A clock-in is rejected
The sign-in dialog shows a failed condition and will not confirm — outside the allowed area, network not allowed, outside working hours, already signed in, or no location at all. Each message is a different rule on the working schedule, and this page maps them.
The sign-in dialog checks the punch against the working schedule before accepting it, and shows each condition as passed or failed. This page is for the failures: the message on screen names the rule, and every rule lives on the schedule’s editor in the console.
"You are outside the allowed area"
Most commonThe schedule requires a GPS position inside one of its geofences, and the phone’s position is outside every circle. The dialog’s map shows Your location against the Allowed area, so look there first: if the pin is just outside the circle, the fence is drawn too tight — indoor GPS is easily 30–50 m off. Widen the Radius (meters) on the schedule’s Security & location page, or add a fence for a site that is missing.
If the pin is somewhere else entirely, the phone’s location is stale or coarse — moving near a window and retrying usually refreshes it.
Open Working schedule"Location permission denied" or "Unable to retrieve your location"
CommonThe schedule requires a position but the app never got one. Location permission denied means the person declined the browser or phone permission prompt — it must be re-allowed in the device or browser settings, not in Offision. Unable to retrieve your location means permission was granted but no fix arrived; retry, or move somewhere with sky or Wi-Fi.
Some embedded hosts never allow location at all — Offision opened inside Microsoft Teams is the common case. The app detects this and offers the way out itself: open Offision in the device’s browser, or use the mobile app.
"Outside of working hours"
CommonThe schedule enforces its working hour for this direction, and the punch is earlier or later than the working hour allows — beyond the Early check-in allowed (minutes) or Late check-out allowed (minutes) tolerance. Check three places, in order: the tolerance fields on the schedule’s Check-in rules page (zero minutes refuses someone ten minutes early), the working hour’s time ranges and weekdays, and its holiday calendar — on a holiday or a non-working day there is no working hour to be inside.
Open Working hours"Network access not allowed" or "Unable to detect network information"
Less commonThe schedule requires the punch to come from an Allowed IP range and this one did not. The usual cause is the list holding the office’s internal range while punches arrive with the office’s public address — add the public address the office traffic leaves through. Unable to detect network information means no address reached the server at all, which is a network or proxy question, not a settings one.
"Already signed in today"
Less commonAllow multiple check-ins per day is off and the person already has a sign-in today on this schedule. That is the rule working as designed for one-shift teams. If the team genuinely punches more than once a day — split shifts, site moves — switch it on; if the first punch was a mistake, an administrator can delete it in Attendance Records and the person can punch again.
Open Attendance RecordsThere is no Sign in button at all
Less commonThe buttons appear only for people on a working schedule whose rules allow that direction from that channel. No button means no covering schedule: the person is not in the Worker list (check the group membership, not just the names), or every schedule covering them has Allow check-in via User Portal switched off — the dialog’s Access not allowed from this channel is the same rule caught one step later. At a kiosk, the equivalent switch is Allow check-in via Player.

