Blog

Employee monitoring without keylogging: what should companies actually track?

Start from the question you need answered, not from the feature list. Most companies discover they need considerably less than they were about to buy.

The usual way a company buys monitoring software is backwards. Somebody becomes concerned about output, looks at a category of products, sees a feature list, and buys the one with the most features on it. Six weeks later they have screenshots nobody looks at, an activity score nobody trusts and a team that has quietly stopped volunteering information.

The better approach takes ten minutes and starts with a question.

Start with the question, not the product

What you are actually asking, and the least invasive thing that answers it
The questionWhat answers itWhat you do not need
Is this person working the hours we pay for?Attendance with shifts and a late policyScreenshots, activity scores, app tracking
Where did the month go on this client?Time attributed to projectsScreenshots
Is this retainer profitable?Hours per project against contracted hoursAnything about individuals
Is the team overloaded?Tracked hours against available hoursScreenshots, keystroke counts
Did the contracted work actually happen?Time entries plus daily work reportsUsually nothing more
A client contract requires evidence of activityScreenshots at a long interval, or blurredKeystroke content, ever

Notice what is in the right-hand column. In five of the six most common questions, screenshots add nothing to the answer — they add storage, sensitivity and a conversation with your team that you did not need to have.

Why keystroke logging never makes the list

Recording keystroke counts as an activity measure is reasonable and common. Recording keystroke content is a different thing entirely, and it fails on every dimension that matters.

  • It answers no management question. Nothing in the table above becomes answerable by knowing which characters were typed.
  • It captures what you do not want. Personal messages, passwords typed into non-work sites, medical information, a resignation letter drafted in a text editor. You now hold all of it and are responsible for it.
  • It fails purpose limitation. Under a data-protection framework you must collect for a specific purpose and no further. Keystroke content is the textbook example of collecting further.
  • It is unsurvivable when discovered. And it will be discovered, because someone always checks.

This is why there is no keylogger in Employee Desk. Not as a setting, not for enterprise customers, not on request. Key presses and clicks are counted as an activity measure and the characters are never captured. See the privacy page.

The four levels, and picking the lowest that works

Level 1

Attendance only

Who worked, which days, how long. No agent installed anywhere. Answers more questions than most people expect, and costs nothing in trust.

Level 2

Attendance plus reported work

Daily work reports written against projects. Still no agent. You now know what people worked on, from them.

Level 3

Measured time

Active and idle time from a desktop agent, attributed to projects. Now the hours are measured rather than reported. Screenshots off.

Level 4

Measured time plus screenshots

Only where a client contract or an audit genuinely requires visual evidence. Long interval, short retention, employee-visible.

Most companies that arrive asking for level 4 need level 2 or 3. It is worth spending an hour deciding which, because the difference in how the rollout lands is enormous.

If you do enable screenshots

  • Tell people first, in writing. A monitoring policy they have actually read, not a clause in a handbook nobody opened.
  • Use a long, randomised interval. Ten minutes tells you as much as two and costs a fifth of the storage and a fraction of the resentment.
  • Set retention short. Seven or fourteen days covers almost every purpose. Indefinite retention converts a small monitoring programme into a large data-protection liability.
  • Let people see their own. This one change does more for adoption than every other decision combined.
  • Consider blurring. If you need evidence of activity rather than of content, blurred captures give you the shape of the work without the substance.
  • Restrict and log access. Role-based, with an audit trail of which manager opened whose gallery.

The rollout conversation

The single most useful thing you can do is publish what is recorded and what is never recorded, and hand it to the team before installing anything. Not a summary — the actual list. If your vendor will not give you that list in a form you can circulate, that is worth noticing before you buy.

Then explain the purpose in one sentence, honestly. "We need defensible hours for client billing" is a reason people accept. "We want to see what everyone is doing" is not, and dressing it up does not help.

Related

Frequently asked questions

Is keystroke logging illegal?

It is not automatically illegal on company-owned devices, but it is very hard to justify under purpose limitation, it captures data you almost certainly do not want to hold, and it destroys trust when discovered. The practical answer is that no legitimate management question requires it.

What is the minimum useful monitoring?

Attendance. Knowing who was working, on which days, for how long answers most of what companies actually ask, and needs no agent on any machine.

Should employees be told before monitoring starts?

Yes, always, and in writing. Beyond the legal position, covert monitoring produces worse data because people who suspect they are watched but cannot see what is recorded optimise for looking busy.

Try it on your own team this week

Start on the cloud in ten minutes, or tell us your headcount and where the server has to live and we will price the self-hosted licence on the call.

  • 7-day trial
  • No credit card
  • Cancel anytime