eSSL · ZKTeco · Hikvision

Biometric attendance without the sync utility

Most biometric deployments come with a Windows machine in a corner running the vendor's sync tool, and an unspoken rule that nobody reboots it. ADMINFACE talks to devices directly — polled on a schedule, or receiving live pushes over ADMS — so punches reach attendance without a PC in the middle.

No credit card at signup. No trial clock. Your organisation gets its own isolated database.

Integration

Devices connected properly, not exported manually

Scheduled pull sync

The platform connects to each device on a schedule and fetches new logs, so punches arrive without anyone touching the reader.

ADMS live push

Devices post punches to a receiver endpoint as they happen — the option that works when the reader sits behind a router you do not control.

Multiple devices and sites

Register as many readers as you have. Each carries its own connection settings, so branches with different hardware coexist.

Connection testing

Test a device from the interface when adding it, instead of finding out at month end that it never connected.

Sync logs

Every sync attempt is recorded, so a device that stopped reporting on the 4th is visible on the 4th.

Employee mapping

Device user IDs map to employee records once, and punches land on the right person from then on.

How it works

Getting a device connected

1

Add the device

Register the reader with its make, address and credentials, then run a connection test before saving.

2

Choose pull or push

Either let the platform poll it on a schedule, or point the device at the ADMS receiver endpoint to push live.

3

Map the users

Match device user IDs to employee records once. New joiners are mapped as they are enrolled on the reader.

4

Punches become attendance

Logs land in the attendance register, get resolved against shifts, and carry into payroll.

The problem with how biometric attendance is usually deployed

The hardware is rarely the issue. Fingerprint and face readers are cheap, reliable and widely deployed. The failure is in what happens after the punch:

  • A Windows PC on-site runs the vendor's utility, and everything stops when it is switched off or updated.
  • Somebody exports a file from the device monthly and emails it to HR.
  • The export is a device log, not an attendance register — it has punches, not paid days.
  • Reconciling punches against shifts, leave and holidays is done by hand in a spreadsheet.
  • A reader that stopped syncing on the 4th is discovered on the 30th, with three weeks of data missing.

The last one is the expensive failure, because by the time it is found the data is often unrecoverable and a month of attendance has to be reconstructed from memory.

Pull or push

Two integration modes cover most site conditions:

  • Pull — the platform initiates the connection to the device on a schedule. Simple to set up, and appropriate where the device has a stable reachable address.
  • Push (ADMS) — the device posts each punch to a receiver endpoint as it happens. This is the mode that works on sites behind NAT, on consumer broadband, or anywhere you cannot get an inbound route to the reader. It is also closer to real time.
Silent failure is the real risk. Every sync attempt is written to a log, so a device that stopped reporting shows up as a gap you can act on rather than a surprise at month end. This matters more than raw sync speed.

Supported hardware

Dedicated adapters cover eSSL, ZKTeco and Hikvision devices — between them the majority of readers deployed in Indian offices, factories and clinics. The adapter layer is structured so each vendor's connection handling is separate, which is what makes supporting more of them a contained piece of work rather than a rewrite.

If you are running something else, the ADMS push route works with any device that speaks the protocol, since the receiver accepts the punch rather than the platform having to understand the device.

From punch to paid day

A punch is not attendance. Turning one into the other requires knowing which shift the employee was on, what the grace period is, whether the day was a declared holiday, and whether approved leave already covers it. Because shifts, holidays and leave all live in the same platform, that resolution happens automatically instead of in a spreadsheet.

The result is a daily register with a status per employee per day, which payroll reads directly to derive paid days, loss of pay and overtime. There is no export step between the reader and the payslip.

When the reader is not the whole story

Almost no organisation captures everyone on a device. Field staff, drivers, remote workers and anyone travelling need another route, and if that route is informal it undoes the discipline the reader was bought for. Web and mobile clock-in, GPS check-in for field staff, and WFH requests all write into the same register, so the exceptions are recorded rather than remembered. There is more on this on the attendance management page.

How we differ

ADMINFACE vs typical HR software

ADMINFACETypical HR platform
CostFree for unlimited employees and devicesOften licensed per device or per employee
On-site softwareNone requiredUsually a Windows sync utility
Live push supportADMS push receiver includedVaries; often pull only
Failure visibilitySync logged per attemptCommonly silent until month end
Shift resolutionAutomatic against shifts, leave and holidaysOften a manual spreadsheet step
Payroll linkDirect — same platformTypically a CSV hand-off

"Typical HR platform" describes the pricing and packaging patterns common across the category — per-employee monthly billing, feature tiers and time-limited trials. Individual products vary; check current terms with any vendor you are comparing.

FAQ

Frequently asked questions

Which biometric devices are supported?

eSSL, ZKTeco and Hikvision readers have dedicated adapters. Any device that supports the ADMS push protocol can also post punches to the receiver endpoint, since in that mode the device initiates the connection rather than the platform needing to understand the hardware.

Do we need a computer on site running sync software?

No. The platform either connects to the device on a schedule or receives pushed punches over ADMS. There is no on-premise utility and no dedicated Windows machine to maintain.

What is the difference between pull and push sync?

With pull, the platform initiates a connection to the device on a schedule — simple, and fine where the device has a stable reachable address. With push, the device posts each punch as it happens, which works on sites behind NAT or consumer broadband where you cannot route inbound to the reader, and is closer to real time.

How do we know if a device stops syncing?

Every sync attempt is written to a log you can review, so a device that stopped reporting is visible as a gap rather than discovered at month end. Silent failure is the most expensive biometric problem, because the missing data is usually unrecoverable by then.

Can we connect devices at multiple branches?

Yes. Any number of devices can be registered, each with its own connection settings, so branches running different hardware work side by side under one organisation.

How do device punches become payroll data?

Punches resolve against the employee's assigned shift, the holiday calendar and any approved leave to produce a daily attendance status. Payroll reads that register directly to derive paid days, loss of pay and overtime, so no export or re-keying is involved.

Is biometric integration included on the free plan?

Yes, with no per-device or per-employee charge. Device integration is commonly held back as an enterprise feature elsewhere; here it is on the free plan.

Explore more

Other things ADMINFACE handles

Connect your readers this week

Register your devices, run a connection test and let punches flow into attendance and payroll. Free for unlimited employees and unlimited devices.