Skip to content
Between the Events

Index  ·  Task mining

Task Mining Is Employee Monitoring

Desktop capture of identified individuals, continuously. The obligations that attach, and what to settle before deployment rather than after.

Analysis

Task mining records what named people do on their computers. Whatever it is called internally, that is workplace surveillance, and treating it otherwise creates legal exposure and destroys the cooperation the data depends on.

General orientation. Requirements differ substantially by jurisdiction and change; take advice for yours.

What is actually collected

Application and window titles, which frequently contain customer names, case references and document titles.

Keystroke and mouse activity, as counts and in some products as content.

Screenshots or continuous screen capture, frequently with text recognition applied, which converts images into searchable text.

Clipboard contents, in some implementations.

Idle periods, which record when someone was not at the machine.

All attributed to a named person, because it originates on their workstation.

What that inevitably captures

Personal use, however clear the policy is.

Third-party personal data: customer records visible on screen, colleagues' names in window titles.

Special category data, where the person's work involves health, union or similar records.

Private communications, where a personal message window was open.

This incidental capture is not a misuse; it is unavoidable, which is why scoping and exclusions have to be technical rather than policy.

The obligations that commonly apply

Notice, before deployment, stating what is captured and why. A clause in an induction pack is not sufficient.

Proportionality, with less intrusive alternatives considered and the consideration recorded.

Purpose limitation, so data collected to characterise a task is not used to assess a person.

Impact assessment, required in several jurisdictions before systematic monitoring.

Consultation with employees or their representatives, which is a legal requirement in a number of places.

Retention limits, where excess retention is itself a failure.

Access rights, so the person can see what was recorded about them.

Restrictions on automated decisions with significant effects.

What to settle before anything is installed

Scope: which people, which applications, which hours.

Granularity: individual, role or aggregate.

Exclusions, enforced in the agent configuration rather than in the reporting layer.

Duration, with an end date. A study has one; a monitoring deployment does not.

Retention of raw captures, which should be short.

What it will not be used for, written down and enforced.

Who can see raw captures, which should be very few people.

The framing that survives scrutiny

A time-boxed study, with volunteers, to characterise a specific task, whose raw data is discarded once the task model is built.

Not: continuous capture across a workforce, retained indefinitely, with individual dashboards.

The first is defensible and useful. The second is surveillance with an analytics interface, and it will be resisted, gamed and eventually restricted.

The end date as the control

The single provision that distinguishes a study from surveillance.

A stated date on which capture stops.

A stated date on which raw captures are deleted.

Both agreed before deployment and confirmed in writing when they pass.

No extension without a new question and a new assessment.

An agent left installed but dormant still carries the trust cost, so uninstall it rather than disabling it.

Without an end date the deployment becomes permanent by default, which is the failure mode in every case.

The impact assessment

Required before systematic monitoring in several jurisdictions and useful regardless.

What is captured, specifically: applications, window titles, keystrokes, screen content, clipboard.

Why, with the operational question it answers.

Who is affected and how many.

What less intrusive alternatives were considered and why they were rejected. System-log analysis is almost always one of them.

What safeguards apply: scope, exclusions, retention, access, aggregation.

Retained as evidence that the proportionality question was asked rather than assumed, because it cannot be reconstructed later.