How to Stop Buddy Punching (Without Surveillance Creep)

If you run an on-site team, you’ve probably suspected it: someone clocks in a friend who’s running late, or punches in from the parking lot, or from home. It’s called buddy punching, and it’s one of the quietest ways payroll money leaks out of a small business. The frustrating part is that most time clocks don’t actually stop it — they just record where it happened, if that.

This is a practical guide to how to stop buddy punching for good, without turning your shop into a surveillance state. We’ll cover what it actually is, why so many time clocks allow it by design, the two real fixes (and which one is the hard control), and how to roll it out so your honest staff don’t feel policed.

What buddy punching actually is

Buddy punching is when one employee clocks in or out on behalf of another who isn’t physically there. The classic versions:

  • A coworker punches in your card or PIN because you’re stuck in traffic.
  • Someone clocks in from home before they’ve left for their shift.
  • A staff member punches a friend out at the end of the day so they can leave early.

None of these require malice. They usually start as a small favor between coworkers. But across a 25-person hourly team, even a few padded minutes per shift add up to real, recurring payroll cost — money you’re paying for time nobody worked. And because it’s woven into ordinary social goodwill, it rarely shows up in an obvious way. It just quietly inflates your labor cost.

Why most time clocks let it happen

Here’s the uncomfortable truth: most time-clock tools weren’t built to prevent buddy punching. They were built to track attendance, and prevention is bolted on later — usually as GPS.

The common approaches and their limits:

  • A shared PIN or code. Anyone who knows it can punch for anyone. This is the easiest method to abuse.
  • A login on a personal phone. If the punch happens on a personal device, the device can be anywhere. There’s nothing tying it to the workplace.
  • GPS geofencing. This is what most small-business time clocks lean on. The app checks the phone’s location against the work site. The problem is two-fold: GPS needs an app on every employee’s phone, and a phone’s location can be spoofed with freely available tools. So GPS tells you where a phone says it is — not where the person actually is.

Among well-known SMB time clocks, most rely on GPS-only location checks rather than a network-based lock. (This is approximate, as of June 2026 — confirm current capabilities — but tools like Deputy, When I Work, Connecteam, Homebase, and Jibble lean on GPS geofencing for location, not an office-network lock.) That makes GPS the de facto standard, and it’s a soft control: a deterrent, not proof of presence.

The two real fixes

There are exactly two location controls worth taking seriously, and it helps to be clear about which is the soft one and which is the hard one.

Fix 1 (soft): GPS geofence

A GPS geofence draws a radius around your work site and checks the punching device against it. It’s genuinely useful — especially for staff who legitimately move between sites — and it raises the effort required to cheat.

But treat it as a deterrent, not proof. GPS can be spoofed from a phone sitting on someone’s couch, and it requires an app and a location permission on every device. It’s a good second layer. It is not the thing that finally closes the door.

Fix 2 (hard): office-IP clock-in lock

The control that actually shuts buddy punching down is locking clock-in to your office network.

Here’s the idea in plain terms. Every internet connection has a public IP address — your office Wi-Fi and wired network share one. An office-IP lock says: this employee can only clock in or out from our network. If the punch comes from anywhere else — home, the parking lot, a coffee shop, a spoofed phone — it’s refused. Not logged. Refused.

That’s the key difference. A phone’s GPS can claim to be at the office. A device genuinely sitting on someone’s home Wi-Fi cannot fake your office’s public IP address. To punch in, you have to actually be on the network — which means actually being in the building.

This is exactly how Punchwell’s office-IP clock-in lock works. It’s our flagship feature, and it’s a hard control: the punch is refused server-side when the device is off your office network, rather than merely noting a location after the fact. You can:

  • Allow exact IPs, whole CIDR blocks (a range like 203.0.113.0/24, so you don’t list every address by hand), or address ranges — IPv4 and IPv6.
  • Set allowlists at three levels that combine (and only ever widen access): company-wide, per office, and per individual employee.
  • Apply it per employee — lock your on-site cashiers to the building while letting genuinely remote staff clock in from anywhere. One setting per person.

