One record of who worked, from the gate to the payroll ledger

A corporate group running a head office in Harare and several operating sites, with permanent staff, daily-rated labour and contractors on one wage bill. The problem was never the payroll software; it was the weeks each month spent gathering, disputing and re-keying the attendance behind it. We built the layer between the site and the pay run, so the record of who worked arrives complete and already approved.

Automated HR & payroll
Sector
Corporate operations

The operational challenge: month-end as an archaeological dig

Attendance arrived in four incompatible forms — a signed register at each gate, overtime chits from supervisors, a WhatsApp group for weekend call-outs, and phone calls for anyone working away from a site. The HR officer spent much of each month assembling that into a spreadsheet, and the rest of it defending the result. Disputes could not be settled honestly, because nobody held a timestamped record: a supervisor's memory of a Saturday shift was the only evidence.

The infrastructure already on site

Nothing was bought in the first phase. Each site had cameras covering the pedestrian gate for security, supervisors carried Android phones, the stores counter had a tablet, and head office ran an established payroll package finance trusted and had no wish to replace. Week zero confirmed what each camera could actually see at shift changeover, and which system held the authoritative employee record.

What was built

Three things. Clock-in points: facial recognition on the existing gate cameras, a geofenced check-in on supervisors' phones for staff who never pass a gate, and the stores tablet as a fallback for new starters not yet enrolled. An attendance ledger turning raw arrivals and departures into shifts, overtime, absence and leave against each employee's grade and roster. And an approval layer that raises only exceptions, holds the audit trail, and exports the payroll input in the format the existing package expects.

How it runs day to day

Staff are recognised at the gate without stopping at a reader or signing anything. Supervisors no longer approve registers; at shift start they clear a short list of exceptions — a missing clock-out, a shift longer than the roster allows, an absence with no leave request behind it. At period end the run is assembled from records approved as they happened.

Integration points

The system reads the gate cameras over the site network, the supervisor application, and the employee master in the existing HR records. It writes a payroll import file to the finance package, statutory schedules for ZIMRA, NSSA and the relevant National Employment Council in the formats finance already files, and notifications — contract expiry, probation end, certificate renewal, an ageing exception — into channels managers already watch. Where a site runs its own access control, the same events drive access decisions rather than being captured twice.

Guardrails and what stayed with people

Biometric attendance is personal data, so enrolment followed a written policy, staff were told the purpose and retention, and the data lives in the group's own tenant. Nothing pays without human approval, and an uncertain reading escalates to a named person rather than being resolved by the machine.

What it covers

No new hardware in phase one

Gate cameras, supervisor phones and the stores tablet became the clock-in points. A dedicated terminal was considered only where a camera angle could not be made to work.

Exception-based approval

Supervisors review what looks wrong rather than signing off every name every day, which is what makes the approval meaningful.

Evidence behind every line

Each shift on a payslip traces to a timestamped event at a known place, so a disputed Saturday is settled by looking it up, not by seniority.

The payroll engine was kept

Finance carried on with the package they knew. We automated everything upstream and handed over a validated import file each period.

Offline by design

Clock-in points buffer locally through a power cut or a dropped link and synchronise when service returns. Gaps are flagged, never quietly closed.

Mixed workforce, one record

Permanent staff, daily-rated labour and contractors clock in the same way, each with their own rate rules, so site headcount is a single number.

How it works

01

Site assessment

Week zero. We walked each gate at shift changeover, sat through a month-end in the payroll office, and documented the cameras, phones, HR records and payroll package already in use.

02

Integration and observation

Weeks one to three. Clock-in points, employee master and payroll export were connected, then run beside the paper register. The system recorded but could not act, and both records were compared daily.

03

Rules and guardrails

Week four. Grades, rosters, overtime, allowances, leave accrual, statutory deductions and escalation paths were encoded, then replayed over periods already paid until a test run reconciled to a pay run the group recognised.

04

Go live and optimise

Week five onward. The system took capture, approval, calculation and the payroll file, with weekly reviews tightening exception thresholds and tuning recognition as each gate's real patterns emerged.

Questions buyers ask

Can you name the client for this deployment?

Not on a public page — attendance and payroll data is sensitive, and most clients prefer the work stays unattributed. For a serious evaluation we can arrange a reference conversation under a mutual non-disclosure agreement, and show you a working system.

We have five sites in three provinces. Does this scale past one location?

Each site keeps its own clock-in points and runs independently of head office connectivity, while the ledger and dashboard consolidate. We take one site fully live, prove the configuration through a real pay run, then roll the tested setup out.

What happens if facial recognition does not identify someone?

Nobody is turned away and the shift is not lost. The event is recorded as unmatched and offered to the supervisor to confirm against the tablet or phone check-in, so a poor match becomes an exception to clear, not an unpaid day.

Does this replace our HR officer?

It replaces the data entry, not the role. What disappears is transcription, chasing chits and rebuilding registers; what remains is exception handling, employee relations and compliance work.

How long before we could run a pay period on it?

Approximately four to six weeks from site assessment to go live for a first site, with the observation period deliberately overlapping a full pay cycle so you compare the system against your own register before depending on it.

Who holds the biometric and payroll data?

You do. It sits in your environment or a dedicated tenant, with an agreed retention period, controlled access and a record of who looked at what. We will not deploy an enrolment process your HR and legal advisers have not approved.

Platform briefing

Book a platform briefing

Fifteen minutes with an engineer, not a sales pitch. Tell us how attendance reaches your payroll office today and we will say which part we would automate first and what it would take on your sites. Email sales@eigenstatesystems.com or message us on WhatsApp on +263 77 636 6999.

sales@eigenstatesystems.com · +263 77 636 6999 · Harare