People · 3.6
What staff are told about monitoring
What staff are told about monitoring. What it costs, who decides, and what usually goes wrong.
If the organisation uses employee monitoring software, the notice should explain the purpose, data categories, access, retention and review process before collection starts.
For an independent reference point, see CISA insider-threat mitigation resources.
The situation
You are deploying something that watches file activity
People will find out. They will find out from a colleague, from a notification, or from a rumour, and partial information about monitoring is considerably worse than complete information.
This site's position on covert monitoring is stated on the platform page: we do not supply it. What follows is about doing the visible kind properly.
What to tell them
Five things, in writing, before deployment
What is collected. Specifically. File access, copy and transfer events, and the account that performed them, rather than a vague reference to activity.
What is not. Usually more reassuring than the first list. Not keystrokes, not screenshots, not personal messages, not webcams, not anything outside working systems.
Why. The contractual requirement, named, and what happens to the business without it.
Who sees it. By name or by role, and under what circumstances. Most staff assume the answer is everybody.
How long it is kept and what it will not be used for. Performance management is the fear, and if it will not be used for that, say so and mean it.
The rumour problem
Silence is filled
In the absence of an explanation, people construct one, and the constructed version is invariably broader and more intrusive than the reality. Correcting it afterwards costs far more than explaining it first, because the first account is the one that sticks.
Where the law requires it
Transparency is frequently an obligation
Requirements to inform staff about monitoring vary considerably between jurisdictions and can be strict, including obligations to consult employee representatives before deployment in some countries.
Where you operate in more than one, the strictest applies to that part of your workforce. This is a question for employment counsel in each jurisdiction rather than for a vendor, and nothing here is legal advice.
Doing it well
Say it in person first
A written notice alone reads as a legal formality and invites the worst interpretation. A short meeting, with the written notice handed out afterwards and questions answered honestly including the awkward ones, produces a different result for the same content.
The awkward question is always whether this will be used against somebody, and the honest answer is what the policy says it can be used for.
What changes behaviour
Announced monitoring works better than the other kind
The deterrent value of a control that people know about is substantially higher than one they do not, and the trust cost is substantially lower. Concealment buys a small increase in detection at the price of the relationship that makes everything else work.
Which is the practical argument, alongside the legal one, for the position this company takes.
Afterwards
Report back once
Six months in, tell people what the system has actually done: how many alerts, how many were nothing, what changed as a result. It closes the loop, it corrects the assumption that everyone is being watched constantly, and it costs one paragraph.
The written notice
One page, in plain language
Legal review is sensible and a notice written entirely by lawyers reads as a warning. Have it drafted plainly, reviewed for accuracy, and issued in the plain version.
Access to the records
Tell people what they may see about themselves
In several jurisdictions individuals have rights of access to data held about them, and monitoring records are data about them. Knowing that the records can be seen changes how the system is perceived and it is an obligation regardless.
Establish the process before the first request rather than during it.
Also
Elsewhere in people
- What compliance actually costs, itemisedWhat compliance actually costs, itemised. What it costs, who decides, and what usually goes wrong.
- Reading a proposal that quotes a certificateReading a proposal that quotes a certificate. What it costs, who decides, and what usually goes wrong.
- What to build and what to buyWhat to build and what to buy. What it costs, who decides, and what usually goes wrong.
- Making the budget case to somebody who resents itMaking the budget case to somebody who resents it. What it costs, who decides, and what usually goes wrong.
- The costs that arrive after the purchase orderThe costs that arrive after the purchase order. What it costs, who decides, and what usually goes wrong.
- Doing this with almost no moneyDoing this with almost no money. What it costs, who decides, and what usually goes wrong.
- Who owns compliance, and why it cannot be nobodyWho owns compliance, and why it cannot be nobody. What it costs, who decides, and what usually goes wrong.
- Running it as a project rather than as a documentRunning it as a project rather than as a document. What it costs, who decides, and what usually goes wrong.
- Reporting to a board that wants one numberReporting to a board that wants one number. What it costs, who decides, and what usually goes wrong.
- When the date slips, which it willWhen the date slips, which it will. What it costs, who decides, and what usually goes wrong.
- Staying compliant after the assessmentStaying compliant after the assessment. What it costs, who decides, and what usually goes wrong.
- Working to two standards at onceWorking to two standards at once. What it costs, who decides, and what usually goes wrong.
- Training that changes what people doTraining that changes what people do. What it costs, who decides, and what usually goes wrong.
- How a control looks from the machineHow a control looks from the machine. What it costs, who decides, and what usually goes wrong.
- Contractors, temps and the visiting engineerContractors, temps and the visiting engineer. What it costs, who decides, and what usually goes wrong.
- Hiring for a role most suppliers have never filledHiring for a role most suppliers have never filled. What it costs, who decides, and what usually goes wrong.
- Giving people a way to say a control is unworkableGiving people a way to say a control is unworkable. What it costs, who decides, and what usually goes wrong.
- What counts as an incidentWhat counts as an incident. What it costs, who decides, and what usually goes wrong.
- Reporting obligations and their clocksReporting obligations and their clocks. What it costs, who decides, and what usually goes wrong.
- Being able to answer afterwardsBeing able to answer afterwards. What it costs, who decides, and what usually goes wrong.
- The first hour, and who decidesThe first hour, and who decides. What it costs, who decides, and what usually goes wrong.
- Telling a customer something happenedTelling a customer something happened. What it costs, who decides, and what usually goes wrong.
- What changes afterwards, and what shouldWhat changes afterwards, and what should. What it costs, who decides, and what usually goes wrong.
- The other frameworks you have also metThe other frameworks you have also met. What it costs, who decides, and what usually goes wrong.
- Export control, named and not advised onExport control, named and not advised on. What it costs, who decides, and what usually goes wrong.
- Your own suppliers, and what to ask themYour own suppliers, and what to ask them. What it costs, who decides, and what usually goes wrong.
- Suppliers outside the United StatesSuppliers outside the United States. What it costs, who decides, and what usually goes wrong.
- Where the data physically sitsWhere the data physically sits. What it costs, who decides, and what usually goes wrong.
- What is changing, and how to tellWhat is changing, and how to tell. What it costs, who decides, and what usually goes wrong.