Feature lists in this market are written in categories: activity tracking, application monitoring, productivity analytics. The categories are vague in a direction that flatters the product, and the only way to know what a tool does is to establish what leaves the machine.
The ladder, and where it crosses a line
At the shallow end sit session facts: when somebody signed in, when input stopped for long enough to be called idle. These are labels about work rather than the work itself.
Next comes which application had focus, which is still roughly a label. Then window titles, and this is where most buyers stop paying attention and should not.
A window title is not a category. It is a document name, an email subject line, the title of a web page, the name of a customer record. A tool that captures window titles is capturing the content of the work in summary form, and it is usually described as "application usage" in the brochure.
Beyond that: full addresses rather than domains, periodic screenshots, continuous screen recording, every keystroke, file and removable-media activity, clipboard contents, and inspection of messages. Each rung records more of what was actually being done, and each is a different proposition legally and culturally.
Three sets, not one
What is captured on the device, what is transmitted and stored, and what is displayed to a manager are three different sets, and vendors frequently answer a question about one with a fact about another.
Blurring a screenshot at the point of display is not the same as never capturing the pixels. Aggregating activity in a dashboard is not the same as discarding the underlying detail. The question worth asking is what exists in the store, because that is what can be exported, subpoenaed, breached, or looked at by somebody with more access next year.
Things captured that nobody intended
An agent cannot reliably distinguish work from personal use on a device that does both, and most devices do both. A screenshot taken on a fixed interval catches whatever was on screen: a personal banking tab, a message from a partner, a medical appointment, a colleague's private message in a shared window.
Keystroke capture has a sharper version of the same problem, because credentials typed into a field the agent does not recognise are keystrokes like any other. A store containing them is a security liability in addition to a privacy one.
And the third parties. The person on the other end of a conversation never agreed to anything, is frequently not an employee, and in the European framing their data is being processed too.
Special categories arrive by accident
Data revealing health, religion, trade union membership, political opinions and sexual orientation carries heightened protection under European-style regimes. Nobody sets out to collect it in a monitoring tool, and screenshots collect it routinely: a calendar entry for a hospital appointment, a union mailing list, a page open in a browser.
Incidental collection is still collection. This is one of the reasons systematic screen capture is treated more seriously by regulators than its vendors' materials suggest, and it belongs in the assessment described in the next article.
The settings that decide the answer
Four defaults change the character of a deployment more than the choice of product does. Whether capture runs outside working hours. Whether it runs on personally owned devices. Whether the subject can see their own data. And how long the raw material is kept before only aggregates remain.
All four are configuration, all four are usually left at the vendor's default during a hurried rollout, and the vendor's default is set to demonstrate capability.
How to find out, rather than asking
Vendor documentation describes intent. The reliable method is to deploy on a test machine with an account containing nothing personal, use it normally for a day, and then look at what the system holds: the retained records, the export, and where possible the traffic leaving the device.
Ask for the data dictionary in writing, and ask specifically whether window titles, full addresses, clipboard and keystrokes are captured, with the answer stated per feature rather than per plan. A supplier who will not put that in writing has answered the question.
What this publication will not describe
This article explains what these tools record, which is information a buyer needs and an employee is entitled to. It does not describe how to deploy monitoring so that people do not know it is there, how to avoid a notification duty, or how to configure capture to be difficult to detect. That is a fixed limit here rather than a matter of tone.
What we cannot verify
Capabilities differ per product and per version, and every list in this field, including the vendors' own, goes stale. We have tested nothing and name no product. Legal characterisation of any particular capture is jurisdictional and fact-specific and belongs with a lawyer. The only account of a specific tool worth relying on is the one produced by running it and looking.
The short version
- The category names in feature lists are vague in the product's favour.
- A window title is a document name, a subject line and a page, not a label.
- Captured, stored and displayed are three different sets, and vendors conflate them.
- An agent cannot separate work from personal on a device that does both.
- Special category data arrives incidentally through screenshots and is still collected.
- Deploy it on a test machine and look at what the store holds.