Restrict Clock-In to Wi-Fi
Home > Management Mode > Clock-In Records and Management > Clock-In Point Settings > Select Clock-In Point > Restrict Clock-In to Wi-Fi
In Management Mode, open Clock-In Records and Management from the Home page, then select Clock-In Point Settings to open the settings for a clock-in point.
When Restrict Clock-In to Wi-Fi is enabled, the system compares the Wi-Fi connection information available from the employee's device with the allowed list at clock-in. This feature checks whether the employee is using an approved network condition. It does not calculate a precise physical location or independently prove that the employee is at a particular site.
Results may be affected by the device, operating system, app permissions, wireless access point settings, and network changes. Before enabling the rule for regular use, test it with the devices and network used at the site.
Features
- Network condition check: Determines whether the available Wi-Fi connection information matches the allowed list.
- Supporting record: Adds the Wi-Fi comparison result as supporting attendance data for later review by administrators.
How to Use It
- Connect to the approved Wi-Fi: The employee connects the device to a Wi-Fi network allowed by the organization.
- Clock in: The employee clocks in through the SwipePoint app.
- System comparison: The system compares the Wi-Fi connection information it can obtain. If the information is unavailable or does not match, follow the on-screen instructions.
Benefits
- Adds a clock-in condition: An approved Wi-Fi network can be included in the clock-in rules.
- Reduces extra equipment: Employees can use their existing phones and the organization's network without a separate time clock.
- Supports review: Administrators can review the result together with time, GPS, photo, and other records when investigating an exception.
Important Notes
- This is not a positioning feature: Connecting to an approved Wi-Fi network does not identify a precise location or confirm the identity of the person who clocked in.
- Test before enabling: Device limitations, permission settings, access point replacement, or network reconfiguration may affect the result.
- Privacy and data management: The organization should explain the collection purpose, use, retention period, and authorized access to employees, and manage the data under applicable requirements.
Require a Photo
Home > Management Mode > Clock-In Records and Management > Clock-In Point Settings > Select Clock-In Point > Restrict Clock-In to Wi-Fi > Require a Photo
In Management Mode, open Clock-In Records and Management from the Home page, then select Clock-In Point Settings to open the settings for a clock-in point.
When this option is disabled, employees may choose whether to take and upload a photo at clock-in. When it is enabled, employees must take and upload a photo according to the organization's instructions, such as a photo of an on-site clock or address sign. A photo is supporting material only; it cannot independently prove the photographer's identity, actual location, or capture time.
Before using this feature, the organization creator must subscribe to the Premium Storage plan. Photo clock-in becomes available after cloud storage is enabled.
Require GPS Location for Clock-In
Require GPS Location for Clock-In is disabled by default, so employees may choose whether to submit GPS coordinates when they clock in. When it is enabled, employees must allow the system to attempt to obtain and submit GPS coordinates. The result may still be affected by the device, permissions, signal, and environment.
Important:
- GPS coordinates can be falsified: Requiring GPS coordinates cannot completely prevent location spoofing.
- Coordinates may be missing or inaccurate: Device hardware, permissions, indoor conditions, or signal quality may prevent coordinates from being obtained or uploaded, or may reduce their accuracy.
- Photos are supporting material only: Requiring a photo may reduce uncertainty during review, but a photo does not guarantee that an attendance record is authentic.
Wi-Fi Access Points
This section lists the Wi-Fi access points allowed for clock-in. Select the plus sign (+) to add an access point. If an access point is replaced, reconfigured, or retired, update the allowed list and test again with the devices used at the site.
Restrict IP Addresses
Restrict IP Addresses compares the network IP address used by a clock-in request with the allowed list. It can verify whether the network source matches the rule, but it cannot determine the employee's precise physical location.
Features
- Network source check: Checks whether the network IP address used at clock-in is on the allowed list.
- Rule enforcement: Can serve as an additional clock-in condition for an office or organization network with a stable public egress IP address.
How to Use It
- Confirm the egress IP address: Ask the network administrator to confirm the public egress IP address shown externally by the organization's network and whether it is stable.
- Configure the allowed list: Add the permitted IP address to the clock-in point or employee profile.
