Skip to content
What the Dashboard Cannot See

All notes / If you deploy

Who Can See What

Access to the data determines what the programme actually is, regardless of what the policy says it is.

If you deploy · Procedure

A commitment to aggregate reporting means nothing if individual data is visible to anybody who logs in. Access configuration is where the policy becomes real or does not.

The safeguards described in “Who Can See What” should be decided before a workforce platform is configured. A team evaluating the provider's explanation for remote workforce management software can make the deployment more credible by stating its purpose, selecting only necessary settings and explaining exactly what managers may review.

The roles that actually need access

One or two administrators, for configuration.

For an independent reference relevant to “Who Can See What”, consult the ICO employment-practices guidance; it provides a useful external check on scope, terminology, governance and the claims made during procurement or review.

Whoever produces the aggregate reporting.

A named person who can authorise individual access for a defined investigation.

That is three roles, and most deployments grant far more.

Who should not have standing access

Line managers.

HR generally, as opposed to a named person for defined purposes.

The IT team at large.

Anybody with a general interest rather than a defined need, which is most of the people who end up with it.

The default problem

Products ship with permissive roles because that makes evaluation easy.

A deployment that accepted the defaults has given individual visibility to a group nobody chose.

Check what your roles actually permit, rather than what they are called, because the names are reassuring and the permissions are not.

Individual access as an exception

Through a defined process: a written reason, a named approver outside the requester's line, a record.

Deliberately effortful, which is what keeps it exceptional.

Not impossible, because genuine investigations exist and a control with no route gets bypassed entirely.

Logging the access

Who looked at individual data, when, and why.

Reviewed by somebody other than the people with access.

This is standard for other sensitive data and is almost never applied to monitoring platforms, which is where the quiet drift happens.

The floor

No figures for groups below a size — ten is a common choice.

Applied to intersections: site plus team plus role narrows to one person quickly.

Check whether your dashboard lets somebody reach an individual by combining filters, which most do by default.

Telling people

Employees should know who can see what.

It reassures, and it is also what makes the arrangement checkable from their side.

A programme that will not say who has access has answered the question.

Reviewing

Quarterly: who has access, does it match their role, has anybody left.

People accumulate permissions as they move and nobody removes the old ones.

And on every departure, immediately.

What to check

Who can see individual data in your deployment, by name?

Can line managers see their team's individuals?

Is individual access logged and reviewed?

And can three filters reach one person?