the box — you enable it by giving it a password. The account name stays
biurowhatever language the panel is set to.
The office account exists so that whoever settles working hours does not need the administrator password. Clearing its password disables it again.
Password rules
- Panel password: at least 10 characters. WiFi password: at least 8.
- Rejected: a single repeated character, and anything containing an obvious pattern such as
12345678,qwerty,passwordoradmin. - We do not demand an uppercase letter, a digit and a symbol. Rules like that end in
Passw0rd!, which falls faster than four random words.
The device never sends passwords back to the browser. In the settings form an empty password field means no change — it does not mean clear it.
Sessions and lockout
- A sign-in lasts 16 hours. Restarting the device signs everyone out.
- Up to eight people can be signed in at once.
- After five failed attempts the account is locked for a growing period, from 2 seconds up to a minute. The panel then shows how many seconds remain, instead of a misleading wrong password.
Second factor
The administrator account can additionally require a code from an authenticator app — Google Authenticator, Aegis, 1Password, Bitwarden, anything that handles standard six-digit codes.
- 1
Set the device clock first. Without it the codes will not match.
- 2
In settings, enable the second factor and scan the code with your app.
- 3
Type in the six digits. Only this step stores the setting on the device — if anything goes wrong, nothing changes and you keep signing in with the password alone.
Turning the second factor off, or replacing it, requires a current code from the app that still works. The password alone is not enough — so a hijacked session cannot strip the protection.