Collaboration / Source date:

Employee Monitoring Software Backfires

Surveillance tooling damaged trust and output more than it recovered, pushing firms toward outcome measures.

Illustration of a home-based worker reviewing deliverables and an architectural sketch away from an idle laptop screen.

The surveillance software bought in a panic in March is now six months old, and the results are in. Screenshot intervals, keystroke counts, active-window timers, idle alerts, periodic webcam captures: the category has grown enormously this year, the vendors are reporting record demand, and a striking number of the companies that deployed it are now quietly trying to work out how to stop. The usual explanation is that employees hate it. They do, but that is not the interesting part. The interesting part is that it does not work, and it does not work for a reason that was predictable in advance: it measures the only things a computer can see, and none of them are the work.

What the software can actually observe

Strip away the dashboards and every tool in this category measures the same underlying signal — whether a human body is generating input at a keyboard and mouse. That signal has two problems. It is trivially defeatable, and the counter-measures cost almost nothing: a cheap mouse jiggler, a weighted key, a script. Within about a fortnight of deployment, the metric stops distinguishing diligent employees from lazy ones and starts distinguishing employees who have worked out the trick from employees who have not. The people who game it best are rarely the people you want to reward. And it is systematically wrong about knowledge work. The consultant reading a forty-page contract registers as idle. The engineer sketching an architecture on paper registers as absent. The account manager on a two-hour call from a mobile shows no activity at all. Meanwhile the employee who spends the day in the inbox, touching nothing important, produces a beautiful chart. A measurement that is easy to fake and wrong about the work generates a ranking that inverts reality. Managers then make decisions from that ranking, which is how monitoring software makes an organisation worse rather than merely unpleasant.

Three costs that show up within a quarter

The trust signal is received clearly. Installing keystroke logging tells the workforce that the organisation's default assumption is idleness. The employees who mind most are the ones with the strongest external options, which is a selection effect running in exactly the wrong direction. Six months of goodwill — people working evenings from kitchen tables through a genuinely frightening spring — can be spent in a single IT rollout email. Behaviour moves toward the metric. People start signalling activity: staying logged in, moving the mouse during calls, timing tasks to appear in the window, taking on visible work rather than valuable work. Hours lengthen while output does not, and because the tool reports hours, the organisation records this as a productivity improvement. It is the opposite. You have created a high-sensitivity data store nobody scoped. Screenshots capture customer records, medical information, banking details, colleagues' messages and the employee's own personal accounts. Keystroke logs capture passwords — including, routinely, credentials for systems the monitoring team has no right to access. Very few of these deployments went through a privacy assessment, defined a retention period, restricted who can view the archive, or considered what happens when that archive is subpoenaed, breached, or requested by the employee it describes. Security teams should be more worried about this than anyone: it is a deliberately constructed repository of everything sensitive that passes across every screen in the company.

What managers actually lost in March

The impulse behind the purchase was legitimate. Managers lost the ability to see whether work was progressing, and reached for a product that promised to restore it. The product restored the wrong thing — presence — because presence was never what they needed; it was simply the proxy they had been using for years without noticing. The substitutes are unglamorous and mostly free. Work defined as deliverables with dates, so that progress is observable without watching anybody. Work visible in a shared system — a board, a queue, a ticket list — where status is a property of the task rather than a question to a person. A short, regular one-to-one that is about obstacles rather than status. And an explicit expectation about responsiveness, so that unavailability is a defined event rather than an anxiety. That is a management system rather than a software purchase, which is precisely why it was not what anybody bought in March.

The line that keeps monitoring legitimate

None of this argues for measuring nothing. Some observation is required, some is contractually mandated, and some is a security necessity. The workable distinction is this: monitor systems and data, not bodies. Endpoint security telemetry, access logs, data-loss prevention on file movements, recorded lines where a regulator or a dispute process requires it, case and ticket throughput, quality sampling of completed work — all of these observe the work product or the system, they are explainable to the person affected, and they survive being described out loud in an all-hands meeting. Screenshots, keystroke capture, webcam checks and idle timers observe the human being, and they generally do not. Where you do monitor, four conditions keep it defensible: tell people exactly what is collected and why, collect the minimum that answers a specific question, delete it on a defined schedule, and never collect covertly. A monitoring programme that cannot be described in a paragraph to the people it covers is a programme waiting to become an incident.

Practical Guidance for Performance Model Review

  • Define output before you measure input. If you cannot say what good looks like for a role in one sentence, no telemetry will tell you who is performing.
  • Replace presence data with visible work. Deliverables with dates, status held in a shared system, and obstacles surfaced in a short weekly one-to-one.
  • Audit what your monitoring tool is storing right now. Screenshots and keystroke logs almost certainly contain customer data, credentials and third-party personal information.
  • Set retention and access limits immediately, or delete the archive. Indefinite retention with broad access is the worst configuration and usually the default.
  • Keep security telemetry, drop behavioural surveillance. Endpoint detection, access logs and data-movement monitoring are defensible; webcam capture is not.
  • Handle suspected fraud as an investigation, not a policy. Targeted, authorised, time-limited, and documented — not fleet-wide collection because of two bad cases.
  • If you are withdrawing a tool, say why in plain language. Announce the deletion, confirm it happened, and explain what replaces it. A silent uninstall wastes the credibility you could recover.
  • Train managers to manage output. The deficit exposed this year is supervisory skill, and software has never once fixed that.