- Connect to the organization network: Before clocking in, the employee connects to the specified organization network.
- Clock in: The system compares the network IP address. If it does not match the allowed list, follow the on-screen instructions.
Management
- Flexible configuration: Administrators can maintain the allowed list for a clock-in point or an individual employee.
- Exception review: The IP comparison result can be reviewed with time, Wi-Fi, GPS, photo, and other data, but it must not be treated as proof of location by itself.
Benefits
- Adds a network boundary: Employees can be required to clock in through a specified organization network.
- Works with other conditions: IP rules can be combined with Wi-Fi, GPS, or photo rules to reduce reliance on a single data source.
Important Notes
- An IP address is not a physical location: Multiple devices may share one egress IP address, and an IP address can change because of the internet service provider or network architecture.
- Public and private IP addresses are different: In most cases, configure the public egress IP address shown by the clock-in request, not the private IP address assigned to the device by a router.
- Watch for dynamic or shared addresses: A dynamic IP address, carrier-grade sharing, VPN, proxy, or mobile network can change the comparison result.
- Review the configuration regularly: Confirm the IP address and test clock-in again after changes to network equipment, service provider, or egress architecture.
- Protect configuration data: Limit allowed-list administration to authorized personnel and retain or use related records under the organization's policies.
In most cases, enter the public egress IP address shown externally by the clock-in request. Private addresses assigned by a router, such as 192.168.x.x or 10.x.x.x, are not normally the source address visible to an internet service. If the organization uses a VPN, proxy, or specialized network architecture, ask the network administrator to confirm the correct value for the actual environment.
Frequently Asked Questions
1. What does Wi-Fi-restricted clock-in do?
Answer: It compares the Wi-Fi connection information available at clock-in with the allowed list, making an approved network one of the clock-in conditions. It can reduce the need for extra clock-in equipment, but it does not provide precise positioning or independently prove an employee's identity or location.
2. Can Wi-Fi clock-in determine an employee's exact location?
Answer: No. A Wi-Fi comparison only checks whether the device meets the specified network condition. Signal coverage, network extenders, device limitations, and permission restrictions may all affect the result.
3. How do I configure Wi-Fi clock-in?
Answer: From the Management Mode home page, go to Clock-In Records and Management > Clock-In Point Settings. Select a clock-in point, enable Restrict Clock-In to Wi-Fi, and add the allowed Wi-Fi access points. Test the configuration with a device used at the site.
4. What is the purpose of requiring a photo?
Answer: When enabled, employees must take and upload a photo according to the organization's instructions for supporting review. The organization creator must first subscribe to the Premium Storage plan. A photo cannot independently prove a person's identity, location, or time.
5. Why require GPS coordinates at clock-in?
Answer: Enable this option when GPS coordinates are needed as part of attendance review. Coordinates may still be missing, inaccurate, or falsified, so review them together with other records.
6. What other clock-in methods are available?
Answer: SwipePoint supports conditions involving QR codes, GPS, Wi-Fi, NFC, photos, and IP addresses. Each method has its own appropriate uses and limitations. Administrators should choose based on the work environment and test the configuration first.
7. How do I restrict clock-in by IP address?
Answer: Ask the network administrator to confirm a stable public egress IP address, then add it to the allowed list for the clock-in point or employee. The employee must connect to the corresponding network before clocking in. An IP comparison verifies the network source, not a precise location.
8. What risks should I consider when using these features?
Answer: Wi-Fi, GPS, photo, and IP data may all be affected by devices, permissions, networks, or user actions. The organization should clearly explain the collection purpose and retention method, restrict access, and establish a process for reviewing exceptions.
9. How do I set an allowed IP address in an employee profile?
Answer: Go to Home > Management Mode > Personnel > Personal Information, select the employee, and find Allowed IP Address. Add the allowed public egress IP address. If the field label differs in the current version, follow the label shown in the app.
For more help, contact us.
This manual strives for accuracy and completeness, but we do not assume any liability for errors, omissions, or updates. The content may be modified at any time without prior notice. We are not responsible for any damages arising from the use of this manual or downloading its contents, including but not limited to system failures, data loss, or infringement of rights. Users assume full responsibility and risk.