Work TimeTimekeeping · Monitoring · Evidence

Monitoring & Privacy

Productivity Surveillance: What It Measures and What It Costs

Section
Monitoring & Privacy
Written
2026-08-06
Last checked
2026-08-06
Law and programme rules in this area change. This article states the position at the time of writing and is revised when it moves. It is general information, not legal advice.

The category of tools variously called productivity monitoring, employee analytics, or — by the people subject to them — bossware, all rest on one assumption: that observable activity is a usable proxy for work performed.

For a product-oriented view of measurement tools, see Monitask on workforce analytics software.

For privacy-risk considerations, see the FTC privacy and security guidance.

For some jobs that is close to true. For most knowledge work it is not, and the gap between what these tools measure and what managers think they measure is where the damage happens.

This article is about the practical and organisational consequences. For the legal position, see employee monitoring: what is lawful.

What the tools actually capture

Activity level. Keyboard and mouse events per interval, usually rendered as a percentage.

Application and website usage. What was open, and for how long.

Screenshots. Periodic or triggered captures of the screen.

Idle time. Intervals below an activity threshold.

Keystroke logging. In some products, the actual keys pressed.

Webcam capture. Periodic photographs of the person at the desk.

Location. For field and mobile roles.

Communication metadata, and in some products the content.

The measurement problem

Take the headline metric. Activity level counts input events. It does not distinguish:

  • Reading a specification from staring at a wall
  • Thinking about an architecture from doing nothing
  • A difficult problem solved in twenty minutes from an easy one padded to two hours
  • Writing valuable code from writing a lot of code
  • A meeting where someone contributed decisively from one where they typed notes

Every one of those distinctions is the actual difference between productive and unproductive work, and the metric is blind to all of them.

The consequence is not merely that the number is uninformative. It is that the number is gameable, and people game it. Mouse jigglers exist as a commercial product category. Once a metric is used for evaluation, employees optimise for the metric, and the metric stops measuring even what it originally did.

This is Goodhart's law operating in an unusually clean form: activity monitoring converts a weak proxy into a target, at which point it ceases to be a proxy at all.

The costs that do not appear on the invoice

Trust, which is expensive to rebuild. Surveillance communicates a belief about the workforce, and people hear it accurately. A manager who installs monitoring has told their team what they think of them, whatever the stated rationale.

Turnover among the people you least want to lose. Strong performers have options and are the least tolerant of being watched. The correlation runs the wrong way: surveillance is most tolerated by people with the fewest alternatives.

Presenteeism replacing performance. When activity is measured, people produce activity. Staying logged in, moving the mouse, keeping the tab open. The organisation gets exactly what it measures.

Risk aversion. Deep work looks like idleness. Thinking looks like idleness. Reading documentation looks like idleness. Rational employees under activity monitoring shift toward visible, shallow, continuous work.

Manager time. Someone has to look at the dashboards. In practice most organisations install the tool, look at it for a fortnight, and then never look again — having paid the trust cost in full for a benefit nobody collected.

Legal exposure. Notice requirements, biometric statutes, audio consent, and — where monitoring data is later used in a termination — an evidentiary record you did not design. See when monitoring data is used in a termination.

When monitoring is reasonable

This is not an argument that no monitoring is ever justified. Several cases are straightforward:

Regulatory requirement. Financial services communication supervision, healthcare access logging, and similar obligations are not optional.

Security. Data loss prevention, access control, and anomaly detection are about protecting systems, not about measuring people. Keep them separate — including in how they are described.

Safety. Vehicle telematics, lone-worker monitoring, hours-of-service compliance.

Billing accuracy. Time recorded against a client matter, where the record is the invoice.

Specific investigation. Narrow, documented, time-limited, with legal advice.

What these have in common: a defined purpose, proportionate collection, and a use that is not "assessing whether this person is working hard enough."

Better ways to answer the actual question

The question behind most surveillance purchases is "is the work getting done?" There are cheaper and more accurate ways to answer it.

Define output. For most roles this is possible and has simply never been done. What should exist at the end of the week that did not exist at the start?

Shorten the feedback loop. Weekly one-to-ones surface problems faster than any dashboard, and they surface causes rather than symptoms.

Look at delivery, not activity. Did the thing ship, at what quality, when it was expected.

Ask. Employees generally know who is struggling and why. They will not tell a dashboard.

If a manager cannot tell whether someone is doing their job without watching their screen, the problem is that the job has never been defined — and no tool fixes that. See measuring knowledge work without measuring keystrokes.

If you are going to do it anyway

Say exactly what is collected. Covert monitoring that surfaces — and it surfaces — is worse than the monitoring itself.

Collect the minimum for the stated purpose. Screenshots and keystroke logging are the highest-intrusion, lowest-value options in almost every case. Being able to justify them individually is a reasonable test.

Do not use it for individual performance evaluation. Aggregate and anonymised is a different proposition from a per-person activity score in a review.

Set retention and stick to it. Data kept indefinitely is data you will eventually have to explain.

Limit access. Who can see it, and under what circumstances.

Give employees access to their own data. In several jurisdictions this is a right; everywhere it is a check on accuracy.

Review whether anyone is using it. If nobody has opened the dashboard in three months, you are paying the trust cost for nothing. Turn it off.

The question to ask before buying

What decision will we make differently because of this data?

If the answer is specific — we will identify accounts at risk, we will meet a regulatory obligation, we will bill accurately — the purchase may be justified.

If the answer is a general sense of visibility, the tool will not deliver it, and the cost is not the licence fee.