TimeTac
Cloud time tracking, attendance and leave management for teams, with clock-in via web, mobile and terminals.
If you are one person logging hours against projects, this is a solved evening: a table, a timer, a CSV export, done. TimeTac is not sold for that, it is sold to companies that must prove who worked when, which in Spain means a daily time record that survives an inspection. An agent can absolutely build the clock-in screen, the leave calendar and the monthly timesheet PDF, and it will feel surprisingly complete. What it will not hand you is the tamper-resistant audit trail, the payroll and HR exports your accountant already accepts, and the phone app your field staff will actually open. So: yes for yourself, shaky the moment other people's paychecks depend on your SQLite file.
Build verification: not recorded. How we judge buildability
What you give up
- Legally defensible records: no tamper-evident log, no retention guarantees, nothing an inspector or works council will nod at
- Native iOS and Android apps with GPS, offline clock-in and geofencing for people who are not at a desk
- Hardware terminals and badge or fingerprint clock-in for shop floors
- Payroll, ERP and HR integrations plus the export formats your bookkeeper already imports without complaining
- Someone else owning uptime, overtime rule edge cases and the shift and break math for each country
Why people still pay
Companies do not buy time tracking because timers are hard, they buy it because a missing time record is a fine and a disputed overtime claim is a lawsuit. The paid version comes with rule sets for breaks, overtime and absence accrual per country, exports that payroll accepts, apps that work on a phone in a van, and a vendor to point at when something is wrong. A self-hosted app you wrote yourself is fine for your own invoicing and a bad idea the moment an employee disagrees with it.
Your build guide
The stack, security requirements, and agent rules for a focused replacement.
Before you start
- Runtime and tools: TypeScript, React, Node and PostgreSQL with workspace membership enforced on the server.
- Before starting: A PostgreSQL database, session authentication, two isolated example workspaces and private attachment storage.
Use these project rules and optional skill references alongside the prompt. Review each skill before adding it to your agent; the AGENTS.md export includes the same guidance.
Project rule — domain: Store Employee, WorkInterval, Break, ProjectAllocation, LeaveRequest and Approval; no overlapping open intervals and post-approval corrections create a visible amendment.
Project rule — scope and recovery: This is a time ledger, not automatic labor-law or payroll compliance. Document rounding, breaks and local policies explicitly; restrict individual records to authorized roles.
Project rule — acceptance: Clock out after midnight, allocate time to two projects and correct an approved entry; totals reconcile with the chosen timezone and the earlier approved export stays reproducible.
Project rule — delivery: document real setup commands and permissions; do not claim a build, accuracy level, performance result or security certification that has not been demonstrated.
Recommended skill: supabase-postgres-best-practices — review this PostgreSQL domain schema, uniqueness constraints, transaction boundaries and access-scoped queries; Supabase hosting is not required. Follow the maintainer's installation instructions and match its requirements to the chosen runtime.
Recommended skill: web-design-guidelines — review keyboard access, focus, validation, error recovery and the readable work/review interface or HTML report. Follow the maintainer's installation instructions and match its requirements to the chosen runtime.
Implementation plan
Phase 1
Pin the working slice and create its example input: Record clock-in/out and project time, request leave and let a reviewer approve a versioned monthly timesheet export. Confirm setup: A PostgreSQL database, session authentication, two isolated example workspaces and private attachment storage.
Phase 2
Implement persistence and write-time invariants before decorating the UI: Store Employee, WorkInterval, Break, ProjectAllocation, LeaveRequest and Approval; no overlapping open intervals and post-approval corrections create a visible amendment.
Phase 3
Connect the working view to real saved state. Check membership on reads, mutations, attachments and exports. Keep activity history separate from editable current state; do not make private records public through search.
Phase 4
Expose the app-specific limits and recovery path in context: This is a time ledger, not automatic labor-law or payroll compliance. Document rounding, breaks and local policies explicitly; restrict individual records to authorized roles.
Phase 5
Walk through this concrete acceptance case and preserve its exported evidence: Clock out after midnight, allocate time to two projects and correct an approved entry; totals reconcile with the chosen timezone and the earlier approved export stays reproducible. Finish the README and backup/restore instructions; report unfinished capabilities explicitly.
