How it works
- HR opens Capture controls under Policies in Settings. The card states plainly that with nothing set, people can punch from anywhere.
- For web punches, HR adds the office network addresses or ranges. The card shows HR's own current address, whether it is in the list, and a button to add it.
- HR decides whether a web punch also needs the browser location inside a check-in spot. The browser asks for the location when the person punches.
- For app punches, HR turns on the location rule, so the phone must be inside a check-in spot for the person's branch or a spot that covers every branch.
- A refused punch explains itself: a web punch from another network names the network it came from, and an app punch outside the spot gives the distance to the nearest spot.
- Punches that HR records and punches from biometric machines are never checked, so HR can still mark someone whose phone or network fails.
What you can set
- Allowed networks for web punch: IPv4 or IPv6 addresses or ranges such as 203.0.113.0/24, up to 100 entries. An empty list allows any network.
- Web punch needs the browser location inside a check-in spot: yes or no.
- App punch needs the location inside a check-in spot: yes or no.
- Check-in spots tied to a branch cover that branch's staff; a spot without a branch covers everyone.
- Each person can punch only from approved phones: yes or no. The first phone after switching on is approved automatically.
- Kiosk punching on or off, and whether kiosk punches need the phone inside the spot.
What location checks do, and what they do not do
A check-in spot is a place with a radius, such as a branch, a plant gate or a warehouse. When a location rule is on, a punch is accepted only if the phone or browser reports a position inside one of the person's spots. That is the whole check. ZeniaHR reads the location once, when the person punches, and stores it with the punch. It does not track anyone during the day, draw a route or show where staff are now. Tell your staff this plainly when you switch the rule on.
Worked example: a Jaipur branch and its sales team
A distribution company's Jaipur branch has 22 office staff and 9 sales officers. HR adds the branch network range 203.0.113.0/24 to the allowed list, so office staff can punch on the web only from the branch. HR also creates a check-in spot for the branch and turns on the app location rule and phone binding. On Monday, accountant Neha Sharma tries a web punch from home and is told that web punching is allowed only from the office network, with her home network's address in the message.
The sales officers punch in on the app at the branch before going out. When Imran Khan spends Thursday at a dealer in Ajmer, he cannot punch there, because Ajmer is outside the Jaipur spot, so he raises an on duty request for Thursday, which his manager approves and the day counts as present. When the branch's broadband provider changes its network address, the first refused web punch shows the new address, and HR adds it to the list the same morning.
Switching capture controls on without locking people out
Capture controls fail in the employee's favour when something is not set up: if no check-in spot covers a person's branch, a location rule has nothing to check for that person. Plan the rollout so the rules bite where you mean them to.
- Add check-in spots for every branch before you rely on a location rule.
- Start with one branch, watch the refused punches for a week, then extend to the rest.
- Check the phones waiting for HR approval every morning while phone binding is new.
- Give field staff a clear route for days away from the office, such as on duty requests.
- Keep HR's option to record a punch for network or phone failures, and review how often it is used.
See geo-fenced and network-restricted punching in a demo
We show it on a video call with your own shifts, leave types and rules. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What is geo-fenced attendance?
Geo-fenced attendance accepts a punch only when the phone or browser is inside a set area, called a check-in spot, such as an office or a factory gate. In ZeniaHR the location is checked once, at the moment of the punch, and saved with it. A punch from outside the spot is refused with the distance to the nearest spot.
Does ZeniaHR track employees' location during the day?
No. ZeniaHR reads the location only when a person punches, and only when your capture controls ask for it. There is no live location, no route history and no tracking between punches. The stored location belongs to the punch, much like a biometric machine records which gate was used.
Can web punching be allowed only from the office?
Yes. Add your office network addresses or ranges to the allowed list in Capture controls, up to 100 entries. A web punch from any other network is refused with a message that names the network it came from. Leave the list empty if you want to allow web punches from anywhere.
What if an employee's phone gives no location?
If a location rule applies and the phone sends no location, the punch is refused with a message asking the person to turn on location for the app. If the problem continues, HR can record the punch for them on the Attendance Punches page, because punches that HR records are never checked.