How to Enable Timecard Editing in UKG WFM

UKG Workforce Management (WFM) gives managers and administrators precise control over when and how employees can edit their timecards. But that control comes layered across multiple configuration levels — which means enabling timecard editing isn't always a single toggle. Understanding where those settings live, and what governs them, makes the process significantly less frustrating.

What "Timecard Editing" Actually Means in UKG WFM

In UKG WFM (formerly Kronos Workforce Central or UKG Dimensions, depending on your platform version), timecard editing refers to the ability for employees, managers, or both to add, modify, or delete punch entries, pay code edits, and comments on a timecard.

This isn't a single system permission. It's a combination of:

  • Access control profiles — defining who can edit
  • Pay period status — defining when editing is allowed
  • Timecard authorization rules — defining what state a timecard must be in before edits are permitted
  • Organizational role assignments — defining which records a user can touch

Each layer can independently block or permit editing, so troubleshooting requires checking all of them.

Step 1: Check and Configure Access Control Profiles 🔐

Access Control Profiles (ACPs) are the primary mechanism for granting timecard edit rights in UKG WFM.

To review or modify them:

  1. Navigate to Administration > Application Setup > Access Profiles > Access Control Profiles
  2. Locate the profile assigned to the user role in question (employee, manager, or supervisor)
  3. Expand the Timekeeping section within the profile
  4. Look for permissions such as:
    • Edit Timecard
    • Edit Own Timecard (employee self-service)
    • Approve Timecard
    • Sign Off Timecard

Enable the relevant permissions and save. Changes typically apply at the next login or session refresh, though some environments require a cache clear.

Important: ACPs are assigned to People Records or Job Roles, not to individuals directly in most configurations. Verify which ACP is actually attached to the affected users before assuming a permission change will take effect.

Step 2: Verify Pay Period Close and Sign-Off Status

Even with the correct ACP, a timecard locked by sign-off or pay period close cannot be edited without additional action.

Lock TypeWhat It DoesHow to Unlock
Manager Sign-OffLocks the timecard after manager reviewManager must remove sign-off before edits
Supervisor Sign-OffSecondary lock layerSupervisor removes sign-off
Pay Period CloseSystem-level lock after payroll processingRequires admin to reopen the pay period
Timecard ApprovalWorkflow-based lockApproval must be retracted in workflow settings

To reopen a signed-off timecard, navigate to the timecard directly, select the relevant pay period, and use the Sign Off > Remove Sign Off option — if your role permits it.

Pay period reopening is a more elevated action. In UKG Dimensions (UKG Pro WFM), this is done through Maintenance > Pay Period Close, where administrators can reopen specific periods for specific employees or departments.

Step 3: Review Timecard Authorization Rules

Timecard authorization is a workflow feature that, when active, routes timecards through an approval chain. If your organization uses this feature, a timecard in an "approved" or "authorized" state will be read-only to most users.

To check whether authorization is blocking edits:

  1. Go to Administration > Application Setup > Pay Policies > Timecard Authorization
  2. Review whether authorization rules are active for the affected employee group
  3. Determine whether a retract-authorization permission needs to be added to the relevant ACP

Some organizations enable authorization rules during initial WFM deployment and forget they're active — which surfaces as a mysterious inability to edit timecards that otherwise appear unlocked.

Step 4: Employee Self-Service Timecard Editing

If the goal is enabling employees to edit their own timecards (rather than managers editing on their behalf), the configuration path is slightly different.

In UKG WFM, employee self-service timecard editing is controlled through:

  • Employee Self-Service profiles — separate from manager ACPs
  • Punch rounding and edit rules — which may restrict what employees can modify
  • Workflow rules — which may require manager approval of any employee-initiated edits

Navigate to Administration > Application Setup > Employee Self-Service > Timecard to find the relevant profile settings. Enabling the Allow Employees to Edit Timecard option here, combined with the correct ACP, is what most organizations need. ✅

Variables That Affect Your Configuration

The path to enabling timecard editing varies meaningfully based on several factors:

  • UKG platform version — UKG Workforce Central, UKG Dimensions, and UKG Pro WFM have different navigation structures and terminology for the same underlying concepts
  • Your organization's pay policy complexity — multi-union or multi-FLSA environments often have layered sign-off rules that require careful sequencing to unlock
  • Whether your instance is cloud-hosted or on-premises — some configuration options in cloud environments are managed at the tenant level by UKG administrators rather than your internal team
  • Custom workflow rules — organizations that have built approval workflows on top of standard WFM functionality may need to retract approvals before the standard unlock steps will work
  • Employee group assignments — different hyperfind queries or organizational maps may place employees under different rule sets even within the same company

A configuration change that works for one department's timecards may not apply to another if they're governed by different pay policies or ACPs.

When Standard Steps Don't Work 🔧

If you've confirmed the ACP settings, pay period status, and authorization rules are all correct but editing is still blocked, the issue is often one of:

  • Profile assignment mismatch — the user's People Record is linked to a different ACP than intended
  • Cached session data — changes not yet reflected in an active session
  • Database-level lock — rare, but possible in on-premises environments after failed pay period processing
  • Integration locks — payroll or HR integrations that write back a locked status to WFM after export

In those cases, UKG's support documentation and your system administrator logs are the most reliable diagnostic path, since the exact cause depends on your environment's specific integration and workflow configuration.

What's consistently true across configurations is that timecard editing in UKG WFM is always a product of multiple settings working together — and the right combination depends entirely on how your organization's instance was set up.