> ## Documentation Index
> Fetch the complete documentation index at: https://docs.timetracker.in/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a location rule

> Build a location rule in TimeTracker: name it, choose what counts as being at work, pick what it limits, assign it to people, then switch it on safely.

A location rule says what counts as being at work, what needs it, and who it
applies to. This page walks the whole thing end to end.

Go to **Settings → Location rules**.

<Info>
  Location rules is **Pro** and the app is **off by default**. Turn it on under
  **Settings → Apps** first.
</Info>

## Before you start

You need the `location.manage` capability – Owner or Admin only.

Have this ready:

* The **public address range** of your office network, from whoever runs your
  network. Not the address of a single computer.
* Or the **address of the place**, if you are fencing a site rather than a
  network.
* A clear answer to *which actions actually need this*.

## Step 1 – Create the rule

<Steps>
  <Step title="Click New rule">
    In the **Rules** card.
  </Step>

  <Step title="Name it">
    **Name** – name it after the place it describes, for example `Head office`.
    Up to 80 characters.
  </Step>

  <Step title="Click Create rule">
    You get *"Rule created – it isn't stopping anyone yet"*.
  </Step>
</Steps>

The dialog tells you what happens: *"Name it after the place it describes. It
starts out watching, so it won't stop anyone until you say what it limits and
switch it on."*

## Step 2 – Say what counts as being at work

Open the rule. In **The rule** card set **Someone counts as here when they are**:

| Option                              | Use it when                                            |
| ----------------------------------- | ------------------------------------------------------ |
| **On an office network**            | People work from a fixed office on your own connection |
| **At one of the places**            | People work at sites, on phones                        |
| **Both the network and the place**  | Strictest – both checks must pass                      |
| **Either the network or the place** | Most forgiving – either one is enough                  |

Add a **Description** if it helps – *"Optional – what this rule is for"*.

<Note>
  The rule page says it plainly: *"Laptops often report a place that is a long way
  out, so office networks are the more reliable check on a computer and places work
  best on a phone."*
</Note>

## Step 3 – Add your networks or places

### Office networks

*"Anyone connecting from one of these counts as being at work."*

The **You're connecting from** card shows your own current address, with an **Add
this address** button. That is the quickest way to add the office you are sitting
in.

Otherwise click **Add address range** and fill in:

| Field                | Example          |
| -------------------- | ---------------- |
| **Name**             | `Office`         |
| **Address or range** | `203.0.113.0/24` |

Up to **50** ranges per rule. Full detail in
[IP restrictions](/location-rules/ip-restrictions).

### Places

*"Named locations someone can be standing in."*

Click **Add a place**:

| Field                        | Notes                                                                  |
| ---------------------------- | ---------------------------------------------------------------------- |
| **Name**                     | `Head office`                                                          |
| **Where is it**              | Paste a maps link, or type `51.5074, -0.1278`, then click **Use this** |
| **Latitude** / **Longitude** | Filled in for you, editable                                            |
| **Area**                     | 50 m, 100 m, 250 m, 500 m or 1 km                                      |

**Use my current location** fills it from your own device. **Check this place**
tells you how far you are from it right now.

Up to **50** places per rule. Full detail in
[GPS restrictions](/location-rules/gps-restrictions).

## Step 4 – Choose what the rule limits

In **What this rule limits**: *"Only these need someone to be at work. Everything
else carries on as normal."*

There are **13** actions, grouped:

| Group                         | Actions                                                              |
| ----------------------------- | -------------------------------------------------------------------- |
| **Workspace**                 | Export workspace data                                                |
| **Clients, projects & tasks** | Create tasks · Edit tasks                                            |
| **Time tracking**             | Track time · Edit time entries                                       |
| **Timesheets**                | Submit own timesheet · Approve or reject timesheets                  |
| **Timecards**                 | Clock in and out · Submit own timecard · Approve or reject timecards |
| **Budgets & money**           | Submit expenses · Approve or reject expenses                         |
| **Reports**                   | Export reports                                                       |

The header shows **"Nothing is limited yet."** or **"N of 13 limited"**.

<Tip>
  There is no "select all", on purpose. Pick the two or three actions that genuinely
  need to happen at work. Limiting all thirteen produces a rule nobody can work
  around and everybody complains about.
</Tip>

Settings, billing, roles and member management can never be limited. That is what
stops a rule locking you out of your own workspace.

## Step 5 – Set how often to check

In **How often we check**: *"A check stays good for this long, so people are not
interrupted constantly."*

**A check stays good for**: 5 minutes, 15 minutes, 30 minutes or 1 hour.

The page explains the trade-off: *"Someone who leaves right after a check can keep
working for up to this long, plus a short allowance for patchy Wi-Fi. Shorter is
stricter but checks more often."*

## Step 6 – Save

A bar appears at the bottom of the page when you have unsaved changes:
**Unsaved changes** · **Discard** · **Save changes**.

One save covers the whole page. You get **Saved**.

## Step 7 – Assign it to people

A rule does nothing until an assignment points at it.

<Steps>
  <Step title="Go back to Settings → Location rules">
    Use the **All location rules** link.
  </Step>

  <Step title="Click Apply rule">
    In the **Who these rules apply to** card.
  </Step>

  <Step title="Choose who">
    **Applies to** – Everyone, A role, A group, or One person. Then pick the
    specific role, group or person.
  </Step>

  <Step title="Choose the rule">
    **Rule** – pick your rule, or **Exempt – no location rule** to lift every
    rule from someone.
  </Step>

  <Step title="Set the dates">
    **Start** defaults to today. **End** can be left empty for no end date.
  </Step>

  <Step title="Check the count">
    The dialog shows **"This covers N people."** Read it before you continue.
  </Step>

  <Step title="Click Apply rule">
    You get **Rule applied**.
  </Step>
</Steps>

### Who wins when several assignments match

Most specific wins:

**Person → Group → Role → Everyone**

Within the same level, an **exemption beats a restriction**. Across levels the
more specific level wins outright – so a rule applied to one person survives a
workspace-wide exemption.

