← Back to all articles Employee Monitoring

User Activity Monitoring: What It Captures and Who It Is For

Security operations view of user activity monitoring records tied to accounts rather than people

User activity monitoring is the recording of what identified users do on corporate systems, so that a particular session can be reconstructed afterward. It is a security discipline before it is anything else. User activity monitoring software was built for insider risk, audit, and incident investigation, and the fact that it also produces charts a manager can read is a side effect rather than a design goal. Most of the confusion in this category comes from mistaking the side effect for the product.

We are an independent publication with a published editorial policy. We sell nothing here, we take no referral money, and we have not tested any product, so this page names no vendors, quotes no prices, and makes no feature claims. What it does instead is separate two use cases that are routinely sold as one, because buying the wrong one is the most common and most expensive mistake in workplace monitoring.

The short version: security monitoring collects deeply and looks rarely. Productivity tracking collects shallowly and looks constantly. Run either one with the other's habits and you get a worse result on both counts.

What user activity monitoring is, and where it came from

The category grew out of a specific problem: an organization needed to prove, after the fact, exactly what a named account did on a sensitive system. Auditors ask that question. Regulators ask it. So does anyone investigating whether a departing employee took a customer list. The answer requires records tied to identity, kept long enough to be useful, and detailed enough to stand up when someone disputes them. What that looks like from the other side is in our guide to detecting employee monitoring.

That origin shapes everything about the design. The unit of analysis is a session attached to an account, not a person's working day. Detail is preferred over readability, because the record has to survive scrutiny. Access is meant to be narrow, since the data would be damaging in the wrong hands. And review is meant to be exceptional, triggered by an alert or an investigation rather than performed every Monday out of habit.

None of those properties suit day-to-day management, and that is not a flaw. It is the tool doing its job. Problems begin when a productivity question gets pointed at it, which happens because both categories describe themselves with the same three words. If you want the underlying mechanics of how any of these agents work, we cover monitoring a computer at the operating system level in a separate explainer.

What user activity monitoring software captures

A security-grade deployment captures identity-linked events across systems, not just a laptop. The usual set includes sign-in and privilege escalation events, application and process launches, file operations such as copies, prints, and writes to removable media, uploads and outbound attachments, command execution on servers, and in high assurance environments a replayable session record. Some configurations add content classification so that the sensitivity of a moved file is known, not guessed.

Productivity-oriented deployments capture a narrower and blunter set: which application was in the foreground, whether input events occurred, which domains the browser reached, and sometimes periodic screenshots. That data is shallower than an investigator would want and more exposed than a manager needs, because a window title or a full URL carries far more personal detail than the settings screen suggests.

The distinction that matters is between records built as evidence and records built as reporting. Evidence needs integrity, timestamps, and chain of custody. Reporting needs readability and aggregation. A dataset optimized for one is a liability in the other role, and our page on what employee monitoring should never collect covers the fields we would keep out of both.

Security and productivity pull in opposite directions

On every design axis that matters, the two use cases want opposite settings. That is why a single deployment serving both purposes ends up serving neither well. The table below sets out the conflict directly.

Design choice Insider risk and audit use Productivity management use What happens if you merge them
Depth of collection Deep, evidence grade, identity linked Shallow, aggregate, team level Deep data in shallow hands, held far longer than needed
Frequency of review Rare, triggered by an alert or investigation Constant, weekly or daily reporting Evidence-grade records browsed casually every week
Who reads it A small named investigations or compliance function Line managers across the organization Access spreads until the access list is meaningless
Retention Long, set by audit obligation Short, because last quarter is irrelevant Long retention applied to everything, raising discovery risk
What success looks like Nothing found, and the record holds up when it is A decision changed, a workload rebalanced Neither is measured, so the program renews by inertia
Effect of people knowing Detection weakens if targets adapt Transparency is required and helps The tool is either too quiet to be fair or too loud to detect

Look at the last row for a moment, because it is the deepest conflict. A productivity program has to be fully disclosed to be legitimate. An insider risk program loses part of its value when the specific detection logic is public. Both positions are defensible on their own. Held together in one system, they force an organization into either unfair opacity or ineffective detection, and there is no configuration that escapes the choice.

