A data flow diagram (DFD) for an attendance monitoring system maps how time-in and time-out data flow between employees or students, biometric or QR devices, HR administrators, and the reporting layer. Attendance monitoring remains one of the most-picked BSIT capstone topics because every school and workplace uses it, and panel reviewers in 2026 expect modern capture methods (biometric plus QR plus facial recognition) and Data Privacy Act compliance. This guide covers the three-level DFD with defense-ready detail.
Quick 2026 verdict
A defensible attendance DFD in 2026 has 4-5 external entities (Employee or Student, HR Admin, Biometric Device, Supervisor, Mobile App User), 8-10 processes covering registration, capture, verification, hours computation, corrections, leave handling, and reporting, and 6-8 data stores with proper Data Privacy Act notation on biometric templates. Add mobile self-service and geolocation flow to look current-year.
What an attendance DFD captures
The DFD shows how identity verification (fingerprint, face, ID card, QR code) becomes a timestamped attendance record that HR uses for payroll and reports. It answers panel questions like: where does the raw fingerprint template live, who can access it, how does the system decide if a swipe counts as time-in or time-out, and what happens when the biometric device is offline.
Panels in 2026 are stricter about biometric handling than in 2020. Any attendance system that captures fingerprint or facial data must show explicit Data Privacy Act (RA 10173) compliance in the DFD, including retention notation and access-log flow.
Level 0 (context diagram)
Employee/Student -----> [Attendance System] <----- HR Admin
^ ^
| |
Biometric Device Supervisor
| |
v v
Payroll System Mobile App UserExternal entities for a 2026 attendance DFD:
- Employee or Student: the person marking attendance via biometric scan, QR code, ID card tap, or facial recognition
- HR Admin: manages enrollment, sets work schedules, reviews attendance reports, exports payroll data
- Biometric Device: fingerprint reader, facial camera, or RFID/QR scanner (physical device or mobile app equivalent)
- Supervisor: approves leave requests, authorizes attendance corrections, views team dashboard
- Mobile App User: separate entity if the system supports mobile self-service (view own attendance, request correction, apply for leave)
- Payroll System: external system that receives finalized attendance data for salary computation
Level 1 (main process decomposition)
Level 1 expands the attendance system into 8-10 sub-processes:
- 1.0 Enroll User: HR Admin registers a new employee or student; captures biometric template from Biometric Device; writes to
D1: Usersand biometric-template hash toD2: BiometricTemplates - 2.0 Set Work Schedule: HR Admin defines shift patterns, cutoff times, grace periods; writes to
D3: Schedules - 3.0 Capture Attendance: input from Employee via Biometric Device; verifies identity by matching against
D2; writes raw event toD4: AttendanceEvents - 4.0 Classify Time-in or Time-out: reads the last event for this user from
D4; determines if current swipe is entry, break, return, or exit based on schedule inD3 - 5.0 Compute Hours: aggregates entry/exit pairs at end of day; computes regular hours, overtime, tardiness; writes to
D5: AttendanceRecords - 6.0 Handle Corrections: input from Employee (correction request) via Mobile App; Supervisor approval flow; updates
D5with audit trail inD6: CorrectionLog - 7.0 Handle Leave Requests: input from Employee (leave application) with type and dates; reads leave balance from
D7: LeaveBalances; Supervisor approval; writes decision toD8: LeaveRecords - 8.0 Notify User: sends SMS or email confirmation of successful attendance capture, leave approval, or correction status
- 9.0 Generate Reports: HR Admin reads aggregated attendance and leave data from
D5, D6, D8; produces daily, monthly, and per-department reports - 10.0 Export to Payroll: at cutoff (weekly, bi-monthly, or monthly), pushes finalized attendance data to Payroll System external entity
Data stores with security notation:
D1: Users(user ID, name, department, role, contact; governed under RA 10173)D2: BiometricTemplates(user ID, template hash; NEVER raw fingerprint image; retention 3 years post-separation, access logged)D3: Schedules(user ID or department, shift, start time, end time, grace period, cutoff)D4: AttendanceEvents(event ID, user ID, timestamp, device ID, event type: raw scan)D5: AttendanceRecords(record ID, user ID, date, time in, time out, hours regular, hours overtime, tardy minutes)D6: CorrectionLog(correction ID, original record ID, requester, approver, reason, timestamp)D7: LeaveBalances(user ID, sick leave days, vacation days, service incentive leave)D8: LeaveRecords(leave ID, user ID, type, start date, end date, status, approver)
Level 2 (focused sub-process zoom)
Highest-value Level 2 decompositions for attendance defense:
- 3.0 Capture Attendance expands into 3.1 Receive Scan from Device, 3.2 Look Up Template Hash, 3.3 Verify Match Above Threshold, 3.4 Handle Failed Match, 3.5 Record Successful Event, 3.6 Trigger Notification
- 4.0 Classify Time-in or Time-out expands into 4.1 Read Latest Event for User, 4.2 Compare to Schedule, 4.3 Classify as Entry / Break / Return / Exit, 4.4 Handle Duplicate Scan within Grace Period, 4.5 Flag Anomaly for Supervisor
- 7.0 Handle Leave Requests expands into 7.1 Verify Leave Balance, 7.2 Check for Schedule Conflict, 7.3 Notify Supervisor, 7.4 Await Approval, 7.5 Deduct Balance on Approval, 7.6 Send Confirmation
2026 attendance features every DFD should include
- Multi-modal capture. Show at least two capture methods in Level 1: biometric (fingerprint or face) plus QR code fallback. Panels ask what happens if the biometric device fails.
