Skip to content
What the Dashboard Cannot See

All notes / People

Covert Monitoring and Why It Ends Badly

Software that can run without the employee knowing. When that is ever defensible, and what happens when it is discovered.

People · Analysis

General orientation, not legal advice; the position differs substantially by jurisdiction and some uses are unlawful.

The safeguards described in “Covert Monitoring and Why It Ends Badly” should be decided before a workforce platform is configured. A team evaluating the Monitask website for stealth computer monitoring software can make the deployment more credible by stating its purpose, selecting only necessary settings and explaining exactly what managers may review.

Most products can run without a visible indicator. The capability is sold as a feature and using it routinely is close to indefensible.

For an independent reference relevant to “Covert Monitoring and Why It Ends Badly”, consult the ICO employment-practices guidance; it provides a useful external check on scope, terminology, governance and the claims made during procurement or review.

Why it is offered

Investigation of suspected serious misconduct, where notice would defeat the purpose.

That is the stated justification and it is narrow, legitimate and rare.

The feature is then available for everything else, which is how routine covert deployment happens without anybody deciding on it.

The legal position

In several jurisdictions covert monitoring of employees requires specific justification: a serious suspicion, proportionality, no less intrusive alternative, and frequently prior authorisation.

Covert monitoring of a general workforce is unlawful in many places and difficult to defend everywhere.

Take advice before, not after, because the question arrives attached to a tribunal.

When it is discovered

It is discovered. People notice agents, compare notes, find processes, or receive their own data in an access request.

And the response is not proportionate to the capability — it is proportionate to the concealment.

An organisation that monitored openly and heavily is in a different position from one that monitored lightly and secretly.

What it does to everybody else

Once covert monitoring is known to have happened, every subsequent assurance is discounted.

"We only collect aggregate data" is not believed by people who know the organisation previously said nothing at all.

Which means one covert episode costs the credibility of every future programme, including the proportionate ones.

The access request problem

A person can usually ask what you hold about them.

Covertly collected data is still their data and still has to be produced.

Which means the concealment has an expiry date set by somebody else, and the discovery happens on their timing rather than yours.

If a genuine investigation requires it

A written basis, naming the suspicion.

Approval from somebody outside the line manager.

A defined scope and a defined end date.

Legal advice first.

And a record of the decision, because the justification will be examined.

The configuration decision

If your product has a covert mode and you will not use it, disable it at the platform rather than relying on policy.

A capability that exists will eventually be requested by somebody senior during a difficult moment.

Removing it is a stronger position than policing it, and it is also something you can state to employees.

What to check

Can your deployment run without an indicator?

Can that mode be disabled, and has it been?

Has it ever been used, and on what basis?

And what would you tell employees if asked directly?