A Punch Is Not Proof That the Post Is Occupied
A security client does not pay for a punch in a mobile app. They pay for a post that was occupied by the right person for the contracted hours. When a supervisor marks a guard present at 22:00 and the client later says the booth was empty, the dispute is not about software in the abstract. It is about whether the agency can show identity, location, and duration as three separate facts. A check-in without those layers is only a claim. A live occupancy view without a named person is only a headcount. Payroll and invoicing both fail if those records are treated as the same thing.
Write the verification policy before changing devices. Decide what constitutes a valid on-site event: who must mark, at which post, inside which boundary, within which grace window, and what happens if the mark is late, missing, or from the wrong place. The same rule must apply to the night supervisor, the client report, and the invoice pack. If operations use one definition of present and billing uses another, the empty-post complaint will keep returning even after GPS is switched on.
Example 1: a mall post is scheduled 22:00 to 06:00. The rostered guard checks in at 21:58 from the food court 180 metres away, then leaves. The attendance sheet shows present. The CCTV at 01:10 shows an empty booth. The failure is duration, not identity. Example 2: a relief guard uses the rostered guard's phone at the gate. Location is correct; identity is not. Example 3: a mock-location app places the device inside the fence while the person is at home. Duration looks complete; location is false. Each case needs a different control.
- Treat identity, location, and duration as three proofs, not one punch
- Define present as occupied post, not as a successful check-in
- Align operations, payroll, and client billing on the same definition
- Design for the empty-post complaint before it reaches the invoice
Separate Identity, Location, and Duration
Identity answers who marked attendance. Location answers whether the device was at the assigned post when the mark happened. Duration answers whether coverage continued until the scheduled end or a documented handover. Security guard GPS attendance software that only stores a coordinate at clock-in cannot defend a night shift. Face or another identity check that ignores the site cannot defend a client who paid for a named post. A timesheet that infers eight hours from a roster cannot defend either. You need all three signals in the same audit trail so a later debit note can be answered without reconstructing radio logs.
Policy: require an identity-verified check-in inside the post geo-fence, then a matching check-out or a named handover event. Do not convert a missing check-out into the scheduled end time. Do not convert a check-in at the wrong post into a present mark for the contracted post. If a guard is moved mid-shift, record the new post as a new assignment so the original site does not stay green. The original event should remain visible after any supervisor correction. Publish this as a one-page rule for supervisors so a night manager cannot invent a local shortcut.
Exception: a genuine device, lighting, or basement GPS failure should enter review, not a silent override. The reviewer needs the post, scheduled guard, attempted time, failure reason, and any site evidence such as a gate log or radio check. Approve the smallest correction that restores occupancy proof. A blanket present mark for the whole night recreates the paper register the client already distrusts. If the same post fails verification three nights in a row, treat it as a site or device problem and fix the fence, lighting, or phone before blaming the rostered guard.
- Identity proves who; geo-fence proves where; check-out or handover proves how long
- Never auto-close a night shift from the roster end time
- Record mid-shift post moves as new assignments, not renamed punches
- Route device and GPS failures through named approval, not silent present
Set the Geo-Fence Around the Post, Not the Campus
Security guard geofencing clock-in fails when the boundary is drawn around the whole industrial park, hospital campus, or mall. A fence that large lets a guard mark from a canteen, a neighbouring tower, or another client's booth. A fence that is only the centre point of a building fails at the gate, basement parking, or a steel-framed lobby. Measure the real access area: the booth, the gatehouse, the loading dock, or the floor the contract names. Walk the post with the supervisor once, note where phones actually get a lock, and draw the polygon from that walk rather than from a pin on a map in the office.
Start with a surveyed radius or polygon, then review failed attempts for two weeks before tightening. Example: a 40-metre fence around a basement ATM lobby produces nightly failures because GPS jumps to the street. The operational fix is a slightly larger polygon plus a required identity check, not a campus-wide 500-metre circle. Example: two posts share a compound. If both use the same fence, a guard at Post A can satisfy Post B. Give each post its own assignment and, where posts are close, require the mark to match the scheduled post ID, not only the campus.
Communicate the rule to guards in the language of the post: you must check in at Gate 3, not anywhere on the plot. Show the allowed area in the app. If a legitimate outdoor patrol leaves the booth during the shift, decide whether patrol is part of occupancy or whether a second event is required when they return. Do not pretend a single morning coordinate covers a roaming night duty. Write the patrol exception into the client contract as well, or the facilities manager will treat every outdoor movement as an empty post.
