How To Enable Timecard Editing In UKG WFM: A Complete Administrator's Guide
To enable timecard editing in UKG Workforce Management (formerly UKG Dimensions), system administrators must configure the appropriate Function Access Profiles (FAPs) within Security Administration. By adjusting security switches for punches, pay codes, and historical corrections, and then assigning these profiles to users via People Information, you grant managers or employees the precise editing permissions required for accurate time tracking. Managing these permissions correctly prevents compliance risks while maintaining seamless payroll processing.
Administrative Prerequisites and Security Planning
Configuring timecard editing permissions in UKG Workforce Management (WFM) requires a structured approach to prevent unauthorized data manipulation while ensuring managers and employees can complete their tasks. Before modifying security permissions, your organization must define its payroll policies, audit requirements, and separation of duties. Unregulated editing privileges can lead to Fair Labor Standards Act (FLSA) compliance infractions or internal control failures.
Essential System Requirements and Prerequisites
- Mandatory User Access: A UKG WFM account with System Administrator or Security Administrator super-user credentials.
- Target Software Environment: UKG WFM (Dimensions) version 10 or higher with active licensing for Timekeeper.
- Information Architecture Knowledge: A fundamental understanding of your organization's Business Structure, Labor Levels, and the distinction between Function Access Profiles (FAPs) and Group Data Access Profiles (GDAPs).
- Audit Policy Standards: Documented business requirements detailing exactly who (e.g., salaried supervisors, hourly leads, self-service employees) is authorized to perform additions, updates, or deletions of timecard data.
- Configuration Timeline: 15 to 30 minutes, which includes profile updates, assignment to test records, and validation.
Step-by-Step Security Profile Configuration for Timecard Editing
Enabling timecard editing involves updating specific security settings in your system configuration. The process differs depending on whether you are adjusting access for a Manager Role (MSS) or an Employee Self-Service Role (ESS). Follow these sequential procedures to configure, assign, and verify timecard editing capabilities.
Step 1: Navigate to the Function Access Profile Designer
All system permissions in UKG WFM are controlled by Function Access Profiles. You must access this administrative module to define what actions a user can execute within their workspace.
- Log in to your UKG WFM instance using your administrative credentials.
- Open the main menu by clicking the gear icon or navigation tiles, depending on your custom layout.
- Select Administration from the navigation tree, then click on Security Administration.
- Within the Security Administration menu, select Function Access Profiles.
- Once the Function Access Profile list page loads, use the search filter to locate the profile assigned to the target user group (for example, "Standard Manager FAP" or "Hourly Employee FAP").
Warning: Never modify the default system profiles provided by UKG out of the box. Always highlight the default profile and click Duplicate to create a secure, custom configuration. This ensures you can revert changes if you encounter unexpected permission behavior.
Step 2: Access the Timekeeper and My Information Security Nodes
Once you have opened the duplicated or existing custom FAP in edit mode, you must isolate the correct functional categories.
- In the FAP Editor, locate the categorized folders in the left-hand navigation pane.
- For manager profiles, expand the Manager - Common node, and then expand the Timekeeper sub-folder. This area governs what a supervisor can do on their direct reports' timecards.
- For employee self-service profiles, expand the Employee - Common node, and then expand My Information followed by My Timecard. This area governs what actions an employee can perform on their own timecard.
Step 3: Configure Punch and Pay Code Editing Parameters
Within the Timekeeper or My Timecard security sub-folders, you will find several access control options. You must toggle these switches to explicitly allow editing functions.
- Scroll down to locate the entry labeled Punches. Toggle the radio button or checkbox to set this to Allowed or Edit. This grants permission to add, alter, or delete standard in/out punches.
- Locate the parameter for Pay Codes. Set this to Allowed to let users manually insert pay codes such as Vacation, Sick, or Jury Duty directly onto the timecard grid.
- Find the parameter labeled Delete Punch and decide if this is appropriate for the target audience. For standard employees, it is highly recommended to disable delete rights to preserve punch-in integrity.
