WordPress HR Setup for a Small Business: A Checklist

Setting up HR software for the first time is where a lot of small businesses stall. Not because it’s hard, but because the order isn’t obvious — you add a person, try to clock them in, and it won’t let you, and now you’re annoyed before you’ve even started. The good news: a WordPress HR setup for a small business follows a sensible sequence, and if you do the steps in the right order, your first 25 employees are clocking in cleanly in an afternoon.

This is that sequence, as a checklist. It assumes you’re using Punchwell on a WordPress site you already run, but the shape of it — structure first, people second, rules third — applies to most WordPress HR tools. If you want the wider picture first, the product overview shows how the pieces fit together.

Before you start: one reassuring fact

You’re not building a second system. In Punchwell, employees are just WordPress users, and their profiles, hours, and leave live in your own WordPress database. If you can add a user in WordPress, you can add an employee — there’s no external directory to sync and no separate cloud account to set up. Keep that in mind; it makes the whole thing less daunting.

One more thing that makes setup low-risk: every new setting defaults to a no-op. Installing the plugin changes nothing about how your site behaves until you deliberately turn something on. So you can set up at your own pace without surprising anyone.

Step 1 — Build your structure first

Resist the urge to add people immediately. Set up the containers they’ll go into, on the Structure page:

  • [ ] Organization — your company name and basic details.
  • [ ] Departments — the groups people belong to (e.g. Front of House, Warehouse, Admin). This one matters most, because clocking in depends on it.
  • [ ] Job titles — the roles you’ll assign to people.
  • [ ] Locations — your office(s). Each location can hold its own office IP addresses (and a GPS fence), which you’ll use later to lock clock-in to the building.
  • [ ] Notices — an announcement board, if you want one.

Doing structure first means that when you add employees, there’s already a department to drop them into — which, as you’ll see, is a prerequisite for punching.

Step 2 — Set your company-wide settings

Head to the central Settings hub and set the basics once, so everything downstream is consistent:

  • [ ] Branding — company name, logo, address.
  • [ ] Timezone and date/time format — get this right early; it affects every punch and report.
  • [ ] Fiscal-year start and employee-ID numbering — so new hires auto-number sensibly.
  • [ ] Notification settings — the From-name, Reply-to, and whether HR is CC’d on alerts.

Remember, none of this forces new behavior — it’s just establishing the defaults your team’s records will use.

Step 3 — Add your people

Now the employees. For each person:

  • [ ] Add them as a user with the employee role (hrm_employee), or manager (hrm_manager) for supervisors.
  • [ ] Assign them to a department and a job title.
  • [ ] Fill in the profile as needed — start date, employment type (full-time, part-time, temp, intern, 1099 contractor), and any key dates like probation or contract end.

With 25 people this is quick, and because they’re WordPress users, anyone you’ve already got an account for is halfway there.

Step 4 — Turn on the time clock (in the right order)

Here’s the sequence people trip over. In Punchwell, three things must line up in order before anyone can clock in, by design:

  1. The person has the employee role.
  2. They’re assigned to a department.
  3. That department has a shift policy.

So the missing piece after Steps 1–3 is usually the shift policy. Create one per department that needs it, and set your attendance rules — rounding, grace periods, and auto clock-out — while you’re there. That guardrail (role → department → shift policy) is deliberate: it stops stray, un-assignable punches from mystery accounts landing in your timesheet. Once a department has its policy, its people can punch.

  • [ ] Create a shift policy for each department.
  • [ ] Set rounding (e.g. nearest 15 minutes), a sensible grace period, and auto clock-out with a max-shift cap.
  • [ ] Take one test punch yourself to confirm the whole flow works end to end.

Step 5 — Decide how strict clock-in should be

This is where you address buddy punching, if it’s a concern. You’ve already entered your office IPs on your Locations in Step 1; now decide how to enforce them.

  • [ ] Under Settings → IP & Geofence, confirm your office IP allowlist (single IPs, a whole CIDR range like 203.0.113.0/24, or an address range — IPv4 or IPv6). A “Use this IP” helper fills in your current public address.
  • [ ] Flag the employees who should be office-only, so they can punch only from your network.
  • [ ] Start in warn mode (records off-network punches without blocking), watch for a week, then switch to block for the roles that need it.
  • [ ] Optionally add a GPS geofence, a kiosk for a shared tablet, or the mobile/PWA punch screen — softer or stricter, your call.

Because the lock is per-employee and per-office, you can lock on-site staff to the building while letting genuinely remote people clock in from anywhere. The short version of a fair rollout: tell people first, warn before you block, and handle legitimate exceptions with the allowlists rather than switching the whole thing off.

Step 6 — Set up leave, holidays, and onboarding

With the clock running, round out the HR basics:

  • [ ] Define your leave types and work-week, and set up the approval workflow.
  • [ ] Build your holiday calendar — you can import country presets (US, UK, Canada, Australia and more), upload an iCal file, or paste a list, with a preview before saving.
  • [ ] If you use PTO accrual, configure it per leave type (monthly, per-hour-worked, or an annual grant, with caps and carryover).
  • [ ] Set up onboarding/offboarding checklists so each new hire has a repeatable list to tick through.

Your quick setup checklist

  1. Structure — organization, departments, job titles, locations (with office IPs).
  2. Settings — branding, timezone, numbering, notifications.
  3. People — add employees as users, assign department and job title.
  4. Time clock — shift policy per department, attendance rules, one test punch.
  5. Clock-in strictness — flag office-only staff, warn then block.
  6. Leave & onboarding — leave types, holiday calendar, PTO accrual, checklists.

Do them in that order and the “why won’t it let me clock in?” moment never happens.

The bottom line

A WordPress HR setup for a small business isn’t complicated — it just rewards doing structure before people, and rules before enforcement. Because employees are WordPress users, your data stays on your own server, and because every setting defaults to no-op, you can move at your own pace and turn on strictness only when your team’s ready.

Ready to start? The product overview walks through what’s included, and the features hub drills into each piece as you build out your setup.


Punchwell, by Sturdyhaus — a self-hosted WordPress time clock and HR suite. Your employee data stays in your own WordPress database: no cloud, no data call-home. Holiday preset countries may vary by version — confirm the shipped list in your install.


Punchwell is an independently maintained GPL fork. Not affiliated with the original “WP Human Resource Management” plugin or its authors. Competitor names and figures are nominative and approximate (as of the date noted) — confirm current rates.