RIO Ready: QR Attendance Setup
Post-deployment steps to configure QR Attendance for a new org.
Table of Contents
Overview
Before using the QR Attendance functionality, complete the following setup steps:
- Assign the permission sets.
- Register the trigger handler.
- Schedule the auto-expiry batch.
- Configure QR Settings.
- Add the ipify.org CSP Trusted Site.
- Confirm sharing rules.
- Add the QR scan page to your Experience Cloud site.
- Add the QR Attendance Generator component to the Booking page.
- (Optional) Set up the WiFi/location check.
- (Optional) Set up Check Other As Late.
- Test the flow.
Step 1: Assign Permission Sets (Objects/Fields/Apex Classes/User Permission)
Grant the necessary permissions for each component to users. Ensure these are assigned to the relevant profiles or permission sets.
| User Type | Type of Permission | Component Name | Access Type |
| Admin | Object | redu_QR_Token__c | Read/Write (full CRUD) |
| Admin | Custom Field | Account.redu_WiFi_Network_Name__c | Read/Write |
| Admin | Custom Field | hed__Facility__c.redu_Effective_WiFi_Network_Name__c | Read (formula field) |
| Faculty | Permission Set | QR Attendance - Faculty | Assign |
| Student | Permission Set | QR Attendance - Student | Assign |
Step 2: Register the Trigger Handler
- Open the Developer Console.
- Go to Debug > Open Execute Anonymous Window.
- Run: redu_QRTokenExpiry_TDTM.installTDTMSetting();
Note: This step is safe to run again if you are not sure whether it has already been done — it will not create a duplicate registration.
Step 3: Schedule the Auto-Expiry Batch
- Navigate to Setup > Apex Classes > Schedule Apex.
- Schedule redu_QRTokenAutoExpiry_BATCH to run every 5–15 minutes.
Step 4: Configure QR Settings
- Navigate to the QR Settings custom setting > Manage > New (Org Default).
- Experience Site URL (required) — the full URL of the QR scan landing page created in Step 7.
- Auto Expiry Batch Size (optional) — leave blank to use the default of 50.
- Check Other As Late field names (optional) — see Step 10.
- Enable Skip WIFI Check (optional) — Enable this to have Skip WIFI check feature in generator.

Step 5: Add the ipify.org CSP Trusted Site
Note: This step is required for the WiFi/location check to work at all. Without it, every scan on a WiFi-restricted class is blocked with a "could not verify your network connection" error.
The student landing page resolves the scanning device's public IP with a direct browser call to api.ipify.org. This must be allow-listed per org:
- Navigate to Setup > CSP Trusted Sites > New Trusted Site.
- Trusted Site URL: https://api.ipify.org
- Context: All (or Communities, at minimum).
- Check Active and enable it for connect-src (allow the site to be called from scripts).

Step 6: Confirm Sharing Rules
- Navigate to Setup > Sharing Settings for the QR Token object.
- Confirm the two faculty owner-based sharing rules exist, granting faculty Edit access to the QR Tokens they generate.
- No student-facing sharing rule is required — the student attendance-marking logic does not depend on row-level sharing.

Step 7: Add the QR Scan Page to Your Site
- In Experience Builder, create a standalone page (for example, /qr-attendance) that requires login.
- Drag the QR Attendance Landing component into the page's single region.
- Set the page's audience/visibility to the student profile.
- Publish the site, then copy this page's full URL into the Experience Site URL setting from Step 4.

Step 8: Add the Generator Component to the Booking Page
- In App Builder, open the Booking record page.
- Drag the QR Attendance Generator component into the desired region, or replace the record detail section with it entirely.
- Save and activate the page.
Note: The component's Late Grace Period (Minutes) property defaults to 10, and Token Expiry defaults to the Booking's End time (0 or blank = right at End; a negative value cuts scanning off earlier, a positive value allows a short grace window past End). Both can be adjusted per placement in the property panel.

Step 9 (Optional): Set Up the WiFi/Location Check
- Create a WiFi Network custom metadata record for each physical classroom network, with its allowed IPv4 and/or IPv6 address ranges.
- On each Facility record, set the WiFi Network Name field to match a WiFi Network record's Developer Name exactly.
- To share one configuration across many Facilities, set the WiFi Network Name on a Parent Facility or an Account instead — a Facility with its own field left blank inherits from its Parent Facility first, then its Account.
- Leave the WiFi Network Name blank on the Facility, its Parent Facility, and its Account to skip the check entirely for classes at that Facility.



Step 10 (Optional): Set Up Check Other As Late
- In QR Settings, set the Other Status Field Name and Attendance Marking Additional Field Name to the real field names to use.
- Grant field-level access to both fields on both the Faculty and Student permission sets.
- This only changes how a late scan (after the grace period) is recorded — a student who never scans before the code expires is always marked plain Absent, regardless of this setting.
Step 11: Test the Flow
- Generate a QR code from a Booking.
- Scan it as an enrolled student and confirm attendance is marked.
- If the WiFi restriction is configured, test scanning from both inside and outside the allowed network.