What the insider risk numbers actually measure

The clearest picture of what this discipline is built for comes from its own research, and reading it carefully explains why the tool behaves the way it does. The 2026 Cost of Insider Risks report from the Ponemon Institute, sponsored by DTEX, a company that sells software in exactly this category, analyzed 7,490 incidents across 354 organizations.

Its central finding is about speed. Organizations took an average of 67 days to contain an insider incident in 2025, down from 81 days the year before, and only 13% of incidents were contained inside 30 days. Cost tracks that timeline closely. Incidents contained in under 30 days averaged $14.2 million, while those running past 90 days averaged $21.9 million.

Notice what is being optimized there. Every one of those figures is about detecting a specific event and shortening the window before someone acts on it. That is a different problem from working out whether a team spent its week well, and it produces a different tool: one built for alerts, retention, and evidence rather than for patterns and conversations. That confusion runs across the whole category, and our guide to remote computer monitoring software disentangles the four product types buyers routinely mix up.

The incident mix explains the rest of the design. That same vendor-sponsored report counted an average of 13.8 negligent insider incidents per organization at $747,107 each, 6.3 malicious insider incidents at $742,125, and 5.3 credential theft incidents at $842,462. Negligence, not malice, is the most common category by a wide margin, which is why these systems watch for mistakes at least as closely as for intent.

How to read a vendor-sponsored study

The same report states that user behavior analytics saves organizations an average of $5.1 million, and that privileged access management saves $6.1 million. Both figures describe the value of the sponsor's own product category, in research the sponsor paid for. That does not make them false, and it does not make the containment timeline above unusable. It does mean the savings claims carry a commercial interest that the containment data does not, and they deserve to be weighed differently. Ask who funded a security study before you put its return on investment figure into a business case.

What goes wrong when a security tool manages people

Two failures arrive together. The security function loses the data it needed, because once people learn the same records feed performance conversations, they adjust their behavior around the collection, which is precisely the behavior an insider risk program exists to notice. And the management function inherits a stream of numbers never designed to describe work quality, then treats them as if they were. Goodhart's Law does the rest: the moment a measure becomes a target, it stops measuring what it used to.

The measurement problem is not fixable by collecting harder. Microsoft's Work Trend Index, published June 17, 2025 and combining anonymized Microsoft 365 telemetry with a survey of 31,000 knowledge workers across 31 markets fielded February 6 to March 24, 2025, found knowledge workers are interrupted roughly every two minutes during work hours, about 275 times a day, with 48% of employees and 52% of leaders describing their work as chaotic and fragmented. An activity record drawn across that pattern is largely a picture of interruption.

There is a human cost on top of the analytical one. The American Psychological Association's 2024 Work in America survey, conducted by The Harris Poll among 2,027 employed US adults between March 25 and April 3, 2024 with a margin of error of plus or minus 3.1 percentage points, found 43% of workers report feeling tense or stressed out during the workday, rising to 61% among workers reporting lower psychological safety. Those are correlational findings rather than proof of cause, and they describe the environment a repurposed security tool lands in.

Our position is that the two programs should be separated by design: different datasets, different owners, different retention, different access lists, and different documents. Which is another way of saying the decision is organizational before it is technical, and we set out that argument in full in our piece on what a staff monitoring program has to decide first.

The purchase we would talk you out of

The pattern we see most often runs like this. A manager cannot tell what a team is doing. A security-grade tool is available on the corporate agreement, so it gets switched on for visibility. Nobody writes down the question, nobody sets a retention period, and eighteen months later the organization is holding detailed identity-linked records of every employee's working day, with no incident to justify them and a discovery obligation attached to all of it. We cannot tell you which product to avoid, because we have not tested any of them. We can tell you that this sequence is the one that ends badly, and that it starts with skipping the written question.