Most cheap time clocks simply can’t do a network-level lock at all. Among SaaS tools, Buddy Punch does ship real IP restriction (alongside GPS) and Zoho People offers per-user IP restriction — both fine products — but they’re per-user cloud services that hold your data, and (approximate, as of June 2026; confirm current rates) Buddy Punch runs around $1,520/yr for 25 staff. The closest WordPress competitor, WP ERP, offers an IP whitelist too, but it’s global-only — everyone or no one — with no per-employee or per-office control.

You don’t have to choose just one fix, either. Punchwell pairs the IP lock with an optional GPS geofence, plus a kiosk clock and a mobile/PWA punch screen — so you can be as soft or as strict as your team needs.

How to roll it out fairly (warn first, block later)

The fastest way to make staff resent a new time clock is to flip on a hard block with no warning and watch honest people get locked out on day one. Don’t do that. Here’s a calmer rollout.

1. Tell people first, and say why. Frame it honestly: this protects everyone’s paychecks and keeps the schedule fair, and it replaces a clunky old process. Most staff don’t mind a fair rule that’s applied evenly. They mind being surprised.

2. Start in warn mode. Punchwell’s IP lock has three enforcement modes — block, warn, and flag. Run it in warn mode for a week or two. Punches still go through, but off-network attempts get noted, so you can see what’s actually happening before anything gets refused. (One honest note: warn and flag behave the same way by design — neither blocks the punch; they record it. Block is the mode that actually refuses.)

3. Find the legitimate exceptions. Warn mode usually surfaces real-world edge cases: a manager who opens before the Wi-Fi is up, a remote bookkeeper, someone who works from a second site. Handle these with the per-employee and per-office allowlists rather than disabling the whole control. That’s the point of the layered design — you widen access exactly where it’s warranted, and nowhere else.

4. Switch to block — for the roles that need it. Once the exceptions are mapped, turn on block mode for your on-site staff. Because the lock is per employee, your remote and traveling people are unaffected. You can also have HR get an email whenever an off-site punch is refused, so a blocked attempt is a heads-up, not a silent mystery.

5. Keep it light where you can. Optional add-ons like a clock-in time window (only accept punches around shift start) and a kiosk or mobile punch screen let you tighten things without micromanaging. Clock-out, notably, isn’t blocked by location or a time window — nobody gets trapped on the clock because they walked to their car.

This is the difference between attendance integrity and surveillance creep. You’re not tracking where people are; you’re confirming that a punch came from the workplace. That’s a narrower, fairer question — and it’s the one that actually stops buddy punching.

A quick word on ownership

One more thing worth saying, because it matters for a control this sensitive: with Punchwell, your attendance data stays in your own WordPress database. It’s self-hosted, GPL, with no cloud holding your timesheets and no data call-home — we removed and verified all of the original’s outbound network code, and the only outbound call Pro makes is license validation, never your data (see our security page). Pricing is flat — per site, not per seat — $99/yr per site, with unlimited employees on every tier. You can read more on the pricing page.

The bottom line

Buddy punching persists because most time clocks only watch; they don’t refuse. GPS is a useful deterrent, but it’s spoofable and needs an app. The hard fix is an office-IP clock-in lock that refuses an off-site punch server-side — applied per employee, rolled out warn-first, with honest exceptions handled cleanly.

Do that, and the favor-swapping quietly stops, because there’s nothing left to swap. If you’re on WordPress and want to see how the lock works, start with the IP clock-in lock feature page.


Punchwell is an independent, third-party maintained fork of the GPL-licensed “WP Human Resource Management” plugin. Sturdyhaus is not affiliated with, endorsed by, or sponsored by wpspear, weDevs, the original author, or any other prior maintainer. Competitor names (Buddy Punch, Deputy, When I Work, Connecteam, Homebase, Jibble, Zoho People, WP ERP) are referenced descriptively only; all trademarks belong to their respective owners. Competitor pricing and capabilities are approximate, as of June 2026 — confirm current rates and features before relying on them.


Punchwell is an independently maintained GPL fork. Not affiliated with the original “WP Human Resource Management” plugin or its authors. Competitor names and figures are nominative and approximate (as of the date noted) — confirm current rates.