Build the following focused alternative to TimeTac. This is a deliberately limited personal or small-team substitute, not parity with the paid service. WORKING SLICE Record clock-in/out and project time, request leave and let a reviewer approve a versioned monthly timesheet export. SETUP AND ARCHITECTURE Use TypeScript, React, Node and PostgreSQL with workspace membership enforced on the server. Prerequisites: A PostgreSQL database, session authentication, two isolated example workspaces and private attachment storage. Before integrating anything, record actual versions and permissions, plus model files or provider limits only where used, in the README; make unavailable dependencies visible rather than simulating success. DOMAIN MODEL AND INVARIANTS Store Employee, WorkInterval, Break, ProjectAllocation, LeaveRequest and Approval; no overlapping open intervals and post-approval corrections create a visible amendment. IMPLEMENTATION CONTRACT Check membership on reads, mutations, attachments and exports. Keep activity history separate from editable current state; do not make private records public through search. Provide an input/setup view, the main work view, and a review/export view appropriate to this workflow. Preserve the last saved state if a job or save fails. Include empty, loading, permission-denied, partial and retryable-error states. Log identifiers and error categories without secret values or unnecessary private content. APP-SPECIFIC BOUNDARY AND RECOVERY This is a time ledger, not automatic labor-law or payroll compliance. Document rounding, breaks and local policies explicitly; restrict individual records to authorized roles. ACCEPTANCE SCENARIO Clock out after midnight, allocate time to two projects and correct an approved entry; totals reconcile with the chosen timezone and the earlier approved export stays reproducible. Also reopen the app after an interrupted operation, confirm the saved record/export remains inspectable, and document the recovery action. These are implementation acceptance requirements, not a claim that this guide has been tested. DELIVERY Deliver a runnable repository with migrations or project-format versioning, a non-sensitive example, environment/permission setup, the exact manual acceptance steps, and a backup/export-and-restore walkthrough. Implement the working slice before optional integrations; list any deferred paid-product capabilities honestly. Do not add capabilities outside the working slice just to resemble the original product. PROJECT RULES FOR AGENTS.md Keep the domain invariants above executable at the write boundary. Propose scope changes before adding providers or permissions. Never fabricate source evidence, publish results, identity matches or successful delivery. Preserve user originals and require an explicit confirmation for destructive changes or external publication.
$ open in your agent (prompt prefilled, you press enter), copy the prompt or copy or download AGENTS.md · generated from this app's build plan
prompt copied. want to know what dies next week?
new verdicts + top votes, weekly. free. one-click out.
No prior-art project is listed yet. Compare the scoped build with the paid product before choosing.
Questions about TimeTac
Can you build your own TimeTac with AI?
Partly. If you are one person logging hours against projects, this is a solved evening: a table, a timer, a CSV export, done. TimeTac is not sold for that, it is sold to companies that must prove who worked when, which in Spain means a daily time record that survives an inspection. An agent can absolutely build the clock-in screen, the leave calendar and the monthly timesheet PDF, and it will feel surprisingly complete. What it will not hand you is the tamper-resistant audit trail, the payroll and HR exports your accountant already accepts, and the phone app your field staff will actually open. So: yes for yourself, shaky the moment other people's paychecks depend on your SQLite file.
What does the TimeTac build prompt cover?
The prompt starts with this scope: Record clock-in/out and project time, request leave and let a reviewer approve a versioned monthly timesheet export. Full-product capabilities excluded from the comparison include: Legally defensible records: no tamper-evident log, no retention guarantees, nothing an inspector or works council will nod at; Native iOS and Android apps with GPS, offline clock-in and geofencing for people who are not at a desk; Hardware terminals and badge or fingerprint clock-in for shop floors. Follow the implementation plan and its prerequisites before expanding the build.
How do I use the prompt, AGENTS.md and agent skills?
Start with the TimeTac prerequisites and stack, then copy the prompt into your coding agent. Save the project rules as AGENTS.md in the project root. Linked skills are optional packages or source instructions for specific tasks; review their current contents and install only those matching the chosen stack. A skill does not supply API credentials or verify the finished app.
How long will this TimeTac project take?
The catalogue estimate is a weekend for the limited scope. Setup, integration approvals, debugging, deployment and ongoing maintenance can add time. This is an estimate, not a delivery guarantee.
What would I give up by replacing TimeTac?
Legally defensible records: no tamper-evident log, no retention guarantees, nothing an inspector or works council will nod at; Native iOS and Android apps with GPS, offline clock-in and geofencing for people who are not at a desk; Hardware terminals and badge or fingerprint clock-in for shop floors; Payroll, ERP and HR integrations plus the export formats your bookkeeper already imports without complaining; Someone else owning uptime, overtime rule edge cases and the shift and break math for each country. Companies do not buy time tracking because timers are hard, they buy it because a missing time record is a fine and a disputed overtime claim is a lawsuit. The paid version comes with rule sets for breaks, overtime and absence accrual per country, exports that payroll accepts, apps that work on a phone in a van, and a vendor to point at when something is wrong. A self-hosted app you wrote yourself is fine for your own invoicing and a bad idea the moment an employee disagrees with it.
What price is this guide comparing against?
The recorded Employee Time Tracking module plan is $7.2/mo per seat (monthly per user, per module, plus a base fee), checked 2026-08-18. Check the linked pricing source before buying. Building your own also has hosting, API and maintenance costs; the recorded amount is not a guaranteed saving.
What can I use instead of building TimeTac?
No alternative is listed in this entry yet. That is a gap in this catalogue, not proof that no suitable product exists. Compare the paid product and the proposed scope before committing to a build.