Check-in that captures no location

Self-serve check-in in PeopleMuster captures no location at all. No coordinates, no map, no address check. A browser card on the dashboard, a window around the shift a person was assigned, and a record. Nothing else was collected, and that was a decision rather than an omission.

The alternative to location is a narrow window and a reviewable exception.

What location capture is meant to solve

The stated reason is verification. Recording where a punch happened is supposed to prove the person was where they should be.

The verification is weaker than it looks. A coordinate proves where a device reported being, which is a different statement, and the gap between the two is well known to anyone who wants to exploit it.

Meanwhile the cost is certain. A continuous record of where your employees are is sensitive data you now hold, explain, secure and eventually delete.

What we do instead

A shift gives every check-in a natural boundary, and four configurable edges turn it into a window.

Check-in opens a set number of minutes before the shift starts. Sixty by default. And closes a set number after it starts, two hours by default. Check-out opens half an hour before the shift ends and closes four hours after. An administrator can change all four.

Outside the window, the card does not silently record anything. The person is routed to a manual punch request, which a human reviews against what actually happened.

  • Needs an assigned shift. No shift, no self-serve punch.
  • Four window edges, all set per tenant.
  • A missed window becomes a reviewable request, not a gap.
  • Checked out is terminal for the day; returning needs a request.
  • Off by default. An administrator switches it on.

Why a window beats a coordinate

Most attendance disputes are not fraud. They are a dead terminal, a forgotten punch, a person who started early for a deployment.

A window makes those exceptions visible and cheap to handle. Anything outside it becomes a request with a reason, a reviewer and a date, instead of a silent record nobody questions.

And it does that with far less sensitive data. A shift time is something the company already holds. A location history is something it would have to start holding.

What you avoid, and what you get back

Data you never collect is data you never have to protect, explain, or delete on request. That is the plainest benefit and it is easy to undervalue until somebody asks for it.

It also shortens the conversation with the team. Nobody has to be reassured about what happens to a location history, because there is not one.

What you get back is a cleaner record. Every correction is a reviewed request, and the activity log keeps the before and after values of anything an administrator changes.

That is the evidence most disputes actually need: what the record said, what it says now, and who changed it.

Setting the four edges sensibly

Defaults are a starting point, not an answer. A few things to weigh before changing them.

A wide opening before the shift suits people who arrive early and start working. A narrow one keeps the record closer to the shift, at the cost of more correction requests.

The closing edge after the start is the one that matters most. Too tight and a delayed commute becomes paperwork. Too loose and checking in at lunchtime records a normal morning.

Check-out has the opposite risk. A long window after the shift end is forgiving, and it also lets somebody check out at midnight for a day that ended at six.

Set them, watch the correction queue for a month, and adjust once. A queue that never empties usually means an edge is wrong, not that people are careless.

Two paths, and when each one earns its place

Having both a terminal and a browser card is not indecision. They answer different situations, and most companies need only one.

A terminal suits a single site where nearly everyone is on shift and present. It removes the honesty question entirely, and it needs hardware, a network and an enrolment process. Fingerprints stay on the terminal: PeopleMuster receives only who punched and when.

The browser card suits everything the terminal cannot reach. No hardware, no enrolment, and a window instead of a scan.

Running both means reconciling two sources, which is real work. Worth doing where some of the team is on site and some is not. Not worth doing for the sake of coverage.

Pick the one that matches how your team actually arrives, and switch the other off rather than leaving it available.

Questions people ask

Does self-serve check-in record where someone is?

No. No GPS, no geolocation, no coordinates and no address check anywhere in that path. The product captures none of it.

Is self-serve check-in on by default?

No. The tenant setting defaults to off, and an administrator switches it on. There is also an optional expiry timestamp that disables it again automatically.

What if someone misses the check-in window?

The card routes them to a manual punch request. An administrator reviews it. The day is not silently left blank.