← Back to all articles Employee Monitoring

Staff Monitoring Programs: What They Do and What to Decide First

Planning board showing the six decisions behind a staff monitoring program

A staff monitoring program is the set of rules an employer writes about what work activity gets recorded, who may read it, and for how long, together with whatever software carries those rules out. The word program does double duty here, and the confusion is not accidental. Search for staff monitoring programs and you will get software listings. Ask an employment lawyer the same question and you will get a document with six sections and no product in it. Both are real, and the order matters: the organizational program has to be decided before the software question means anything.

We are an independent publication with a published editorial policy, we sell nothing in this category, and we take no referral money. So we will not tell you which tool to buy, quote prices we cannot verify, or claim to have tested anything. What we can do is set out the decisions that determine whether this works, most of which get skipped because a demo is more exciting than a retention schedule.

The pattern we see repeatedly is a team that buys first, switches on every default, and then writes a policy backwards from whatever the tool happened to collect. That sequence produces the worst of both outcomes: more data than anyone can defend, and less clarity than before.

Staff monitoring programs mean two different things

One meaning is a computer program, the other is an organizational program, and only the second one can fail quietly. Software either runs or it does not. An organizational program fails by drifting: collection widens because a new default arrived in an update, access spreads because someone senior asked for a login, and retention becomes indefinite because nobody set a deletion rule. None of that shows up as an error message.

Treating the two as one thing is how organizations end up unable to answer basic questions. Who approved screen capture. Which roles are in scope. What happens to the data when someone leaves. If those answers live only in a settings screen, then your policy is whatever the vendor's defaults were on the day it was installed, and it will change when they do.

The alternative is boring and effective. Write the program as a document, name a human owner, and configure the software to match the document rather than the reverse. Our walkthrough of how to write an employee monitoring policy covers what that document has to contain to be worth signing.

What the software side actually does

Staff monitoring software records activity on work devices and reports it to a place the employer can query. In practice that means an agent on the laptop sampling which application is in focus, which window title is showing, which domains the browser reached, and whether the keyboard and mouse produced events in a given interval. Broader configurations add periodic screen capture, file and removable media events, and gateway-level traffic records.

Everything on that list is a configuration choice, not a fixed property of the category. Two organizations running the identical product can end up with completely different exposure: one collecting three aggregate fields at team level, another collecting screenshots every few minutes tied to named individuals. The category name tells you nothing useful, which is precisely why the shopping question cannot come first. If you want the mechanics in detail, we wrote a full explainer on monitoring a computer at the operating system level.

One honest caveat about the reports. Activity data is a record of interaction with a machine, and interaction with a machine is a weak stand-in for value in most knowledge roles. It is genuinely good at some things: license waste, unapproved software, unusual data movement, and spotting a team whose hours have quietly crept past reasonable. It is bad at ranking people, and using it that way is the fastest route to a program nobody trusts.

The six decisions a staff monitoring program has to make

Six decisions carry almost all of the risk, and each one has a right place to be written down. Make them in order. Purpose constrains scope, scope constrains notice, and retention and access follow from what you decided to collect. The review date is last on the list and first to be forgotten, which is why programs outlive the reason they were started. Internet usage is the component most programs start with and the one New York names directly, so our guide to monitor employee internet usage is worth reading before you scope it.

Decision The question it answers What a bad version looks like Where it lives
Stated purpose What specific question are we trying to answer? Improve visibility, or increase accountability One sentence at the top of the policy
Scope Which roles, devices, and hours are covered? Everyone, everything, always A named list, reviewed when roles change
Notice What are people told, when, and how do they acknowledge it? A clause buried in an onboarding pack nobody opened Signed acknowledgment plus a posted notice
Retention How long is each field kept before automatic deletion? Indefinite, or deleted manually when someone remembers A schedule per data type, enforced by the system
Access control Which named roles can query the data, and is the query logged? All managers, unlogged, on request A short access list plus an audit trail of lookups
Review date When do we prove this changed a decision or switch it off? No date set, so the program renews by inertia A calendar entry with a named owner

Add a seventh if you can: a correction route. People should be able to see their own record and challenge something they believe is wrong, and someone should be obliged to answer. It costs very little and changes how the whole arrangement is received, because it converts a system done to people into one they have standing in. The same instinct drives our advice on rolling out time tracking, where the sequence of announcements matters more than the tooling.