Where pc activity monitoring software fits

The phrase pc activity monitoring software usually points at the lighter end of the category: an agent on a desktop or laptop recording applications, active and idle time, and websites, with reporting built for managers rather than investigators. It is shallower and cheaper than a full insider risk deployment, which makes it a smaller data-holding risk and a weaker source of evidence at the same time.

That combination has an honest use. If your question is about license waste, unapproved software, or whether a team's hours have quietly crept past reasonable, an endpoint agent reporting at team level will answer it, and the collection can be narrow enough to explain in a sentence. Those are legitimate operational questions and we would not argue against asking them.

What it cannot do is rank people. Activity counts do not distinguish thinking from idling, reading from ignoring, or a hard problem from a slow morning. If the underlying need is a fair read on output, the work is defining what output means for each role, which is the subject of our guide to how to measure employee productivity when the work is not visible from a desk.

How to evaluate user activity monitoring software

Evaluate user activity monitoring software on its triggers and its refusals, not on its capability list. A deep deployment that is only opened under a documented trigger, by two named roles, with every lookup logged, is safer than a light one that anyone browses on a slow Monday. Capability tells you what could happen. Governance tells you what will.

  1. What event causes a human to look at this data, written down before purchase?
  2. Which named roles can query a named individual, and is every query itself logged?
  3. Which collection categories can be permanently disabled, and can employees verify that state?
  4. What is the retention period per field, and is deletion automatic rather than manual?
  5. How does an employee see their own record and challenge something they believe is wrong?
  6. Is this dataset separate from anything used in performance management, in writing?
  7. What is the export and destruction path if the contract ends?
  8. On the review date, what decision or detection will we point to as justification?

Public opinion should inform where you set those dials. The Pew Research Center published survey work in April 2023, from American Trends Panel Wave 119, finding 51% of US adults oppose employers using AI to record what people do on their work computers, and a wide age gap underneath that average: 64% of adults aged 18 to 29 opposed it, against 38% of adults 65 and over. If your workforce skews young, the headline number understates the resistance you should plan for.

Plan against the population you actually employ rather than the national average, and check the base of any figure someone puts in front of you before it shapes a decision. We keep a wider set of verified employee monitoring statistics with their samples and fielding dates attached, precisely so numbers like these can be argued with.

Notice and access: what US law expects

A security purpose does not remove an employer's notice duty, and that surprises people. In the United States, monitoring company systems is broadly permitted, but several states impose notice requirements that apply regardless of why you are collecting. Because those duties follow the employee's location, a distributed team can create obligations in a dozen states at once.

New York Civil Rights Law section 52-c is the clearest to reason from. Employers who monitor telephone conversations, email, or internet usage by an electronic device must give prior written notice upon hiring to all employees subject to monitoring. The notice must be in writing or electronic form and acknowledged by the employee, and it must be posted conspicuously where affected employees can see it. Penalties run up to $500 for a first offense, $1,000 for a second, and $3,000 for a third and each subsequent offense. There is an exemption for processes managing the type or volume of email, voicemail, or internet usage performed solely for computer system maintenance or protection, which is narrower than a general security justification. Read the statute rather than a summary of it, including this one.

We describe New York because it is specific and checkable, not because it is universal. Monitoring law varies by state and you should confirm your obligations with counsel wherever you employ people. If you employ staff in the EU, GDPR imposes a separate set of requirements beyond anything here. Whatever the jurisdiction, the document that carries the weight is a written employee monitoring policy that names the purpose, the fields, the access list, and the retention period, and that people have actually signed.

If you are at the stage of comparing products rather than understanding the category, we keep a running breakdown of the ten monitoring products side by side.

