Work top to bottom. Each item is a precondition for something below it — geofences before punches, punches before payroll, payroll before filings.
Organization
Organization profile is complete
Display name, legal name, country and currency are set, and the off-site punch reasons match how your people actually work. Settings → Organization. Locations exist, with correct geofences
Every place people work is a location, and its latitude/longitude/radius is right. Walk the perimeter with a phone if you can — a radius that is too tight turns ordinary arrivals into exceptions, and one that is too loose makes the check meaningless.
Time policy
Shift templates are created and published
Times, unpaid break, grace period, half-day cutoff, weekly offs, and the overtime rules. A draft template cannot be rostered — publish it. See Shift templates. Rosters are published for the first period
Assigning cells is not enough. Until a week is published, employees and managers do not see it, and the day engine has no shift to judge against. See Rosters. The holiday calendar is loaded
Import last year’s calendar and adjust, or add each holiday. Holidays change what a no-punch day means — with the calendar loaded, such a day is Holiday rather than Absent, and payroll does not debit it as loss of pay. See Holidays.
People and access
Employees are loaded, with manager links
Every employee has a department, a location, a shift and — critically — a manager. Approvals route on the direct-manager link; an employee with no manager has nobody to approve their leave. See The employee directory. Imported employees have real passwords
CSV import generates a random password that is never shown. Set a real one on each imported employee before go-live, or they cannot sign in.
Roles are reviewed
Confirm who is Admin, HR, Manager and Employee. Pay attention to who holds HR rights — that permission overrides the direct-manager restriction across the whole organization. See Roles & permissions and the roles editor.
Leave
Leave types are configured
Quota, accrual method and rate, carry-forward cap, half-day allowance, paid flag, and whether an HR second approval step is required. See Leave types and policies. Opening balances are correct
Employees joining mid-year rarely start at zero. Check what each person’s balance shows before the first request lands. See Balances and accrual.
Capture hardware
Biometric terminals are registered
Each terminal appears by serial once the connector has forwarded its first message. Register the ones you recognize. See Register a terminal. Terminal users are mapped to employees
A terminal identifies people by its own numeric user ID. Until that ID is mapped to an OnTime employee, punches from it are parked rather than applied. Clear the Unclaimed users queue on the Devices page — mapping replays what was parked. See Map terminal users. The connector is running with a real secret
Not the development default. Generate a strong CONNECTOR_SECRET and confirm the connector reaches your OnTime instance over HTTPS. See Install the connector.
Payroll and compliance
Salary components are defined
Compensation is set for every employee
Anyone without a salary structure will calculate to nothing. See Compensation. Run one cycle as a dry run
Start a cycle on a past month, freeze, calculate, and read the review screen — but do not disburse. Check the flagged rows: high loss-of-pay, high overtime, and large variance against the previous month are exactly where a bad geofence or an unmapped terminal shows up as money. See Running a cycle.
Disbursing a cycle materializes payslips and is the point of no return for that month. Do the dry run first.