Time & Attendance FAQ
Answers to common setup and operating questions about Time & Attendance.
For what the app is and how to set it up from scratch, see the
Time & Attendance Overview.
Setup
Do I need Shifts & Scheduling before Time & Attendance works?
Not necessarily. By default, employees can clock in without a scheduled shift — the system creates an ad-hoc shift at the moment they punch. If you want to require a scheduled shift before anyone can clock in, turn on Require Shift for Clock-In in Admin → Attendance Settings. That setting is off by default because Shifts & Scheduling is a separate licence.
Who can see attendance records once I turn the app on?
Every employee sees their own clock history. Managers see records for their direct reports and for employees at locations they are assigned to. The View All Attendance capability (configurable in the app’s authorization settings) controls who sees records beyond their own authority — the default is App Admins (business admins plus anyone you delegate as a Time & Attendance app administrator). You can widen it to Managers or restrict it to Specific users.
Permissions and access
Why can’t our Time & Attendance app administrator see all records?
Check two things. First, the person must be granted the Time & Attendance app-admin role in the platform’s App Administrators setting — a business admin or super admin has it automatically, but a delegated app-admin needs the explicit grant. Second, the View All Attendance capability must be set to App Admins (the default) or Managers. If it is set to Specific users, only the named individuals see records outside their own reporting chain.
Who can clock in on behalf of an employee?
Managers and admins can add a manual record or clock someone in from the manager dashboard. Managers can do this for their direct and indirect reports and for employees assigned to their locations, but never for themselves. Admins can add a record for any employee in the business.
Day-to-day
How does the system decide whether someone is late?
It compares the clock-in timestamp against the scheduled shift start plus the late grace period. The default grace period is 30 minutes (admin-configurable in Attendance Settings). A punch within the grace period is on-time; a punch after it is late. Ad-hoc shifts — created when no scheduled shift exists — are always treated as on-time. A tardiness that rounds to less than one full minute is also treated as on-time, so employees are never flagged “late by 0 minutes.”
What happens when an employee forgets to clock in or out?
They can submit a missing-punch request from the Time & Attendance app with the correct clock-in and clock-out times, any breaks taken, and a reason (5–1,000 characters). The request must fall within the retroactive window, which follows the Timesheet Lockout Days setting (default 7 days). It routes to the employee’s manager for review and is never auto-approved. A single missing-punch request cannot span more than 24 hours.
What does auto clock-out do, and when does it fire?
Auto clock-out closes forgotten punches automatically so they do not stay open indefinitely. It has two rules, both on by default for new tenants:
- After shift end — closes a scheduled punch after the configured number of minutes past the shift’s end time. Default: 30 minutes (admin-configurable, max 480).
- Maximum hours — closes any open punch that has been running longer than the configured limit. Default: 12 hours (admin-configurable, max 24).
A stale punch left open beyond 24 hours is closed by the system regardless of these settings. Every auto-closed punch is flagged for manager review.
How are meal and rest breaks tracked?
When an employee clocks in, the system automatically creates a break record for each break type your business has marked as Required. Break types default to 30 minutes and Paid. Paid break time stays in payable hours; unpaid break time is subtracted. If an employee ends a required break short of its configured duration, the record is flagged for manager review. Any break still in progress when the employee clocks out is auto-completed at the clock-out time.
What is the difference between Time & Attendance and Timesheets?
Time & Attendance records discrete clock events — each clock-in and clock-out is a record with a status (on-time, late, or missed), a punch source, and verification data. Timesheets aggregate those events into pay-period hours for review and approval. Every clock event, including breaks, syncs into the matching timesheet in real time, where hours roll up into overtime, double-time, and premium-pay totals. In short: attendance answers “when did they punch and was it valid?”; timesheets answer “how many payable hours this period, ready to approve?”
When something looks wrong
“I clocked in but it says I’m a no-show”
This happens when the no-show detector ran before the employee punched. If the employee then clocks in (for example through the kiosk’s grace window), the no-show flag is automatically cleared and the record is reclassified as on-time or late based on the actual punch time. If the flag persists, a manager can review and approve the record from the Requires Review queue.
“I can’t clock in — it says the clock-in window is closed”
The Enforce Time Window Restrictions setting is on, and the employee is outside the allowed window. Clock-in is allowed from the Early Clock-In Buffer (default 15 minutes) before shift start until the shift ends. After the shift ends, the window closes. Ad-hoc shifts (no scheduled shift) are not subject to this restriction. If this is a legitimate late arrival, a manager can add a manual record.