- Locate Add/Edit Comments and set it to Allowed. Requiring comments for edited punches is an industry standard that ensures a clear audit trail for any changes made to worked hours.
- Identify the Historical Corrections permission. Toggle this to Allowed if you want supervisors to edit previous, signed-off pay periods. Note that this feature requires a separate approval workflow to process retroactive payroll adjustments.
Pro-Tip: If you want users to be able to enter transfers (such as changing cost centers or departments on the fly), ensure that Labor Category Transfers within this same Timekeeper folder is set to Allowed. Without this, the system will prevent edits that involve changing labor allocation.
Step 4: Map Group Data Access Profiles for Managers
Function Access Profiles dictate what actions can be taken, while Group Data Access Profiles (GDAPs) control whose records can be modified. For managers to edit timecards, their GDAP must be correctly configured.
- From the Security Administration menu, navigate to Group Data Access Profiles.
- Select the GDAP associated with your managers and click Edit.
- Verify that the Labor Levels or Organizational Jobs assigned to this profile correspond to the active employees whose timecards need editing.
- Set the access type to Read/Write for the defined business structure nodes. If it is set to Read-Only, the manager will see the timecard but cannot click into the cells to perform edits, even if their FAP allows it.
- Click Save to apply the data access rules.
Step 5: Assign the Updated Profiles to Employees or Managers
For the security modifications to take effect, the updated FAP must be bound to the target users' accounts.
- Go back to the main menu and select Maintenance, then choose People Information.
- Search for the specific user or select a group of users using the filter criteria.
- Open the employee's profile and expand the Licenses and Access section on the left-side navigation panel.
- In the Access Profiles section, locate the Function Access Profile drop-down menu.
- Select the custom FAP you modified in Step 3.
- Check the Display Profile to ensure it aligns with the timecard views you want to show (for example, hourly views versus salaried views).
- Click Save in the upper-right corner of the screen.
Step 6: Verify and Audit the Configuration
Before rolling the changes out to your live environment, test the editing workflow to ensure it works correctly and meets audit standards.
- Log out of your administrator account and log in using a test manager or employee account assigned to the modified FAP.
- Navigate to the Timecard widget.
- Attempt to add a punch, modify an existing in/out time, and add a pay code with a note.
- Verify that the Save button is active and that the edits save without throwing validation errors.
- Return to an administrator account, open the tested timecard, right-click on the edited punch, and select Punch Audit. Verify that the system correctly recorded the edit, listing the user who made the change, the precise timestamp of the edit, and the computer's IP address.
How to Create Schedules for Employees in UKG Pro WFM - UKG Partner
UKG WFM Security Permissions and Access Level Matrix
The table below outlines the core configuration variables, security paths, and recommended settings for setting up timecard editing access across different roles within your organization.
| Permission Parameter | FAP Configuration Path | Impact of Selection | Recommended Setting (Standard Employee) | Recommended Setting (Frontline Supervisor) |
|---|---|---|---|---|
| Punches - Edit | Timekeeper > Punches | Controls the ability to insert, modify, and adjust punch times on the grid. | No Access (or restricted to specific self-service tasks) | Allowed |
| Pay Codes - Add/Edit | Timekeeper > Pay Codes | Allows insertion of non-worked hours (Sick, Leave, Personal Time). | Allowed (if request workflow is not utilized) | Allowed |
| Punch - Delete | Timekeeper > Delete Punch | Grants the privilege to remove a recorded punch from the database. | No Access | Allowed with Audit Comment Required |
| Historical Corrections | Timekeeper > Historicals | Allows editing of closed and signed-off payroll cycles. | No Access | Allowed (with secondary HR/Payroll approval required) |
| Timecard Approval | Timekeeper > Approvals | Allows the user to apply an electronic approval signature to the timecard. | Allowed (for self-approval) | Allowed (for direct reports) |
| Labor Transfers | Timekeeper > Transfers | Allows shifting of worked hours to different department codes on the timecard. | No Access | Allowed |
Troubleshooting Common Timecard Edit Failures
Even after you configure the correct security profiles, users may still run into issues when trying to edit timecards. Below are common real-world failure points along with the steps to resolve them.