Someone in several groups follows their **first** group.

<Note>
  You cannot give the same target two overlapping assignments. You get: *"This
  target already has a location rule covering those dates. End or remove that one
  first."*
</Note>

## Step 8 – Watch before you enforce

Leave the rule in **Watching** for about a week. Read **Recent checks** each day –
see [Activity log](/location-rules/activity-log).

You are looking for people who would have been stopped but should not have been.
Every one of those is a range you forgot or a place drawn too tightly.

## Step 9 – Switch it on

Open the rule and click **Start enforcing** in the **Enforcement** card.

The confirmation tells you the truth about what you are about to do:

> **Start enforcing Head office?**
> N people will only be able to *track time, clock in and out* from work.
> In the last 7 days, **N** of them would have been stopped at least once.
> You can switch back to watching at any time, and you will always be able to
> reach these settings – location rules never limit settings, billing or roles.

Confirming also saves any unsaved edits on the page.

<Warning>
  If a number of people would have been stopped in the last 7 days, stop and find
  out why before you continue. That number is your rule's real error rate.
</Warning>

### When TimeTracker refuses to enforce

A rule that would stop everyone cannot be switched on. You see one of:

| Message                                                                                                                                    |
| ------------------------------------------------------------------------------------------------------------------------------------------ |
| *"This rule checks the office network but no address ranges are set, so it would stop everyone. Add one, or change what the rule checks."* |
| *"This rule checks the person's place but none are set, so it would stop everyone. Add one, or change what the rule checks."*              |
| *"Add an office network or a place before switching this rule on – as written it would stop everyone."*                                    |
| *"Pick at least one thing this rule should limit."*                                                                                        |

## Example

Northwind Studio wants contractors to clock in from the studio only.

| Step           | What Maya does                                                        |
| -------------- | --------------------------------------------------------------------- |
| Create         | Name it `Studio`                                                      |
| What counts    | **On an office network**                                              |
| Networks       | Adds the studio's range using **Add this address**                    |
| Limits         | Ticks **Clock in and out** and **Track time** – 2 of 13               |
| Check interval | 15 minutes                                                            |
| Assign         | **A role → Contractor → Studio**, starting Monday                     |
| Watch          | One week. Ana Ferreira would have been stopped twice, both from home. |
| Decide         | That is the intended behaviour, so Maya clicks **Start enforcing**    |

Sarah Lin and Jonas Bergman are Members, not Contractors, so nothing changes for
them.

## Switching a rule back off

Open the rule and click **Switch back to watching**. It stops stopping people
immediately.

To lift **every** rule at once, turn the Location rules app off under **Settings
→ Apps**. The rule page mentions this: *"Turning the Location rules app off in
Settings → Apps lifts every rule at once, if you need to undo this in a hurry."*

## Deleting a rule

In the **Rules** table, click the delete icon on the row. The confirmation reads
**"Delete {name}?"** – *"The rule and everything it limits will be removed. This
cannot be undone."*

You cannot delete a rule that is still assigned: *"'{name}' is still assigned to N
targets. Remove those assignments first."*

## Permissions

| Action                             | Capability        | Roles        |
| ---------------------------------- | ----------------- | ------------ |
| Create, edit, assign, delete rules | `location.manage` | Owner, Admin |

## Common questions

<AccordionGroup>
  <Accordion title="Nothing happened after I created a rule. Why?">
    Three things must all be true: the rule limits at least one action, an
    assignment points it at someone, and it is Enforcing rather than Watching.
  </Accordion>

  <Accordion title="How do I exempt one person from a workspace-wide rule?">
    Apply a rule to that person and choose **Exempt – no location rule**. A
    person-level assignment beats a workspace-level one.
  </Accordion>

  <Accordion title="Can I schedule a rule to start next month?">
    Yes. Set the assignment's **Start** date. Leave **End** empty for no end date.
  </Accordion>

  <Accordion title="What if someone is in two groups?">
    They follow their first group. If that is not the group you meant, assign the
    rule to that person directly – a person-level assignment beats a group one.
  </Accordion>

  <Accordion title="Do client-portal contacts get caught by a rule?">
    No. Clients are never subject to a location rule and never appear in any
    count.
  </Accordion>
</AccordionGroup>

## Troubleshooting

**Start enforcing is refused.** The rule has an empty signal or limits nothing.
The message names the exact problem.

**The person count looks wrong.** Read the **Who this affects** table on the
settings page. It shows exactly who is covered today, with the level each rule
was applied at.

**I cannot add my office address.** It must be a public address range, not an
internal one such as `192.168.x.x`. Ask whoever runs your network for the public
range.

## Related guides

<CardGroup cols={2}>
  <Card title="Location rules overview" icon="map-pin" href="/location-rules/overview">
    The concept and what it cannot see.
  </Card>

  <Card title="IP restrictions" icon="network-wired" href="/location-rules/ip-restrictions">
    Office networks in detail.
  </Card>

  <Card title="GPS restrictions" icon="location-dot" href="/location-rules/gps-restrictions">
    Places in detail.
  </Card>

  <Card title="Activity log" icon="clock-rotate-left" href="/location-rules/activity-log">
    What to read before you enforce.
  </Card>

  <Card title="Location permissions" icon="shield" href="/location-rules/location-permissions">
    Who can manage rules.
  </Card>

  <Card title="Groups" icon="users" href="/team/groups">
    The groups you can assign a rule to.
  </Card>
</CardGroup>