“My punch was flagged for review — what triggered it?”
A punch is flagged when any verification check fails. The review reason appears on the record and can include:
- Suspicious IP address — the punch came from an IP not on the allowed list (when IP validation is enabled)
- Outside allowed time window — punched outside the early/late buffer
- Unknown device — device fingerprint not previously seen for this employee (when device verification is enabled)
- Location verification failed — GPS coordinates outside the location’s geofence radius (when location verification is enabled)
- Photo verification failed — no photo provided or camera unavailable (when photo verification is required)
Why did a manager correction not show up in the timesheet?
Check whether the correction was saved successfully — the manager should see a confirmation. Clock-in and clock-out time changes sync to the timesheet automatically. If the adjustment involved a missing-punch request, it must be approved with a positive outcome (Approved, Adjusted, Time Corrected, Location Accepted, Tardiness Accepted, or Security Verified) before hours appear on the timesheet. Rejected, Unexcused Absence, and Excused Absence outcomes do not promote hours.
Clock-in methods and security
What are the three IP validation modes?
IP validation must first be turned on with the Enforce IP Validation for Clock Actions toggle in Attendance Settings. Once on, you choose a mode:
- Passive — IP addresses are recorded but no restriction is enforced.
- Warning (default) — punches from unauthorized IPs are flagged for manager review but still accepted.
- Strict — punches from unauthorized IPs are blocked entirely.
When GPS coordinates are not available, the system falls back to IP-based geolocation for location verification.
How does the kiosk PIN lockout work?
The kiosk locks out after 5 failed PIN attempts per device for 5 minutes. A broader lockout triggers after 20 failed attempts across all devices on that kiosk for 10 minutes. Pairing-code guessing is also limited: 10 failed attempts per code lock out for 10 minutes, and 50 failed attempts across a whole business lock out for 10 minutes. Lockouts decay automatically — no admin action is needed to clear them.
Can employees clock in from a personal device or from home?
By default, no. The Allow Remote Clock-In and Allow Off-Site Clock-In settings are both off. When you enable them, employees can choose a work mode (On-Site, Remote, or Off-Site) at clock-in. Remote and off-site punches skip geofence verification but still record GPS coordinates for the audit trail. Only on-site punches appear in “who is in the building” counts.
Notifications
What attendance notification rules can I create?
Eight rule types are available: Missed Check-In, Missed Check-Out, Late Check-In, Early Check-Out, Suspicious Activity, Location Mismatch, Consecutive Late Check-Ins, and Consecutive Missed Check-Ins. Each rule has a severity (Low, Medium, High, or Critical) and a delivery channel — In-App is the recommended default because it also delivers push notifications. Email and SMS are available but reach fewer employees in a typical frontline workforce.
Licensing and limits
Does Time & Attendance require a licence?
Yes. An admin enables it from the Apps Marketplace; it is not turned on automatically. Once enabled, admins must also publish it to employees (it starts in admin-only mode until published).
Are there limits I should know about?
| What | Limit |
|---|---|
| Auto clock-out maximum hours | 1–24 hours (default 12) |
| Auto clock-out after shift end | 0–480 minutes (default 30) |
| Early clock-in buffer | 0+ minutes (default 15) |
| Late clock-in grace period | 0+ minutes (default 30) |
| Missing-punch retroactive window | Follows Timesheet Lockout Days (default 7 days) |
| Missing-punch maximum span | 24 hours |
| Missing-punch reason length | 5–1,000 characters |
| Stale open punch cutoff | 24 hours (system-enforced, not configurable) |
| Attendance CSV export | 10,000 records per export |
| Kiosk PIN lockout | 5 attempts → 5-minute lockout |
| Kiosk session lockout | 20 attempts → 10-minute lockout |
| Kiosk pairing-code lockout | 10 attempts → 10-minute lockout |
| Clock-out reminder lead time | 5–60 minutes (default 5) |
| Overtime warning threshold | 20–80 weekly hours (default 40) |
| Max autonomous actions per day | 1–500 (default 50) |
More help
- Time & Attendance Overview
- Ask AI — the assistant answers Time & Attendance questions from these articles.