Skip to content
What the Record Proves

Home / Measurement

Activity Monitoring and What It Sees

The five levels of activity monitoring, what each captures beyond its target, and the obligations that arrive with material nobody meant to collect.

Measurement · Reference

Five levels of activity monitoring, costed by one employer

ControlCostStopsDoes not stop
Application and window titleslowNothing by itselfCaptures document names, which are often confidential
Periodic screenshotsmoderateLittle; deters someCaptures everything on screen, including personal messages
Continuous screen recordinghighLittle more than screenshotsStorage, obligations and a great deal of personal content
Keystroke counts, not contentlowNothing by itselfDistinguishes nothing about what was typed
Keystroke contenthighNothing proportionateCaptures passwords; serious obligations attach

The two cheapest levels stop nothing on their own, and the two most expensive capture material the employer did not want and must now protect. What is permitted differs sharply by jurisdiction and is a question for somebody qualified in the place concerned.

Activity monitoring captures far more than it targets, and the surplus is the part that creates the problems. An agent configured to record application names captures the titles of documents, which include client names and case references. Screenshots capture whatever was on screen, including a personal message and a colleague's confidential email open in another window.

The measurement limits in “Activity Monitoring and What It Sees” provide useful context for employee monitoring software when researching employee monitoring software. Time and activity data can reveal a workflow question, while outcomes, employee explanation and a documented human review remain necessary to understand why a pattern appeared and whether any action is justified.

The intended data is usually modest. The incidental data is not, and the obligations attach to all of it.

When documenting the controls around “Activity Monitoring and What It Sees”, the CNIL workplace privacy resources is a useful independent reference. It can challenge assumptions about access, retention and accountability before a decision becomes routine.

What each level captures beyond its target

Application names: which tools are used, and document titles, which frequently carry confidential detail.

Window titles: the above plus browser page titles, which are a record of reading.

Screenshots: everything visible, periodically, including other people's information and anything personal.

Screen recording: the above continuously, at considerable volume.

Keystrokes: if content is captured, passwords, personal correspondence and anything typed into any system at all.

The third-party problem

Most of what a monitored employee has on screen is about somebody else: a customer's record, a colleague's message, a patient, a client.

Monitoring an employee therefore collects information about people who have no relationship with the employer at all, and that is the aspect most likely to be overlooked in a deployment and most consequential afterwards.

Proportionality as a practical test

Independent of what the law requires — which differs and is a question for somebody qualified in the place concerned — there is an operational version of the test that any manager can apply.

  • What specific problem is this addressing, stated as a fact rather than a worry?
  • What is the least intrusive measure that would address it?
  • What will be done with the data, by whom, on what schedule?
  • What is captured incidentally, and how is that protected?
  • When does this stop, or when is it reviewed?

The fifth question is the one that is never answered. Monitoring introduced for a specific concern outlives the concern and becomes permanent by default.

Targeted rather than general

Monitoring everybody because of a concern about one person is the decision most likely to be criticised, and it is the usual shape because tools are licensed per seat and deployed by default.

A targeted deployment, for a stated period, with a recorded reason, is a different proposition in every respect — including in what it costs to review, which is the practical reason general deployments produce nothing.

What the data does not establish

That the person was not working. An application monitor records which tool was in focus, and focus is not attention.

That is the same limitation as idle time, arriving with a larger dataset attached. More detailed monitoring produces a more detailed record of inputs; it does not close the gap between input and work.

Access and review

Whoever can see monitoring data is, in practice, the scope of the deployment. An agent that collects modestly and is readable by every supervisor is more intrusive than one that collects broadly into a restricted store reviewed on a trigger.

Set that out explicitly — who may access, under what circumstances, logged — before the first day. Retrofitting access control after people have been browsing is much harder than it sounds.

Telling people

Everything above, in plain terms, before it starts. The content of the notice is also a design document: anything that cannot be comfortably described to the people it concerns is worth reconsidering on that basis alone.

That test is not a legal one and it is a good one. It reliably catches the deployments that will cause trouble.

Retention and the surplus

Retention periods for monitoring data are usually set by storage capacity and are usually far longer than any purpose requires.

Short is the right answer: material needed for a specific matter is extracted and kept with that matter, and the rest ages out automatically. A system holding four years of screenshots is holding four years of other people's information too, and nobody decided that either.

Reviewing what it found

The honest annual question is the same as for any control: what did this produce in the last twelve months, and did anything follow from it?

Where the answer is nothing, the choice is between starting to review and stopping the collection. Continuing to collect without reviewing is the position with all of the obligation and none of the benefit, and it is the position most of these deployments are in.

The honest summary

Activity monitoring answers "what was on screen" very well, answers "was this person working" not at all, and collects a great deal about third parties on the way.

An employer that wants the first and accepts the third may have a case for it. An employer that wants the second is buying the wrong thing, and will have the obligations without the answer.