A time clock that accepts every punch is really a suggestion box. The 7:41 clock-in for an 8:00 shift, the punch from a phone at home, the clock-in from a coffee shop wifi: each one is a few minutes of paid time the schedule never asked for. ClockOut’s punch controls close those gaps where they happen, at clock-in, with a plain message telling the employee exactly why the punch did not count and what to do instead. Every rule is optional and off until you turn it on.
The problem: the punch that technically counts
Most time theft is not dramatic. It is a clock-in 19 minutes before the shift, every day, from someone who then sits in the break room. Or a punch from a personal phone that never entered the building. Multiply a few padded minutes by a team and a year and it is real money, and it is miserable to police by hand because every individual punch looks defensible.
Punch controls make the policy self-enforcing. Instead of a manager auditing timesheets after payroll, the clock-in itself is refused, politely and immediately, when it is outside the rules you set. The employee sees exactly when clock-in opens or which device to use, so there is no ambiguity and no argument.
Punch limiting: stop early clock-ins
Punch limiting ties clock-in to the schedule. Two rules, each optional:
- Early-punch window. Clock-in opens a set number of minutes before the scheduled shift starts, 15 minutes by default, and you can change the number. Someone who taps clock in at 7:30 for an 8:00 shift is told their shift starts at 8:00 and clock-in opens 15 minutes before.
- Require a scheduled shift. Optionally, an employee with no shift on the schedule that day cannot clock in at all. They see a message saying they have no scheduled shift and to ask a manager if that is wrong. Leave this off and employees without a shift can still punch normally.
The deliberate limits, stated plainly:
- Late clock-ins are never blocked. Punch limiting has no upper bound. Someone running late can always clock in; blocking them would just turn a late arrival into missing hours.
- Clock-outs are never blocked, by any rule. Every punch control on this page applies to clock-in only.
- Admins, owners, and managers are exempt. They set the schedules, so a schedule cannot be a precondition for their own punch. This matches how geofencing treats them.
- Overnight shifts work. A 10 PM to 6 AM shift dated yesterday still accepts punches after midnight, so a worker clocking back in from a 12:30 AM break is not refused.
Device locks: only punch from approved devices
With device locks on, a punch only counts when it comes from a device an admin has approved. Here is the whole lifecycle:
- 01
An unknown device punches for the first time
The clock-in is refused, the device registers itself as pending, and admins get a notification that a new device is waiting for approval, with the employee’s name and the device description.
- 02
An admin approves or blocks it in Settings
The pending device appears in Settings with who first punched from it. Approve it and punches go through from then on. Block it and every future punch from that device is refused with a message saying an admin blocked it.
- 03
Approved devices just work, for everyone
Approval is per device within your company, not per person. Approve the shared front-desk tablet once and the whole team can punch from it. There is nothing for employees to configure.
Device locks fail closed: a punch that arrives without a device identity, for example from an app version that predates the feature, is treated like an unknown device and held for approval rather than waved through. If your team punches from the mobile app, roll out the current app update before turning device locks on, so their phones can identify themselves.
IP address locks: only punch from your network
IP locks restrict web and kiosk punches to network ranges you approve, entered as CIDR ranges (a plain IP address works too and means just that address). Add the workplace wifi’s range and a clock-in from the browser at home, or from a phone hotspot in the parking lot, is refused with a message that punches must come from an approved workplace network.
- Web and kiosk punches only, on purpose. A phone on cell data gets an IP address that says nothing about where the phone is, so phone punches are governed by GPS geofencing instead. The two rules cover the two cases: IP for fixed networks, GPS for phones in the field.
- Multiple ranges. Approve several ranges, for example the office network and each site’s wifi, and a punch is accepted from any of them.
- Fail closed. A punch whose network address cannot be verified is refused rather than allowed through.
Layer the rules to match your workplace
Each rule has its own toggle, so you combine only what fits:
| Plan | Applies to | |
|---|---|---|
| Punch limiting (schedule windows) | Starter and Pro | All clock-ins |
| Device locks (approved devices) | Pro | All clock-ins |
| IP address locks (approved networks) | Pro | Web and kiosk clock-ins |
| GPS geofencing (approved work areas) | Starter and Pro | Phone clock-ins with location |
A restaurant might use punch limiting plus a QR badge kiosk on an approved tablet. An office might lock web punches to the building wifi. A field crew leans on geofencing and punch limiting, with devices locked to the crew’s phones. All of it is enforced by the same checks whether the punch comes from the web app or the kiosk, so a rule can never behave differently on the wall tablet than in a browser.
Which plan includes punch controls
Punch limiting is on Starter ($19 a month for up to 5 people, then $3 per extra person) and Pro. Device locks and IP address locks are Pro features ($39 a month for up to 5 people, then $6 each). Paid plans include a 14-day free trial. Full details on pricing, and every behavior on this page is restated with its numbers on product facts.
Punch controls FAQ
How do I stop employees from clocking in early?
Turn on punch limiting. Clock-in then opens a set number of minutes before each scheduled shift, 15 by default, and an earlier attempt is refused with a message showing the shift start time and when clock-in opens. It works from $19 a month on the Starter plan.
Can employees still clock out if a rule would block them?
Yes, always. Every punch control applies to clock-in only. Clock-out is never blocked by punch limiting, device locks, or IP locks, so nobody stays on the clock because of a rule.
What happens when someone punches from a new device?
With device locks on, the punch is refused, the device registers itself as pending, and admins are notified. An admin then approves or blocks the device from Settings. Once approved, the device works for every employee, which is what a shared kiosk tablet needs.
Do IP address locks apply to phones?
No, by design. IP locks cover web and kiosk punches, where the network says something about where the punch happened. A phone on cell data has an IP that reveals nothing about location, so phone punches are governed by GPS geofencing instead.
Can I require a scheduled shift to clock in?
Yes, as an optional rule inside punch limiting. When it is on, an employee with no shift on the schedule that day cannot clock in and is told to ask a manager if that is wrong. Leave it off and unscheduled employees punch normally. Admins, owners, and managers are always exempt.
Which plans include punch controls?
Punch limiting is on Starter ($19 a month for up to 5 people, then $3 per extra person) and Pro. Device locks and IP address locks require Pro ($39 a month for up to 5, then $6 each). Both paid plans have a 14-day free trial. See pricing.
Related pages
- GPS time clock: geofencing, the location-based punch control for phones in the field.
- QR badge kiosk: instant badge-scan clock-in on a shared tablet, a natural pair with device locks.
- Photo proof: photo evidence of the work itself.
- Product facts: every rule on this page, restated as checkable facts.
- Pricing: current plans and checkout.