Skip to content

Biometric, Face & Location Verification

This guide covers the optional hardware and location-based ways the system can verify a clock-in.

Purpose

For some organizations, a web button isn't enough — attendance needs to be tied to a physical device, a verified face, or a specific location. This answers: "How do we make sure a clock-in is really who and where it says it is?"

Biometric Devices

The system can connect to biometric attendance devices (fingerprint and card-based terminals from several common vendors) and pull punches from them automatically, either continuously or on a scheduled interval. Each device user is mapped to an employee once, and from then on, every punch from that device flows through the exact same attendance logic as a web clock-in — late-come, grace time, and overtime rules all apply identically, regardless of how someone actually punched in.

Face Photo Capture

When enabled, employees can register a reference photo of themselves, tied to their profile. This supports face-based verification on compatible clock-in hardware or apps — the system stores and manages the reference photo, while the actual matching happens on the verifying device or application.

Location Restriction (Geofencing)

A company location and radius can be configured, restricting clock-ins to within that distance. This applies to clock-ins made through the system's API — such as a mobile app — where the device's location is checked against the configured radius before the punch is accepted.

Geofencing only applies to API-based clock-ins

The standard web clock-in button does not currently enforce this location check.

Network Restriction

Separately, clock-ins from the web can be restricted to a specific set of allowed network addresses — useful for requiring that attendance only be marked from an office network. This check doesn't apply to biometric device punches, which are trusted as coming from the device itself.

What Each User Sees

ActionEmployeeHR Administrator
Clock in via a connected biometric device
Register their own reference photo✅ (if enabled)
Configure devices, face detection, geofencing, or network restrictions

How Visibility Is Decided

  1. Configuration is administrative. Setting up devices, enabling face capture, and configuring location or network restrictions all require the relevant permission.
  2. Participation is individual. Registering a reference photo, and clocking in through a connected device, is something every employee does for themselves once the feature is turned on.

Customization Options

  • Which biometric devices are connected, and whether they're polled continuously or on a schedule, is configurable per device.
  • Face capture is an opt-in company setting.
  • Location radius and allowed networks are both configurable, and independent of each other — a company can use one, both, or neither.

Good to Know

  • All of this is optional. A company that only wants a simple web clock-in button doesn't need to touch any of these settings.
  • Biometric and web clock-ins produce identical attendance records — there's no separate "biometric attendance" data to reconcile; it's the same Attendance module either way.
However they punch in, it counts the same.