Security
How to manage 2FA, web access, clock-in/out controls, and grace periods in WorkClock HQ.
Security
Use Security to protect administrator accounts and control how employees clock in and out.
Open it from Company Settings > Security, or go to /company-settings?tab=security.
What You Can Manage
| Setting | Purpose |
|---|---|
| Two-Factor Authentication (2FA) | Adds extra protection to the signed-in user's account. |
| Web Access | Allows users to clock in and out from the web app. |
| Clock In | Enables or disables clock-in for the organization. |
| Clock Out | Enables or disables clock-out for the organization. |
| Clock In Access Time | Sets organization-wide clock-in access time in minutes. |
| Clock Out Grace Period | Sets organization-wide clock-out grace period in minutes. |
Two-Factor Authentication
2FA is controlled for the current signed-in user.
How To Enable 2FA
- Open Company Settings > Security.
- Find Two-Factor Authentication (2FA).
- Turn the toggle on.
- Complete the 2FA setup modal.
How To Disable 2FA
- Open Security.
- Turn the 2FA toggle off.
- Wait for the app to process the change.
Web Access
Web Access controls whether users can clock in and out from the web app.
How To Enable Or Disable Web Access
- Open Security.
- Find Web Access.
- Turn the toggle on or off.
This setting can be restricted by plan or permission. If restricted, the toggle may be disabled and an upgrade or restriction message may appear.
Clock-In Control
Clock In controls whether users can clock in when working.
How To Enable Or Disable Clock-In
- Open Security.
- Find Clock In.
- Turn the toggle on or off.
When disabled, users cannot clock in until the setting is enabled again.
Clock-Out Control
Clock Out controls whether users can clock out when working.
How To Enable Or Disable Clock-Out
- Open Security.
- Find Clock Out.
- Turn the toggle on or off.
When disabled, users cannot clock out until the setting is enabled again.
Clock In Access Time
Clock In Access Time is an organization-wide minute value. The UI also displays the equivalent in hours and minutes when the value is greater than zero.
How To Update Clock In Access Time
- Open Security.
- Find Clock In Access Time.
- Enter the number of minutes.
- Click Save.
Clock Out Grace Period
Clock Out Grace Period is an organization-wide minute value. The UI also displays the equivalent in hours and minutes when the value is greater than zero.
How To Update Clock Out Grace Period
- Open Security.
- Find Clock Out Grace Period.
- Enter the number of minutes.
- Click Save.
Operating Advice
- Keep 2FA enabled for administrators with billing, role, security, or employee management access.
- Disable organization-wide clock-in or clock-out only during planned maintenance or emergency control situations.
- Review web clocking carefully if your attendance policy depends on mobile app location controls.
- Use practical grace periods that match how your organization handles early clock-ins or late clock-outs.
FAQs
Does 2FA apply to everyone in the organization?
The visible 2FA toggle applies to the current signed-in user's account.
Why is Web Access disabled?
The feature may be restricted by plan, organization policy, or your permissions.
What happens if Clock In is turned off?
Users cannot clock in until the setting is turned on again.
What happens if Clock Out is turned off?
Users cannot clock out until the setting is turned on again.
Are grace periods entered in minutes?
Yes. Enter the value in minutes. The UI shows the equivalent in hours and minutes for easier review.
Roles & Permissions
How to create and edit administrative roles with granular permissions in WorkClock HQ.
Departments & Sub-Departments Management
Comprehensive guide to managing company departments, sub-departments, structural hierarchy rules, deletion conditions, and department head leadership delegation.