Problem 1: Timecard Cells are Greyed Out and Uneditable for Managers
- Root Cause: The target pay period is currently locked or signed off. Once payroll processes a pay period and applies a "Signed Off" status, UKG WFM locks those records to prevent edits that would cause discrepancies between the system of record and the issued paychecks.
- Actionable Fix: The administrator or payroll manager must temporarily lift the sign-off for that specific group of employees. Navigate to Maintenance > Share and Sign Off, select the target group, and click Remove Sign-Off. Once the edits are complete, re-apply the sign-off immediately to protect payroll integrity.
Problem 2: Employees Can Modify Punches but Cannot Save Changes
- Root Cause: This is typically caused by a mismatch between the Function Access Profile permissions and the Display Profile or Work Policy parameters. If the Work Policy assigned to the employee has strict "Punch Restriction Windows" or lockout policies active, the system will block changes even if the user's FAP allows them.
- Actionable Fix: Go to Application Setup > Work Policy Connections. Check the Punch Restriction Profile assigned to the employee. Adjust the restriction parameters to align with your self-service policies, or change the validation rule from "Hard Error" (which blocks saving) to "Warning" (which allows saving but flags the entry).
Problem 3: Managers Can Edit Timecards of Some Employees but Not Others
- Root Cause: The manager's Group Data Access Profile (GDAP) does not cover the complete business structure where the missing employees are currently scheduled or assigned. This often happens after department reorganizations or internal employee transfers.
- Actionable Fix: Open the manager's profile in People Information. Verify their assigned GDAP. If their access is limited to a specific department node, expand the scope of the GDAP to include the newly transferred employees' business units or assign a secondary job transfer path.
Problem 4: Historical Corrections Option is Missing or Returns an Out-of-Range Error
- Root Cause: The Historical Corrections Profile assigned to the user has a limited edit window (for example, restricted to 14 days post-pay period close), or the FAP is missing the permission to "Enable Retroactive Adjustments."
- Actionable Fix: Navigate to Application Setup > Work Policies > Historical Corrections. Select the active profile and verify the Effective Edit Period settings. Extend this duration to match your corporate policy limits, and ensure that the "Allow retro-adjustments" option is enabled in the user's FAP under the Historical Corrections sub-folder.
Frequently Asked Questions
Can employees edit their own timecards after a manager has approved them?
No. Once a manager approves an employee's timecard, it locks the card for that employee to prevent discrepancies. To make further changes, the manager must first remove their approval signature. This releases the lock so the employee can make changes, after which the card must be approved again.
What is the difference between a Function Access Profile (FAP) and a Group Data Access Profile (GDAP)?
A Function Access Profile controls what actions a user can take, such as adding punches, editing pay codes, or running reports. A Group Data Access Profile controls whose data those actions can be performed on, restricting access based on labor levels, departments, or specific locations within the organization.
How do I run an audit report to see who made edits to a timecard?
To view audit details, open the employee's timecard, right-click on any punch or pay code cell, and select Audit. Alternatively, you can run the system's Timecard Audit Trail Report from the Reports workspace. This report lists all edits, original entries, modified values, and the usernames of those who made the changes.
Why can't a supervisor edit a transferred employee's timecard?
If an employee transfers to a different department mid-pay-period, their hours may fall outside of their supervisor's Group Data Access Profile (GDAP). To fix this, your system's GDAP configurations must be updated to allow supervisors to view and edit timecards based on both the home department and any temporary work locations.
How do historical corrections differ from active pay period edits in UKG WFM?
Active pay period edits modify current, open timecards before payroll processes. Historical corrections are made to pay periods that have already been finalized and signed off. Historical corrections do not alter original paycheck records directly; instead, they calculate differences and apply retroactive pay adjustments to the current open pay cycle.
Optimize Your UKG Workforce Management Strategy
Maintaining a precise balance of security and accessibility in your UKG WFM environment is essential for payroll accuracy and operational efficiency. If you need help tailoring your security settings, implementing compliance workflows, or optimizing your system configuration, reach out to our team of certified system integration experts today.