Key takeaways

Frequently asked questions

What is user activity monitoring?

User activity monitoring is the recording of what identified users do on corporate systems, so that a specific session can be reconstructed later. It grew out of security and insider risk work, where the purpose is to investigate an incident, satisfy an audit, or detect a pattern that looks like data being taken. The unit of analysis is a session tied to an account, not a person's working day, and that difference explains most of what follows.

What does user activity monitoring software capture?

Typically sign-in and privilege events, application and process launches, file operations including copies, prints and writes to removable media, uploads and email attachments, command execution on servers, and in high assurance configurations a replayable record of the session. Productivity-oriented setups tend to collect a narrower and blunter set: application names, active and idle status, and visited domains. The two lists overlap but they are built to answer different questions.

How is user activity monitoring different from productivity tracking?

Direction and audience. Security monitoring collects deeply, looks rarely, and is read by a small investigations function under a defined trigger. Productivity tracking collects shallowly, looks constantly, and is read by line managers with no trigger at all. A tool tuned for one is badly suited to the other, and running a deep security dataset as a daily management report is the combination most likely to cause harm.

Who is user activity monitoring actually for?

Security teams, compliance functions, and organizations with audit obligations, particularly around privileged accounts, third party contractors, and systems holding regulated data. If your organization has none of those conditions and the person asking for the tool is a line manager rather than a security lead, the request is probably a management problem in a security costume, and buying the tool will not resolve it.

Is pc activity monitoring software the same thing?

It usually means the lighter endpoint version: an agent on a desktop or laptop recording applications, active time, and websites, with reporting aimed at managers rather than investigators. It is cheaper and shallower than a full insider risk deployment, which makes it less dangerous as a data holding and less useful as evidence. Judge it on what it lets you refuse to collect rather than on the length of its capability list.

Does user activity monitoring improve productivity?

We have no verified evidence that it does. What is documented is that the signal it produces is a poor proxy for work. Microsoft reported in June 2025, from telemetry combined with a survey of 31,000 knowledge workers across 31 markets, that knowledge workers are interrupted roughly every two minutes during work hours, about 275 times a day. An activity record drawn across that mostly measures fragmentation, and the quietest hour on the chart may be the only valuable one.

Do employees have to be told about user activity monitoring?

In several states, yes, and there is no security exception for ordinary notice duties. New York Civil Rights Law section 52-c requires employers who monitor telephone conversations, email, or internet usage by electronic device to give prior written notice upon hiring to all employees subject to monitoring, acknowledged by the employee and posted conspicuously, with penalties up to 500 dollars for a first offense, 1,000 for a second, and 3,000 for a third and each one after. There is a narrow exemption for processes performed solely for computer system maintenance or protection. Confirm your position with counsel.

What is session recording and when is it justified?

Session recording captures a replayable record of what happened on a screen or a terminal, which makes it genuinely useful for reconstructing an incident and genuinely invasive as a standing practice. We would restrict it to privileged accounts, jump hosts, and third party access, with a documented trigger for review, a short retention period, and a log of who watched what. Applying it to a whole workforce as a management tool is the clearest example of the wrong use of the right technology.

What happens if you use a security tool to manage performance?

Two failures at once. The security function loses the dataset it needed, because once people know the same records feed performance reviews they change their behavior around the collection, which is exactly the behavior an insider risk program is trying to detect. And the management function inherits a stream of numbers that were never designed to describe work quality, then treats them as if they were. Both outcomes are predictable and both are avoidable by separating the two programs.

How should you evaluate user activity monitoring software?

Start with the trigger, not the capability list. Ask what event causes someone to look at the data, who that someone is by role, whether their lookup is itself logged, how long each field is retained before automatic deletion, and how an employee sees and challenges their own record. Then ask which categories can be permanently disabled. A deployment that collects deeply but is only opened under a documented trigger is safer than one that collects lightly and is browsed every Monday morning.

← Back to all articles