When you run more than one location — a few shops, a small franchise, clinics across town, branches in different cities — attendance gets a new failure mode. It’s not just “did this person clock in?” It’s “did they clock in at the site they’re actually scheduled to work?” A staffer covering the east-side store shouldn’t be able to punch in from the west-side one, or from home, and a district manager who legitimately hops between all of them shouldn’t be locked out of any.
A good multi-location time clock solves this by giving each site its own network fingerprint and letting a punch only count when it comes from the right place. The cleanest way to do that is one office-IP allowlist per location — the core of Punchwell’s office-IP clock-in lock.
The multi-site attendance problem
With a single location, “lock clock-in to the office network” is one allowlist and you’re done. With several, three things get harder:
- Each site has its own network. Every location connects out through its own public IP address, so there’s no single “the office” to lock to.
- Staff should be pinned to their site. You want an employee clocking in only from the building they’re rostered at — not another branch, not their couch.
- Some people legitimately roam. Owners, area managers, and relief staff move between locations and need to punch at any of them.
Global, all-or-nothing controls fall apart here. The closest WordPress competitor, WP ERP, offers an IP whitelist, but it’s global-only — one list for the whole company, everyone or no one (approximate, as of June 2026 — confirm current capabilities). That can’t express “the east store’s network for east-store staff, the west store’s network for west-store staff, and every network for the two area managers.” Per-site and per-person control is exactly what a multi-location business needs.
One allowlist per location, unioned together
Punchwell models this directly. Each location you set up (under Structure → Locations) can carry its own allowed IPs — single addresses, ranges, or CIDR blocks. So the east store’s network is on the east store’s location, the west store’s on the west store’s, and so on.
Then three levels combine, and the rule is widen-only: the final allowlist for any employee is the union of the company-wide list, their office’s list, and their own per-person list. Adding an address anywhere only ever widens who can punch — it never accidentally narrows someone else. In practice that gives you:
- Site-pinned staff. A cashier assigned to the east store, with no personal exceptions, can only clock in from the east store’s network. Show up at the west store or at home and the punch is refused server-side — not merely logged.
- Roaming managers, cleanly. Give a district manager a per-employee entry (or use lock-by-role) so they can clock in at any location, without loosening the rule for everyone else. One setting per person.
- New sites without drama. Adding location number six is just another location with its own allowlist. The existing five are untouched.
And because managers usually only care about their own site, the manager approvals inbox is office-scoped — a location’s manager sees their own team’s requests and who’s in today, not the whole company’s. Multi-location structure carries through the day-to-day, not just the punch.
Sites without a fixed IP: geofence and kiosk
Not every location has a static public IP — a small branch on a consumer internet plan might see its address change. For those, you’re not stuck. Punchwell pairs the IP lock with a GPS geofence, kiosk, and mobile punch layer:
- Per-office GPS geofence. Each location can have its own fence — latitude, longitude, and radius (in metres or feet) — so a site without a reliable IP can be pinned by location instead. (Honest framing: GPS is a deterrent, not proof — it’s spoofable — so use the IP lock as the hard control where you have a static address, and the geofence where you don’t.)
- A kiosk per site. Mount a wall tablet at each location; staff clock in with a short code and 6-digit PIN, and the device is tied to that venue’s network. It’s a clean shared clock point for a branch full of on-site staff.
Mix and match by site: hard IP lock where there’s a static address, geofence where there isn’t, a kiosk wherever a shared terminal makes sense.
What “per site” means for pricing
This is worth being precise about, because “location” and “site” aren’t the same word here.
If all your locations run on one WordPress website — which is the usual setup for a single business with several branches — you manage them all as Locations inside that one install. That’s unlimited locations and unlimited employees on a single license: free on WordPress.org, or Pro at $99/year for the one site.
If instead each location (or each franchisee) runs its own separate WordPress site, pricing is per WordPress install — one $99/year Pro license per site. Either way it’s per site, never per seat: headcount is unlimited on every tier, so a location with 8 staff and one with 40 cost the same.
Compare that to per-head SaaS clocks, where every employee at every location is another monthly charge — roughly $1,520–2,100/year for just 25 staff on Buddy Punch, Deputy, or When I Work (approximate, as of June 2026 — confirm current rates), and most of those do GPS-only checks with no true per-site network lock. And because Punchwell is self-hosted, all your locations’ attendance data stays in your own WordPress database rather than a vendor’s cloud.
The bottom line for multi-location teams
Running several sites turns attendance into a per-location question, and the answer is per-location control: one office-IP allowlist per site, unioned with a per-employee layer so roaming managers work and everyone else stays pinned to their building — with a GPS geofence or kiosk for locations that need a softer anchor. All of it at one flat price, however many people you hire across however many sites.
To see how the allowlist levels and per-office setup work in detail, start with the office-IP clock-in lock; for the sites that need a geofence or kiosk instead, see the GPS geofence and kiosk overview.
Punchwell is an independent, third-party maintained fork of the GPL-licensed “WP Human Resource Management” plugin. Sturdyhaus is not affiliated with, endorsed by, or sponsored by wpspear, weDevs, or the original author. Competitor names (WP ERP, Buddy Punch, Deputy, When I Work) are referenced descriptively only; all trademarks belong to their respective owners. Competitor pricing and capabilities are approximate, as of June 2026 — confirm current rates before relying on them.