The Regional Angle

Four considerations weigh unusually heavily here. Begin with the camera, because it is the most serious and the least discussed. Periodic webcam capture in a home is not a photograph of an employee; it is a photograph of a household. In this region a large share of the workforce lives in shared accommodation or in multi-generational family homes, and a tool that takes a picture every ten minutes will eventually capture family members — including women who have given no consent and would refuse it if asked — moving behind the screen. There is no configuration that makes this acceptable, and no business justification that survives being explained to the household. If your deployment includes camera capture, switch it off today and delete what has been collected. Second, be honest about what consent is worth when you hold the residency visa. Most monitoring rollouts rest on an acknowledgement signed by the employee, and in a sponsorship-based employment system that signature means considerably less than it appears to. An employee whose legal presence in the country, family's schooling and housing all depend on continued employment is not in a position to decline. Consent obtained under that asymmetry should not be the foundation of your programme. Build the justification on necessity and proportionality instead, write it down, and be prepared to defend it on those grounds rather than on a signature nobody could realistically have withheld. Third, watch the gap between your entities. Onshore labour law across the Gulf says relatively little about employee privacy, and legal teams reasonably conclude that monitoring is broadly permissible. But groups with DIFC or ADGM entities are now operating under data protection regimes with transparency and proportionality requirements — the new DIFC law having taken effect in July, with enforcement beginning shortly — and any entity serving European customers carries obligations of its own. One monitoring tool deployed across one shared tenancy inherits the strictest standard that applies to any employee in it, and nobody scopes deployments that way. The same applies in reverse to contracted delivery teams in India, Egypt or the Philippines, where client contracts may actually require session recording: uniform surveillance of a non-uniform workforce satisfies nobody and usually breaches something. Fourth, activity metrics encode a particular working day and penalise everyone who does not live inside it. Idle timers flag prayer breaks. Fasting employees on statutorily reduced hours during Ramadan appear less productive by construction. Staff on staggered transport, split shifts, or managing school runs under this autumn's partial reopening arrangements produce fragmented activity charts that describe their commute and their children rather than their competence. Any metric built from keyboard continuity discriminates quietly, and in a workforce this diverse it discriminates along lines that are uncomfortable to defend.

The objection worth taking seriously

The honest counter-argument is that the case against monitoring is usually written by and for autonomous professionals, and much of the working world is not that. Where a client pays for hours, where work arrives as a queue of transactions, where teams are hourly-paid, measuring volume and time is ordinary management rather than surveillance, and it long predates this year. Contact centres, claims processing, collections and shared service operations have measured handle time and throughput for decades without anybody calling it dystopian, and pretending otherwise is a class-bound argument. There is a second point with more force than managers like to admit publicly: dual employment, work quietly subcontracted to a friend, and ghost headcount are all real, and all became easier this year. The suspicion that prompted several of these purchases was not paranoid. Both concede to the same distinction. Transactional work can be measured by its output — units completed, quality sampled, service levels met — and every one of those measures is available without a screenshot. Fraud is addressed by a targeted, authorised investigation into a specific case, which is proportionate, defensible and far more likely to produce evidence that survives a tribunal than a folder of ten-minute screen captures. The failure in 2020 was not that organisations wanted assurance. It was that they bought a general-purpose surveillance capability to answer two specific questions, and kept it running long after the questions were answered.

Common Questions

Usually yes, within limits, and legality is the wrong bar. The questions that matter are whether it is proportionate to a defined purpose, whether people were told, and whether you could defend the collection to a regulator, a tribunal or a journalist.

We already rolled it out. How do we back out without admitting failure?

By admitting it, briefly. Say the tool answered a question the company had in March, the question has been answered, the data is being deleted, and here is what replaces it. This costs one uncomfortable paragraph and buys back a great deal.

What should we measure instead?

Output, quality, and whether commitments were met. For most roles that requires defining the commitments, which is the real work and the reason the software looked attractive.

What should we expect over the next twelve months?

Expect the monitoring category to keep growing into 2021, because the purchases are made under anxiety and anxiety is not in short supply. Expect the first serious disputes — tribunal claims, regulatory attention in the newer data protection jurisdictions, and at least one embarrassing leak of a screenshot archive. Expect the mainstream productivity suites to add softer "activity insight" reporting that raises the same questions with better design and less scrutiny. And expect the organisations that spent this year defining outcomes rather than watching keyboards to be visibly ahead on retention by the time hiring picks up again.


Performance Model Review — we replace presence metrics with defined outcomes, visible work and a supervisory rhythm managers can actually run.

Continue reading

Talk to OPS

Start with the operating problem.