Skip to content
Inside the Boundary

All notes  /  Legal

When the System Decides Pay

A clock-in system feeds payroll, which means a technical failure becomes a wage question. The rules that follow from that.

Legal · Analysis

General orientation, not legal or payroll advice.

The moment a punch determines pay, every failure mode in these notes acquires a financial consequence for a person.

What changes

A refused punch is potentially unpaid working time, which in most jurisdictions is unlawful regardless of the cause.

A late punch is not necessarily a late arrival, and treating the two as identical produces deductions that cannot be justified.

A missing punch has to be resolved, and the default answer cannot be zero.

The employer carries the risk of the system failing, not the worker, and this is the principle that most deployments get wrong by omission rather than intent.

The rules that follow

Work performed is paid, whether or not the system recorded it.

A flagged or manually corrected punch is paid on the same cycle, not held pending review.

No deduction without a contractual right, and in many places not even then for a system failure.

Rounding rules apply as they always did, and a geofence does not change the neutrality requirement.

The correction route

Has to exist, be quick, and be usable by the worker.

Not: find a manager, who is busy.

A self-submitted correction, approved afterwards, is the practical answer.

With a deadline and a named approver, so it does not sit until payroll has run.

Measure the time from correction submitted to resolved. It is the worker's experience of the whole system.

Records you will need

The punch time, the site, and whether it was accepted or flagged.

The accuracy figure at the moment of the punch, which is what explains a refusal in a dispute.

Every correction, with who made it and why.

The rules in force at the time, including the radius, because a boundary change alters what was possible.

Without the accuracy figure, a refused punch cannot be explained, and the explanation is what settles the question.

The scenario worth rehearsing

A worker says they arrived at nine, the system shows a punch at nine twenty, and they say the app would not accept it.

Can you tell whether the app was refusing? If the refusals are logged with their accuracy figures, yes. If only successful punches are stored, no — and the dispute becomes one person's word against a system's silence.

Log the failures, not only the successes. Most products do not by default, and asking for it costs nothing at procurement and everything afterwards.

The check to run

Take three flagged punches from last month and reconstruct what happened.

If you cannot, the records are inadequate and you will find that out in a dispute rather than in a quiet hour.

Rehearse the dispute

Ten minutes that reveals whether your records are adequate.

Take a flagged punch from last month.

Reconstruct it: what was attempted, what the system did, what was corrected, what was paid.

If you cannot, the records are inadequate, and you will find that out in a grievance rather than in a quiet hour.

Fix it now, which usually means turning on refusal logging.

Check the difficult case

Use time tracking for accountants to frame one representative test. The useful evidence is the record created when an employee corrects an entry and an administrator exports it.

Independent reference

For an external point of reference, see the UK government portal. Consult the current material directly because technical and legal details can change.