People · 3.6

What staff are told about monitoring

What staff are told about monitoring. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see CISA insider-threat mitigation resources.

The situation

You are deploying something that watches file activity

People will find out. They will find out from a colleague, from a notification, or from a rumour, and partial information about monitoring is considerably worse than complete information.

This site's position on covert monitoring is stated on the platform page: we do not supply it. What follows is about doing the visible kind properly.

What to tell them

Five things, in writing, before deployment

What is collected. Specifically. File access, copy and transfer events, and the account that performed them, rather than a vague reference to activity.

What is not. Usually more reassuring than the first list. Not keystrokes, not screenshots, not personal messages, not webcams, not anything outside working systems.

Why. The contractual requirement, named, and what happens to the business without it.

Who sees it. By name or by role, and under what circumstances. Most staff assume the answer is everybody.

How long it is kept and what it will not be used for. Performance management is the fear, and if it will not be used for that, say so and mean it.

The rumour problem

Silence is filled

In the absence of an explanation, people construct one, and the constructed version is invariably broader and more intrusive than the reality. Correcting it afterwards costs far more than explaining it first, because the first account is the one that sticks.

Where the law requires it

Transparency is frequently an obligation

Requirements to inform staff about monitoring vary considerably between jurisdictions and can be strict, including obligations to consult employee representatives before deployment in some countries.

Where you operate in more than one, the strictest applies to that part of your workforce. This is a question for employment counsel in each jurisdiction rather than for a vendor, and nothing here is legal advice.

Doing it well

Say it in person first

A written notice alone reads as a legal formality and invites the worst interpretation. A short meeting, with the written notice handed out afterwards and questions answered honestly including the awkward ones, produces a different result for the same content.

The awkward question is always whether this will be used against somebody, and the honest answer is what the policy says it can be used for.

What changes behaviour

Announced monitoring works better than the other kind

The deterrent value of a control that people know about is substantially higher than one they do not, and the trust cost is substantially lower. Concealment buys a small increase in detection at the price of the relationship that makes everything else work.

Which is the practical argument, alongside the legal one, for the position this company takes.

Afterwards

Report back once

Six months in, tell people what the system has actually done: how many alerts, how many were nothing, what changed as a result. It closes the loop, it corrects the assumption that everyone is being watched constantly, and it costs one paragraph.

The written notice

One page, in plain language

Legal review is sensible and a notice written entirely by lawyers reads as a warning. Have it drafted plainly, reviewed for accuracy, and issued in the plain version.

Access to the records

Tell people what they may see about themselves

In several jurisdictions individuals have rights of access to data held about them, and monitoring records are data about them. Knowing that the records can be seen changes how the system is perceived and it is an obligation regardless.

Establish the process before the first request rather than during it.

Also

Elsewhere in people