- Draw the fence around the contracted post and access area
- Review false failures by site before widening or tightening
- Do not let one campus fence satisfy two named posts
- Document whether patrol time counts as occupancy or needs a return mark
Treat Mock GPS as a Control Problem, Not a Rumour
Mock location is the most common explanation offered after a client says the post was empty while the sheet says present. It is also over-used as an accusation. The operating response is to detect and flag mock-location or developer-option patterns on supported devices, bind high-risk posts to an enrolled device where contracts allow it, and require identity at the mark so a borrowed phone is harder to use. None of these proves a person never left; they make a remote punch more expensive to fake.
Policy: a flagged mock-location attempt is not automatically payroll absence. It is a high-risk exception. The supervisor compares the flag with the roster, any site visit, radio or panic-button events, and the client's complaint time. If the mark is rejected, keep the original event. If it is accepted because the device was misconfigured, record the configuration fix so the same phone does not generate monthly disputes. Repeat flags on the same device after a fix should escalate to operations, not disappear into another courtesy present mark.
Do not replace this with continuous background tracking as the default. Continuous maps create privacy pushback, battery drain, and a false sense of occupancy if the phone sits in the booth while the person is elsewhere. Use check-in, check-out, optional on-duty snapshots at handover, and live occupancy of who has an open verified shift at that post. Occupancy is a current assignment state, not a breadcrumb trail. Tell guards in writing when location is collected, who can see it, and that tracking is not a substitute for being at the post.
- Flag mock-location attempts; review them as exceptions, not automatic absence
- Bind high-risk posts to enrolled devices where the contract allows it
- Keep identity on the mark so a borrowed phone is harder to use
- Prefer occupancy of an open verified shift over all-day tracking
Night Posts Need Handover Proof, Not a Morning Screenshot
Night is where empty-post complaints concentrate. The outgoing guard's check-out and the incoming guard's check-in should be two events, preferably with a short overlap window defined in the contract. If only one person marks, you cannot tell whether the post was covered across midnight. If both marks happen from the same device two hours apart, identity and device policy should catch it. If the incoming guard is late, the post should show uncovered after grace, not remain green because yesterday's punch still exists.
Example: shift A ends 06:00, shift B starts 06:00, grace is 15 minutes. At 06:18 with no verified check-in for B, the live view must show Post 12 uncovered and name the supervisor who owns relief. That alert is the operational product. A monthly attendance percentage of 98 percent does not help a facilities manager at 06:20. Relief should be recorded as a replacement assignment so payroll and the client report show who actually stood the post. If relief is late, the gap minutes stay visible rather than being absorbed into a rounded present day.
Exception: a delayed handover caused by transport, a medical emergency, or a client lock-out should be coded, not hidden. The code should appear on the client site attendance report so the invoice is not later described as a full-night occupancy that never happened. Honesty in the exception is cheaper than a disputed debit note. Keep a short code list — transport, lock-out, medical, client delay — so supervisors do not write essays, and so finance can decide whether the gap is billable under the contract.
- Require outgoing check-out and incoming check-in as separate events
- Alert on uncovered posts after a shift-specific grace period
- Record relief as a replacement assignment, not a renamed roster row
- Show delayed handover as a coded exception on the client report
Build a Client Report That Can Defend the Invoice
The client report is not a dump of GPS points. It is a coverage statement: site, post, scheduled hours, who was verified on site, actual start and end, gaps, relief names, and supervisor sign-off. Attach or retain the audit events behind each line so a debit note can be investigated without reconstructing WhatsApp history. Keep billing hours and payroll hours related but separate. A contract may bill a post for eight hours while the relief guard is paid under a different overtime rule.
Give operations a live occupancy view and finance a closed-period pack. Live occupancy answers whether the post is covered now. The closed pack answers what can be invoiced. If a guard was marked present but later rejected after a mock-location review, the invoice pack must not still show that night as fully occupied. Version the monthly file. Do not overwrite last month because a client asked for a courtesy adjustment. A courtesy credit should be a separate line, not a rewritten history of who was verified on site.
Attend Mitra is built for this chain: identity-verified attendance, site geo-fences, live monitoring of who is on an open shift, exception approval, and payroll-ready hours tagged by site. The goal is not more surveillance. It is a short path from roster to on-site proof to a client report that survives the sentence the post was empty. Supervisors work from occupancy and exceptions; finance works from the closed pack; the client sees coverage, not a raw GPS dump. That split is what lets an agency scale posts without inventing a second attendance story for invoicing. Multi-site operations continue in how to track security guards on multiple sites. Empty posts are a dispatch problem: how to handle security guard no-shows. Fake pins are covered in how to prevent GPS spoofing in attendance. Duty design sits in how to manage security guard shifts and security guard workforce software.
- Report approved coverage by post, with gaps and relief named
- Keep GPS events in the audit trail; give the client a coverage view
- Separate client billing hours from employee payroll categories
- Version the monthly invoice pack after mock-location and exception review

