Clock-In Systems
Terminals, badges, apps and biometric readers. What each records, what each costs, and where the biometric option changes the analysis entirely.
Reference
Where the question is when someone started and stopped, a clock is the direct answer and the one that best fits the statutory recording duty.
The methods
Fixed terminal with a code or badge. Cheap, familiar, and it records presence at a place.
Mobile application, which suits distributed and site-based work and raises the location question below.
Badge or card on a reader, frequently reusing an existing access control system.
Biometric reader — fingerprint, palm, face — which is a different proposition and has its own section.
Automatic from access control, which infers working time from entering and leaving the building.
What each actually records
A terminal records that a credential was presented, not that a person was there. Badge sharing is the recurring integrity problem and it is why biometrics are proposed.
A mobile app records that a device reported at a time, with whatever location accuracy was available.
Access control records a door event, which is not the start of work: people arrive, change, get coffee, and the gap is either unpaid time the worker disputes or paid time the employer disputes.
Be precise about what the record means, because in a dispute the difference matters.
Biometrics
A fingerprint or face used to identify someone is biometric data, with the heavier obligations described in the data protection note.
Several jurisdictions restrict it specifically, with consent requirements, retention schedules and in some places a private right of action.
Consent in employment is weak, so a biometric clock offered without a genuine alternative rests on an unstable basis.
Data protection regulators have repeatedly found biometric attendance systems disproportionate where a badge or code would serve, and that is the test: is there a less intrusive method that achieves the purpose.
Where it is used at all, provide a real alternative that carries no penalty, store templates rather than images, and define deletion on departure.
The honest recommendation: for attendance, the purpose is almost always served by something less intrusive, and the badge-sharing problem is better addressed by supervision than by biometrics.
Location
A mobile clock-in that checks the person is at the site is proportionate for site-based work and is narrow: a check at the moment of clocking, not continuous tracking.
Continuous location during the shift is a different thing and needs its own justification, which for most roles does not exist.
Say which you are doing, in the notice, and configure it so the answer is true.
Design details that matter
Record to the minute, do not round at capture.
Record breaks rather than deducting them.
Make it easy to record work before or after the shift, which is where the wage claims come from.
Log every edit with who, when and why.
Show the worker their own record, which is part of the standard where the recording duty applies.
Have a documented fallback for when the terminal fails, or the fallback will be a manager's memory.
What to measure
Proportion of shifts with a complete record: start, end and breaks.
Edits per period, and who makes them. A pattern of manager edits reducing hours is the finding.
Missed clock-outs, which indicate a usability problem.
Time between door event and clock-in, where both exist, which tells you what the systems disagree about.
What the record actually means
Precision about the event, because in a dispute the difference decides it.
A terminal records that a credential was presented.
An app records that a device reported at a time.
A door reader records an access event, which is not the start of work.
Write down what your system records and what you are treating it as.
Where a gap exists — door to desk — decide whose time it is and say so, rather than leaving it to be litigated later.
The fallback when it fails
Terminals break, phones lose signal, and the fallback becomes the record.
Document it before it is needed: who records, on what, and how it enters the system.
Log it as a fallback entry rather than as a normal one, so the audit trail is honest.
Reconcile fallback entries afterwards with the person concerned.
Watch the rate. Frequent fallback use means a usability or reliability problem, not a compliance one.
Without a documented fallback the record becomes a supervisor's memory, which is the weakest possible evidence.
A concrete product reference
When translating this principle into a buying test, see the scheduling example provides a concrete feature and workflow reference. Verify the relevant behaviour in a trial, retain the exported evidence and judge it against the purpose and limits described above.