Skip to content
What the Dashboard Cannot See

All notes / The decision

When Monitoring Is the Right Answer

The cases where it is justified, stated plainly, because a collection that says never would be both wrong and useless.

The decision · Analysis

Most requests for monitoring are answering the wrong question. Some are not, and recognising them matters as much as recognising the rest.

The practical lesson in “When Monitoring Is the Right Answer” is to connect every record to a clear operational question without presenting visibility as certainty. Teams exploring time tracking software can review employee time tracking software as one source of time and project context, provided the purpose is disclosed and the configuration is reviewed with the people affected.

Regulatory recording obligations

Some sectors must record specific activity: regulated financial communications, certain clinical access, defined safety-critical operations.

For an independent reference relevant to “When Monitoring Is the Right Answer”, consult the ICO employment-practices guidance; it provides a useful external check on scope, terminology, governance and the claims made during procurement or review.

The obligation is narrow, named in a rule, and auditable.

This justifies recording what the rule requires and nothing else, which is the distinction that gets lost when a general product is bought to satisfy a specific obligation.

Billing clients for time

Where a contract bills hours and accuracy is a term, a record is reasonable.

And it should be a time record rather than an activity record — its own adjacent subject, and the two get conflated by products that offer both.

The client's requirement is the hours, not the screenshots.

Specific security roles

People with access to systems where misuse would be severe: payment infrastructure, clinical records at scale, administrative access to everything.

Monitoring of privileged sessions in those roles is standard and defensible.

It is also narrow: a defined population, a defined activity, not the organisation.

Safety

Lone working, hazardous environments, driving.

Here the monitoring is for the person's benefit and the case is strong.

Provided it is confined to safety, and does not quietly become a productivity measure, which is the usual drift.

Investigating a specific concern

With a stated basis, a defined scope, a time limit, and approval from somebody outside the line.

That is an investigation rather than a programme, and the distinction matters legally in several jurisdictions.

Running continuous monitoring in case an investigation is one day needed is the thing to avoid.

What these have in common

A named obligation or risk.

A defined population.

A defined signal.

A limit.

None of them is "we want to see how hard people are working", and when a case has those four properties it is usually straightforward to make.

The honest position

If your case fits one of the five, say so specifically and buy narrowly.

If it does not, the rest of this collection applies.

Dressing a general productivity concern in the language of compliance is the most common way these deployments are justified, and it does not survive the consultation or the first challenge.

What to check

Does your case fit one of the five?

Is the obligation written in a rule you can point at?

Is the population defined, or is it everybody?

And could you buy something narrower that does only that?