Choosing: teams

When somebody above you has already decided

The decision is closed and almost everything that determines how badly it goes is still open.

For a separate operational view of time, ownership and team activity, see Monitask.

The decision was taken somewhere else. A board, a client, an insurer, a parent company, or an executive who read something. You have been told to install monitoring, and the question of whether to is closed.

This situation is common enough to deserve its own guide, and the useful observation is that almost everything that determines how badly it goes is still open.

Find the actual requirement

Mandates arrive compressed. "Install monitoring" is a summary of something more specific, and the specific version is usually narrower: an insurer wants evidence of access control, a client contract requires records of hours on their project, an executive is worried about one team, a regulator asked about data leaving.

Ask what would satisfy the requirement, and ask it of the person who holds it rather than of the person who relayed it. The answer frequently turns a company-wide deployment into a scoped one, and nobody upstairs objects, because the scope was never the point.

Six decisions that remain yours

What is captured, from the ladder in the article on endpoint capture. On which devices, and specifically whether personal ones are included. During which hours. How long the raw material is kept. Who can see material identifying an individual. And under what condition it stops.

None of these were decided by the mandate. All of them determine whether the deployment is proportionate, defensible and survivable, and the article on notice and consent explains why the assessment behind them is required rather than optional in several jurisdictions.

Write the purpose down, even if nobody asked

A sentence naming what this is for is the single most useful artefact here, and it does three jobs. It is required by most regimes. It bounds what the tool may later be used for, which the article on retention shows is the main risk. And it gives you something to point at when a different purpose arrives, which it will.

install monitoringdecided elsewhere, and not by youwhat is capturedon which devicesduring which hourskept for how longvisible to whomand when it stopssix decisions remain, and nobody upstairs has an opinion about any of them
Figure 1The mandate settles one question and leaves six open. Nobody upstairs has an opinion about any of the six, and all six decide whether the result is defensible.

The requirement usually has an expiry, and nobody writes it down

Mandates arrive attached to a moment: an incident, an audit, a contract, a nervous quarter. The moment passes and the deployment does not, because switching it off is a decision somebody would have to make and nothing prompts it.

Asking, at the outset, what would have to be true for this to stop is an unusual question and a cheap one. Sometimes there is a clean answer: the contract ends, the audit closes, the incident is resolved. Recording that answer in the same document as the purpose converts a permanent arrangement into a reviewable one, and the article on what cannot be measured explains why nothing else will ever raise the question.

01

Meet it with what already exists

  • Best forRequirements about access, devices or data movement
  • PricingFree; you are already paying for the systems that hold this
  • StandoutIdentity logs, device management and existing security tooling often satisfy the actual requirement
  • Watch out forRequires somebody to reconstruct what those systems already record, which is real work
02

Scope to the specific team or project

  • Best forClient contracts, a single worried executive, one regulated function
  • PricingPer-seat, and the seats are few
  • StandoutSmallest deployment that satisfies the requirement, and the easiest to explain to the people in it
  • Watch out forBeing singled out is its own signal, and it needs saying out loud rather than discovered
03

Time and project recording without activity capture

  • Best forAnything about hours, billing or allocation
  • PricingThe lowest tier in this market, often with a usable free plan
  • StandoutAnswers the hours question completely with none of the capture the ladder describes
  • Watch out forWill not satisfy a requirement that was actually about data leaving
04

A full workforce platform

  • Best forRequirements genuinely about insider risk, with a programme to run it
  • PricingThe most expensive tier, and priced annually
  • StandoutThe only class that answers the security question the mandate may really be about
  • Watch out forEverything in the workforce section applies, and it is the hardest deployment to reverse

Tell people before they find out

You did not choose this and will nevertheless be the person who announces it. The article on covert monitoring sets out what discovery costs, and the version where staff learn from a colleague is the worst available.

Saying plainly what was required, by whom, what was scoped out, and what will not be looked at is a better position than any wording that implies enthusiasm. It is also true, which makes it easier to maintain.

Record what you scoped out, and why

Scope creep in these deployments happens quietly: a feature enabled during a support call, a retention window extended to fix an export. Writing down what was deliberately not turned on, with the reason, is what makes the next change a decision rather than a drift.

What we cannot verify

Whether a specific arrangement satisfies a specific mandate is a question for whoever holds the requirement and, where legal, for counsel; nothing here is advice. Product capabilities and tiers differ and are described by their vendors. We name nothing and rank nothing.

The short version

  1. The decision is closed and almost everything that determines the outcome is open.
  2. Ask what would satisfy the requirement, of the person who holds it.
  3. Six decisions remain yours, and nobody upstairs has an opinion about them.
  4. Write down the purpose; it bounds what the tool may later be used for.
  5. Existing identity and device systems often satisfy the real requirement already.
  6. Announce it yourself, and record what you deliberately did not turn on.

Further context

Start from the class of problem, not the list of tools

Every selection here names the situation first and the criteria second. Product names come last, and each one carries the line describing what it costs you.