Understanding Webpunch settings: A guide to secure and efficient configuration
Webpunch is a versatile tool that enables organizations to manage employee punches, shifts, absences, and other time-tracking data. However, proper configuration of its settings is essential to maintain data privacy and ensure smooth functionality. Key settings like "Punch overview" and "Self-Service" offer powerful features but can expose sensitive information if not managed carefully. Options such as "Allow Camera in Webpunch," "Comment Box," and "Overtime Type Selection" enhance usability, while permissions and audit logs provide layers of control and traceability. This article explores the critical Webpunch settings and offers actionable insights for secure, efficient configuration aligned with organizational needs.
Account manager role
Any user with write access to account settings in their role will have access to Webpunch configurations. Access is not limited to the Account manager role—any role with permission to modify account settings can manage Webpunch and other account configurations.
.png?sv=2026-02-06&spr=https&st=2026-10-11T16%3A44%3A22Z&se=2026-10-11T16%3A59%3A22Z&sr=c&sp=r&sig=3ZE4bTUDvGWda%2FaTeukUnLvqDoycMJeHWG%2BZAumOTOI%3D)
The most secure approach to configuring Webpunch is to limit System Admin or Super User access to a small group of trained users who fully understand the configuration process.
Punch overview
Definition: A setting that allows employees to view punch, shift, and absence data of other employees.
Implications: May expose sensitive personal information if enabled.
Recommendation: Enable only after consulting with the Quinyx team and ensuring it aligns with privacy policies.
Warning! Enables an employee's punch, shift, and absence data to be viewed by other employees and may expose personal information. Please discuss with the Quinyx team before enabling
Absence pop-up
Definition: A feature that prompts users to define the absence type when punching in late.
Use case: Improves tracking and categorization of employee absences.
Why it’s useful:
Helps track and categorize employee absences more accurately.
Enables employees to self-report their absence reasons, reducing administrative follow-ups.
Improves reporting and Compliance by ensuring absence types are correctly recorded.
Allow camera in Webpunch
Definition: Enables the use of a device camera to take photos during punch-in/out events.
Use case: Enhances verification and security.
Note that this feature is only available if your organization has enabled the Webpunch feature for taking pictures on punch in and punch out. If your organization is not using this feature, you will not be affected by this. For more information about the Webpunch feature for taking pictures please contact our Support team.
To comply with GDPR regulations, any picture taken with the image capture functionality in Webpunch3 is stored for 65 days before it gets automatically deleted.
Read more about using pictures in Webpunch here.
Punch manually
The Punch manually feature allows employees to manually enter or adjust their punch/work time, rather than using the automatic timestamp recorded by Webpunch when the action is taken.
Definition: Allows users to manually add or edit details related to their punches, such as shift, comments, or project details.
Important note: Disabling this setting will reset any sub-configurations to default.
Good to know:
The settings below (absence type, comment, cost center, project, and shift) are connected with the “Punch manually setting” - This sub-menu/configuration only pops up if you enable the “Punch manually” function.
Both “Punch manually” and “Overtime” settings can impact the salary outcome based on worked time, so they require careful attention.
Absence type
Definition: A setting that lets users specify the reason for absence when punching in or out.
Comment
Definition: Allows editing of comments associated with punches.
Use case: Useful for providing additional context for punches.
Cost center
Definition: Enables editing of the cost center linked to a punch.
Use case: Ensures punches are accurately attributed to specific cost centers for financial tracking.
Project
Definition: A setting that enables the user to edit the project associated with a specific punch.
Use case: Useful for accurately attributing work hours or tasks to the correct project, ensuring proper reporting and billing.
Shift
Definition: A setting that allows the user to modify the shift details linked to a punch.
Use case: Ensures that punches are assigned to the correct shift, which is critical for accurate time tracking, payroll processing, and compliance with scheduling policies.
Overtime
Definition: Allows users to edit and manage their overtime records.
Overtime type selection: A sub-setting enabling users to decide how to handle overtime (e.g., payout or addition to time balance).
Both Overtime” settings and “Punch manually” can impact the salary outcome based on worked time, so they require careful attention.
No shift pop-up
Definition: Provides a secondary confirmation for punches made without a scheduled shift.
Use case: Reduces accidental punches without a schedule.
Show card number
Definition: Displays the card number associated with a punch during punch-in/out events. It’s the number on the RFID card/badge/fob. So if “Show card number” is set to true/view you will see the number from the card used in the input field in Webpunch.
Implications: Useful for verification but may expose sensitive details if misused.
Comment box
Definition: Enables employees to add comments when punching in or out.
Use case: Facilitates additional context for deviations or exceptions.
Numpad
Definition: Activates a numerical keypad for easier login in the Webpunch interface.
Qmail
Definition: Provides access to Qmail messaging within the Webpunch system.
Use case: Centralizes communication for employees.
Self-service
Definition: Grants users an overview of other employees' time trackers and advanced details.
Implications: Risky if misused; restrict access to reduce data exposure.
Notes for implementation
Ensure proper documentation and training for super users to avoid unintended setting changes.
Regularly review Webpunch settings and audit logs to prevent issues like data exposure.
Use additional safeguards, such as restricted access and clear internal policies, to align Webpunch functionality with privacy and organizational needs.
Additional Webpunch resources
For additional information about Webpunch see:
FAQ
What is Webpunch?
Webpunch is a tool that helps organizations manage employee punches, shifts, absences, and time-tracking data.
Who can configure Webpunch settings?
Any user with write access to account settings can manage Webpunch configurations, not just the Account manager role.
What is the 'Punch overview' setting?
The 'Punch overview' setting allows employees to view the punch, shift, and absence data of other employees, but it may expose sensitive information.
Is it safe to enable the 'Self-Service' feature?
While 'Self-Service' provides an overview of other employees' time trackers, it can be risky if misused, so access should be restricted.
How long are pictures taken with the camera feature stored?
Pictures taken with the camera feature in Webpunch are stored for 65 days before being automatically deleted.
Can employees manually enter their punch times?
Yes, the 'Punch manually' feature allows employees to manually enter or adjust their punch/work time.
What is the purpose of the absence pop-up feature?
The absence pop-up prompts users to define the absence type when punching in late, improving tracking and categorization of absences.
Does enabling the 'Show card number' feature expose sensitive information?
Yes, while it is useful for verification, it may expose sensitive details if misused.
What should organizations do to ensure secure Webpunch configuration?
Organizations should limit access to trained users, regularly review settings and audit logs, and implement clear internal policies.