- Facial recognition support. If your project uses face-api.js, MediaPipe, or OpenCV, add “facial capture” as a variant of the Capture Attendance process. Flag the face-embedding storage under RA 10173.
- Geolocation for mobile self-service. If the Mobile App User external entity is present, add a geolocation flow to prove the user marked attendance from the workplace, not from home.
- Offline capture and sync. Biometric devices sometimes lose network. Show a local-cache flow at the device level and a batch-sync flow when connectivity returns.
- Supervisor approval for corrections. Employees cannot self-correct their attendance. Show approval data flow through Supervisor to the Correction process.
- Automatic overtime flagging. Compute Hours should flag hours above the schedule as overtime pending Supervisor approval, not silently include them in payroll.
- Data Privacy Act notation on D2 BiometricTemplates. Biometric data is sensitive personal information under RA 10173. Add: “Retention 3 years post-employment separation. Access restricted to HR Admin, all reads logged.”
Common Level 1 mistakes reviewers catch
- Storing raw fingerprint images instead of hashed templates (major privacy violation flagged by panels)
- No Classify Time-in or Time-out process (raw events without meaning is not useful data)
- Corrections applied by the Employee directly without Supervisor approval
- Leave Balance store present but Handle Leave process does not deduct on approval
- Payroll export shown as bidirectional (payroll should only receive, never send data back)
- Mobile App User missing but paper claims mobile support
- No offline / sync flow shown, so the DFD implies the system fails when the device loses network
- Biometric template store not annotated with RA 10173 compliance
Comparison: capture methods for attendance capstone
| Method | Hardware cost | Panel Difficulty |
|---|---|---|
| Fingerprint (ZKTeco, Digital Persona) | ₱1500-4000 device + SDK | Medium (classic) |
| Facial recognition (webcam + face-api.js) | Free (open source) | Hard (privacy questions) |
| QR code (student scans printed QR at kiosk) | Free (webcam or phone) | Easy (fastest to build) |
| RFID card tap | ₱500-2000 reader + tags | Medium |
| Mobile app + geolocation | Free (uses user phone) | Medium (2026-friendly) |
Frequently Asked Questions
Do I need biometric hardware for the capstone to be defensible?
No. QR code kiosk or mobile app with geolocation is fully defensible for BSIT capstone in 2026. Biometric hardware is a nice-to-have, not required. Panels grade the DFD and system design, not the hardware price tag.
Where do I show the biometric template storage in the DFD?
Data store D2 (BiometricTemplates), separated from D1 (Users). Add explicit annotation: “Templates only, not raw images. Governed by RA 10173.” The Enroll User process writes to D2; the Capture Attendance process reads from D2 for verification.
How do I differentiate this DFD from a Sequence or Use Case diagram for the same system?
A DFD shows data movement between processes, entities, and stores. A Sequence diagram shows message ordering over time between objects. A Use Case diagram shows actor-goal relationships. Each answers a different question and should appear in different parts of your Chapter 3. Do not skip any of them.
Should mobile app self-service be a separate entity or the same as Employee?
Same person, different channel. Show it as Mobile App User external entity to make the channel visible in the DFD. Reviewers ask specifically about mobile flow if the paper claims mobile support, and having a distinct entity makes the answer easier.
How do I show offline capture in the DFD?
Add an intermediate data store at the device level: D-Local (device-side cache). Capture Attendance writes to D-Local when the network is down; a Sync Local Events process pushes D-Local to D4 (AttendanceEvents) when connectivity returns. This is optional at Level 1 and typical at Level 2 for the Capture Attendance decomposition.
Does the payroll system need to be inside my DFD?
No, only as an external entity. Payroll is a separate system. Show a one-directional data flow from Export to Payroll process out to Payroll System. Do not show payroll internals; that is another capstone project entirely.
Related UML tutorials
- Sequence Diagram for Attendance Management System (UML)
- Use Case Diagram for Employee Attendance Management System
- DFD for E-commerce Website (Levels 0, 1, 2)
- DFD for POS System (Complete 2026 Guide)