Why we will not name a product

We are asked this often, so here is the reasoning. We have not run these tools in a production environment, feature lists and defaults change without notice, and any publication paid a commission on a signup has a financial reason to describe the category more warmly than it deserves. Naming products would mean pretending to a certainty we do not have. What we can offer instead is the sentence an affiliate-funded comparison page will never print: quite a lot of the teams reading this should decide not to buy anything this quarter, and should spend the budget on clearer expectations instead.

What smart staff monitoring should mean

Smart staff monitoring, in the marketing sense, usually means automated scoring, anomaly detection, or a model that rates activity. We would define it differently: a smart program is one that collects less, reports at the level where action is possible, and stops on a date. By that definition, three fields aggregated to team level with a six month expiry is smarter than forty fields tied to named individuals with a machine learning layer on top.

There is a public opinion reason to prefer the narrow version. The Pew Research Center published survey results in April 2023, from American Trends Panel Wave 119, finding that 61% of US adults oppose employers using AI to track workers' movements while they work, 56% oppose using it to track when office workers are at their desks, and 51% oppose using it to record what people do on their work computers. Pew also found 81% believe workers would feel inappropriately watched if employers used AI to collect and analyze information about how they do their jobs, 52% definitely and 29% probably.

Read the ordering rather than the headline. Every option carries majority or near-majority objection, and the automated layer is the specific thing being objected to. Adding scoring on top of collection does not make a program more sophisticated in the eyes of the people inside it. It makes the same collection harder to explain, and explaining it is the job. Our playbook for employee productivity monitoring goes through that conversation in detail.

Notice duties: what US law expects

In the United States, the binding legal constraint on most staff monitoring programs is notice, and the requirements vary by state. For a distributed team that means your obligations follow your employees rather than your headquarters, so the working assumption should be the strictest state you employ in until counsel tells you otherwise.

New York Civil Rights Law section 52-c is the clearest statute to reason from. Employers who monitor telephone conversations, email, or internet usage by an electronic device must give prior written notice upon hiring to all employees subject to monitoring. The notice must be in writing or electronic form and acknowledged by the employee, and it must also be posted conspicuously where affected employees can see it. Penalties run up to $500 for a first offense, $1,000 for a second, and $3,000 for a third and each subsequent offense, with an exemption for processes managing the type or volume of email, voicemail, or internet usage performed solely for computer system maintenance or protection. The text of the statute is short enough to read in full.

We describe New York because it is specific and checkable, not because it applies everywhere. Confirm your obligations with counsel in every state where you employ people. If you employ staff in the EU, GDPR imposes a separate set of requirements beyond anything here. And treat notice as the floor: a program that is legal and still resented has not succeeded at anything except avoiding a fine.

When a staff monitoring program is the wrong answer

A staff monitoring program cannot fix unclear expectations, and most requests for one are really requests for clearer expectations. If a manager cannot describe what good work looks like in their team, activity data will not supply it. It will produce a stream of numbers that get interpreted through whatever the manager already believed, which is worse than having no numbers, because it feels like evidence.

There is also a real cost to installing surveillance in an environment that is already strained. The American Psychological Association's 2024 Work in America survey, conducted by The Harris Poll among 2,027 employed US adults between March 25 and April 3, 2024 with a margin of error of plus or minus 3.1 percentage points, found 43% of workers report lower psychological safety at work, and that those workers were about ten times more likely to describe their workplace as toxic, 30% versus 3%. The same survey found 45% say they work more hours per week than they want to. These are correlational findings, not proof that monitoring causes either condition, but they describe the ground a new program lands on.

Our position, stated plainly: if your honest reason for wanting a staff monitoring program is that you are not sure people are working, do not buy one. Fix the reporting instead. Decide what each team owes, in output terms, by when, and to whom. That work is covered in our guide to how to measure employee productivity, and it is harder than installing an agent, which is exactly why the agent is tempting.

Running the program after launch

The launch is the easy part, and almost every failure we hear about happens in month four. Data keeps accumulating, the original question fades, and the reports become a ritual. A program that is not actively defended becomes a program that exists because it exists, at which point it is pure cost: storage, risk, and a permanent low-grade tax on trust.

