The Attendance Record That Isn't Theirs

The Attendance Record That Isn’t Theirs

Attendance Was Never a Discipline Problem

Most companies file proxy clock-ins under the wrong heading. Someone punches in for a colleague who is still stuck in traffic, and it gets treated as an honesty issue: a quiet word, a warning letter, a line in the handbook about integrity. Manage the people, the thinking goes, and the problem manages itself.

That framing has never held. Proxy attendance is not a character flaw in a few employees. It is a structural weakness in the record itself. An attendance entry that a second person can create on your behalf is not evidence that you were at work. It is evidence that someone pressed a button. The two are not the same, and the gap between them is where payroll leaks, disputes fester, and legal cases quietly fall apart.

The real question is not how to stop dishonest staff. It is whether the record can prove who was actually there.

The Credential Was Always the Weak Point

For decades, the answer was no, and the reason sat in plain view. A card can be handed over. A PIN can be shared over WhatsApp. A fingerprint template, on cheaper devices, can be enrolled for two people or lifted with effort. Every one of these methods verifies a credential, not a person. The system confirms that a valid token was presented. It has no idea whose hand presented it.

This is why buddy punching survived every generation of hardware. Operators upgraded from paper cards to magnetic stripes to fingerprint readers, and the fraud simply moved with them, because the underlying flaw was never addressed. The record kept confirming the token. It never confirmed the human.

Most Malaysian SMEs still run exactly this way today, on shared cards, PINs, or basic fingerprint units, and they carry the same blind spot they had ten years ago. The technology changed. The question it answers did not.

The Fraud Followed the Workforce to the Phone

Then clocking moved to the smartphone, and something got lost in the celebration. Mobile clocking was sold as the fix for so many things at once, remote teams, multiple branches, staff who never sit at a desk, that the identity question fell off the table entirely.

Consider what a basic mobile clock-in actually verifies. It confirms that a registered phone, at a permitted location, tapped a button at a certain time. GPS answers where. It says nothing about who. A worker can hand a phone to a teammate on the way in. A location can be spoofed. A weak check-in that accepts a stored selfie proves only that a photo exists. The device moved from the wall to the pocket, and the proxy problem moved with it, now harder to see because everyone assumed the app had solved it.

Consider what a basic mobile clock-in actually verifies. It confirms that a registered phone, at a permitted location, tapped a button at a certain time. GPS answers where. It says nothing about who. A worker can hand a phone to a teammate on the way in. A location can be spoofed. A weak check-in that accepts a stored selfie proves only that a photo exists. The device moved from the wall to the pocket, and the proxy problem moved with it, now harder to see because everyone assumed the app had solved it.

This is exactly where identity has to be built into the moment of clocking, not inspected afterwards. On a smartphone, a clock-in should not register until the person is confirmed at the point of the punch. In practice that means TimeTec Attendance can require face authentication on the phone before it captures the entry: the system does not record the clock-in when the button is pressed, it records it when the face is verified. Pair that with a geofence radius and the record finally answers both questions at once, where the clock-in happened and who was holding the device. For staff on site, biometric devices carry the same principle at the door, binding each entry to a person rather than a token.

That is the difference between a timestamp and evidence.

Why a Hollow Record Costs More Than Time

The consequences do not stay in the attendance module. They flow downstream into every calculation that trusts it.

Payroll pays for hours that may never have been worked, and overtime multiplies the error at a premium rate. A supervisor trying to address chronic lateness has no defensible ground to stand on, because the record they would cite can be waved away as unreliable. And when a matter reaches the Industrial Court, the weakness becomes decisive. As the argument in When Your Attendance Record Goes to Court makes clear, the standard shifts from what your system stored to what you can prove, and a record that any colleague could have created does not survive that test. It is not that the data is missing. It is that the data cannot be trusted to belong to the person it names.

An unverifiable record is worse than a gap in the log, because a gap is at least honest about what it does not know. A false entry looks like proof right up until the moment someone challenges it.

Design the Identity In, or Defend It Later

The instinct to solve proxy attendance through policy is understandable, and it is the wrong tool. Policy governs behaviour. It cannot make a shared credential belong to one person. Only the system can do that, and only if identity is verified at the instant the record is created rather than trusted after the fact.

Buddy punching did not disappear when clocking went digital. It changed address. The organizations that still treat it as a discipline matter are managing the symptom while the record quietly stays hollow.

An attendance system should not ask whether the button was pressed. It should ask who pressed it, and refuse to write the record until it knows.