Time clock security
with every action on record.
CKZ Time Clock locks down who can punch in, where they can punch in from, and who can touch the records afterward. Every manual edit, schedule change, leave approval, and payroll action is written to an immutable audit log β timestamped, attributed, and searchable.
No credit card Β· Cancel anytime Β· Free forever for small teams
Punches only from
approved locations.
Whitelist the IP addresses your employees should be punching from β your office, your job site, your store β and block everything else. When IP restrictions are enabled, clock-in attempts from any unlisted address are rejected before they reach the timecard.
- Add any number of approved IP addresses per company
- Block punches attempted from home networks, coffee shops, or unknown locations
- Combine with GPS geofencing for layered location enforcement
- Kiosk punches at a shared terminal are exempt β IP rules apply to personal logins
- Changes to the approved IP list are recorded in the audit log
- Works transparently β employees on approved networks see no difference
Sarah M. from 72.44.50.12 (not on approved list)
On-site punches only.
Verified by GPS.
Define job sites by GPS coordinates and radius. When an employee tries to clock in, their location is checked against every approved zone. If they're not on site β the punch is blocked or flagged, depending on how you've configured enforcement.
- Create unlimited geofence zones per company β each with its own center point and radius
- Use "π Use My Location" in settings to drop a pin at your current position
- Choose between warn (flag the punch but allow it) or require (block until inside a zone)
- Works on web app, iOS, and Android β the browser or phone provides the coordinates
- Kiosk punches are exempt β the kiosk is already on-site by definition
- Out-of-zone attempts are recorded in the audit log regardless of enforcement mode
Out-of-zone attempts are blocked and logged
Everyone sees exactly
what they should.
Three distinct access levels β employee, supervisor, and admin β control who can view records, who can edit them, and who can manage company settings. Supervisors only see the employees in their own department or location. Admins control everything.
- Employees β clock in/out, view their own timecard, submit workflow requests
- Supervisors β approve requests, edit punches, run reports, manage schedules β scoped to their assigned employees only
- Admins β full access to all employees, all records, company settings, billing, and the audit log
- Supervisors cannot view or edit employees outside their scope β even if they know the route
- Supervisors can never approve their own punches β even with full edit permissions, self-approval is blocked at the system level
- API access enforces the same scoping rules β no elevation via direct calls
- Role changes are recorded in the audit log with the admin who made the change
| Action | Emp | Sup | Admin |
|---|---|---|---|
| Clock in / out | β | β | β |
| View own timecard | β | β | β |
| Edit punches | β | β (scoped) | β |
| Run payroll reports | β | β (scoped) | β |
| Company settings | β | β | β |
| Audit log | β | β | β |
Decide what employees
can do at the clock.
Role-based permissions control who can see and edit records. Punch permissions control something narrower and just as important: what an employee can do to their own punch, in the moment, without a supervisor's sign-off.
- Allow or block employees from editing their own clock-in/out time after the fact
- Require a supervisor's approval before a self-requested time correction takes effect
- Control whether employees can add a missed punch themselves or must always request one
- Settings apply company-wide, so every employee is held to the same standard
- Combine with the audit log β any punch permission change is recorded with who made it and when
Coverage without
handing over the keys.
When a supervisor is out, they can delegate their approval authority to another supervisor β without granting them admin access or expanding their permanent permissions. Delegates can approve requests and manage the delegating supervisor's team for the duration of the delegation.
- Supervisors assign a delegate from their settings page
- Delegate receives supervisor-level access scoped to the original supervisor's team
- Delegation can be revoked at any time
- All actions taken by a delegate are recorded in the audit log under the delegate's name
- No need to change passwords, share logins, or grant permanent admin access
are logged separately from her own team activity
Who changed what.
Down to the minute.
Every action that modifies employee records is written to the audit log β immutably, with a timestamp and the user who performed it. When an employee disputes a punch or a payroll discrepancy surfaces, the audit log tells you exactly what happened and who did it.
- Punch edits β who changed the time, what it was before, what it became
- Manual punch additions β who added a punch and the reason provided
- Punch deletions β recorded even when the punch no longer appears on the timecard
- Schedule changes β shift adds, edits, and removals all attributed to the supervisor who made them
- Leave approvals and denials β which supervisor acted on each request
- Payroll period locks β who locked the period and when
- Workflow request outcomes β approvals, denials, and who handled each one
- Settings changes β IP restriction updates, geofence changes, role changes
4:30 PM β 5:15 PM Β· Reason: "Forgot to clock out at shift end"
Jul 14β16 Β· 3 days Β· 24.0 hrs deducted
Mon Jun 16 Β· 8:00 AM β 4:00 PM Β· "Employee was on site, app issue"
22 employees Β· exported to ADP WorkforceNow
Explore more features
Lock down your timecards. Know exactly what happened.
Free forever for small teams. All features unlocked for 30 days. No credit card required.
Get Started Free