  1. Publish the notice and confirm every person in scope has acknowledged it, before collection begins.
  2. Set retention as an automatic deletion rule per field, not a reminder in someone's calendar.
  3. Turn on query logging so lookups about named individuals are recorded and reviewable.
  4. Report at team level by default, and require a written reason to view an individual.
  5. At the review date, list the decisions the data actually changed. If the list is empty, switch it off.
  6. Re-run the notice whenever you add a field, because a quiet expansion is the thing people never forgive.

One group should ignore most of the skepticism here. If you operate under a recording obligation, handle regulated data with mandatory audit trails, or run a security incident response function, monitoring is not a discretionary choice and the argument is about scope and governance rather than whether to do it at all. Everyone else should assume the burden of proof sits with the program, every quarter, for as long as it runs.

If you are at the stage of comparing products rather than understanding the category, we keep a running breakdown of the best employee monitoring software.

Key takeaways

Frequently asked questions

What is a staff monitoring program?

The phrase covers two things. One is the software installed on work devices that records application use, active time, visited sites, and sometimes screens. The other is the organizational program that governs it: a written purpose, a defined scope, a notice given to employees, a retention limit, a list of who may look at the data, and a date when the whole arrangement gets reviewed. The second definition is the one that determines whether the first causes harm.

What should a staff monitoring program include besides the software?

Six things at minimum. A stated purpose written as a question you want answered. A scope naming which roles, devices, and hours are covered. A notice delivered before collection starts and acknowledged by each person. A retention period with automatic deletion. An access control list naming the individual roles that can query the data. And a review date at which the program is either renewed with evidence or switched off. Add a correction route so people can challenge a record they believe is wrong.

Should we choose the tool or write the policy first?

Policy first, without exception. A tool bought before the purpose is written will expand to fill whatever it can collect, because every default is set by a company whose interest is in demonstrating capability. Writing the purpose first turns the shopping question into something answerable: which of these products can be configured down to exactly what we said we would collect, and prove it.

What does smart staff monitoring mean?

In marketing it usually means automated scoring or anomaly detection applied to activity data. In practice the useful version of smart is narrow collection, aggregate reporting, and an automatic stop date. A program that collects three fields, reports at team level, and expires in six months unless renewed is smarter than one that collects forty fields and runs forever, regardless of what algorithms sit on top.

Do we have to tell staff they are being monitored?

In several states you are legally required to, and everywhere else you should anyway. New York Civil Rights Law section 52-c requires prior written notice upon hiring to all employees subject to monitoring of telephone conversations, email, or internet usage by electronic device, acknowledged by the employee and posted conspicuously. Penalties reach 500 dollars for a first offense, 1,000 for a second, and 3,000 for a third and each one after. Notice duties vary by state, so confirm yours with counsel.

How long should monitoring data be kept?

For the shortest period that still answers your stated purpose, set as an automatic deletion rule rather than a manual cleanup. Long retention converts a management tool into a discovery liability, because anything you hold can be requested in litigation and has to be produced. If the purpose is spotting a workload pattern this quarter, you do not need last year, and keeping it only creates risk with no matching benefit.

Who should be allowed to see staff monitoring data?

Name roles, not departments, and keep the list short enough to read aloud. Broad access is where trust breaks, because a curious manager looking up a specific person on a slow afternoon does more damage than the collection itself ever did. Log every query so the watching is watched, and tell employees that log exists. If nobody wants their queries recorded, that is useful information about what they intended to do.

How do we know if the program is working?

Ask what decision changed. A staff monitoring program earns renewal if you can point to specific actions taken because of the data, such as a workload rebalanced, a broken process fixed, or a security gap closed. If the honest answer after a quarter is that the reports get generated and skimmed, the program is producing cost and risk with no return, and the correct response is to shut it off rather than add more fields.

When is a staff monitoring program the wrong answer?

When the real problem is unclear expectations, weak reporting, or a manager who cannot describe what good work looks like. Monitoring cannot supply any of those, and installing it signals distrust to people who have not earned it. The American Psychological Association 2024 Work in America survey, conducted by The Harris Poll among 2,027 employed US adults, found workers reporting lower psychological safety were about ten times more likely to describe their workplace as toxic, 30 percent versus 3 percent. Adding surveillance to a low trust environment moves in the wrong direction.

← Back to all articles