Device Management & MDM Operations3 min readUpdated September 2026

Kandji vs Rippling IT When Warehouse Tablets Share a Login

For a wholesale distributor, Kandji or Rippling can manage the office and sales laptops, but neither ties activity on a shared warehouse tablet to a person. The fleet is really two fleets: named-employee laptops that follow your HR setup, and shared receiving tablets that need supervised kiosk-mode lockdown.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Two different device problems living under one roof

A laptop assigned to a named employee can be tracked, encrypted, and tied to that person's access the way most device management is designed around. A shared tablet running a receiving or picking app under a generic login was never built for that model: it belongs to a role and a location, not a person, and it gets handed off between shifts without anyone logging in or out. A platform that only accounts for the first kind of device leaves the second kind essentially invisible. Start by simply counting how many devices fall into each category before deciding on a platform for either one.

Why a shared login on the warehouse floor creates a blind spot

When eight people share one tablet login across two shifts, there is no record of who was using it at the time a shipment was marked received incorrectly or a device went missing from the dock. That is a real operational problem before it is a security one. Kiosk mode and supervised device profiles, available on both platforms in different forms, can lock a shared tablet to a single app and prevent it from being used for anything else, which narrows what a shared login can actually do even if it can't identify who was doing it.

Kandji's case for the office and sales fleet

For the named-employee laptops, Kandji's zero-touch enrollment and patch enforcement work the way they do at any other company: a new sales rep or buyer gets a laptop that is already encrypted and current before their first day, without anyone in the office walking them through setup. That part of the fleet looks like a fairly standard device management problem, and Kandji handles it without needing anything specific to distribution.

Rippling's case when warehouse staff turn over fast

Rippling's tie to staffing records helps most on the office and sales side of the fleet, where laptops are assigned to named employees whose hiring and departures already flow through the same system. Warehouse staff turning over on shared tablets don't benefit from that same tie, since the tablet itself never changes hands in a way tied to an individual employee record. The value shows up on the laptop side of a distributor's fleet, not the shared-device side.

A worked example: locking down eight shared receiving tablets

Say a warehouse runs eight tablets across two shifts, all logged into one shared receiving account. Putting each tablet into a supervised, single-app kiosk profile through either platform means the device can only run the receiving app, nothing else, and can't be used to browse the internet or install anything a shift worker might add on a slow afternoon. Pair that lockdown with a shift log kept separately, even a simple sign-in sheet at the start of each shift, and you get most of the accountability an individual login would have provided without the overhead of managing individual accounts for a rotating crew.

To lock down shared receiving tablets, follow these steps:

  1. Put each tablet into a supervised, single-app kiosk profile so it can only run the receiving app.
  2. Block web browsing and app installs on the device, so a shift worker cannot add anything.
  3. Keep a separate shift log of who held each tablet, since neither platform can identify a person on a shared login.
  4. Enroll every spare tablet before it goes into a drawer, so a swap never puts an unprotected device on the dock.
  5. Update the enrolled-device list whenever a tablet is dropped, swapped or handed to a temp worker.

A mistake that shows up during a busy receiving week

The gap that tends to surface is a shared tablet that gets dropped, swapped for a spare, or handed to a temp worker during a busy receiving week, without anyone updating which device is actually enrolled and locked down. The original tablet's kiosk profile does nothing for a spare pulled out of a drawer and never enrolled in the first place. Keep a small pool of pre-enrolled spares ready for exactly this situation, so a busy week never becomes the reason an unmanaged tablet ends up on the floor.

Picking the right model for each half of your fleet

There is no single answer here, because a distributor's fleet is really two fleets. Named-employee laptops should run on whichever platform fits your existing HR and staffing setup, Kandji for a simpler, Mac-focused baseline or Rippling if staffing records already live there. Shared warehouse tablets need kiosk-mode lockdown regardless of platform, paired with a shift log the device itself can't provide, since neither platform was built to identify an individual user on a device nobody logs into by name.

Executive Capability Standard

What Good Looks Like

Named-employee laptops are encrypted and enrolled before day one, and every shared warehouse tablet runs in a locked-down, single-app profile with a separate shift log to cover what the shared login can't.

Building The Capability (5-Stage Skill Ladder)

1. Learn:List which devices in your fleet are tied to a named employee and which run under a shared login, since they need different rules.
2. Do Manually:Keep a paper or spreadsheet shift log at each warehouse station until a more automated tracking method is in place.
3. Delegate:Assign a warehouse supervisor to own the shared tablets' kiosk configuration, separate from whoever manages the office laptop fleet.
4. Automate:Deploy Kandji or Rippling for the named-employee fleet so encryption and patching apply themselves without manual setup.
5. Buy:Add a supervised kiosk-mode profile to every shared warehouse tablet so it can only run the app it's meant for, nothing else.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Should warehouse tablets have individual logins for each staff member?

Not necessarily. A shared login paired with a locked-down kiosk profile and a separate shift log gets most distributors reasonable accountability without the overhead of managing individual accounts for a rotating crew. Individual logins matter more once a specific incident makes that gap a real problem.

Can Kandji or Rippling identify which shift worker was using a shared tablet?

No. Neither platform ties activity to an individual when the device runs under one shared login. That gap has to be closed with a separate process, like a sign-in sheet at the start of each shift, rather than expected from the device management platform itself.

Does kiosk mode work the same way on a warehouse tablet as it does on an office laptop?

The concept is the same, locking the device to a single app or a narrow set of functions, but it's applied differently. A warehouse tablet in kiosk mode typically runs only the receiving or picking app, while an office laptop keeps its normal range of software and gets locked down through encryption and access controls instead.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides