Skip to content
Between the Events

Index  ·  Foundations

What Task Mining Is, and How It Differs

Capturing activity on individual desktops to see the steps no system logs. A different technique, a different data source, and much heavier obligations.

Explainer

Process mining reads what systems recorded. Task mining records what people do on their computers. The two are frequently sold together and are not the same activity.

What it captures

Application and window focus: which program, which screen, for how long.

Keyboard and mouse activity, at varying levels of detail depending on configuration.

Screen content, in some implementations, as text extracted by recognition or as images.

Copy and paste operations, which reveal data being moved between systems by hand.

Idle and active periods.

All of it attributed to a named individual, by construction, because it is captured on their machine.

What it is for

Seeing the steps between system events. A process log shows an order approved at ten and shipped at two; task mining shows the four applications, the spreadsheet and the two emails in between.

Finding manual workarounds that no system records.

Quantifying repetitive keyboard work, which is the automation candidate identification most task mining is bought for.

Understanding why a step takes as long as it does, where the system log only shows that it did.

The gap it fills

Process mining is blind between events. Where a process runs partly outside instrumented systems — in spreadsheets, email, desktop tools — the log has a hole.

That hole is frequently where the work actually is, particularly in back-office processes.

Task mining is the only way to see into it, which is a genuine capability and the reason it exists.

The obligation difference

This is the point that matters most and it is stated properly in its own section.

Process mining reads system records that were already being created for operational reasons, and can be aggregated with no individual attribution.

Task mining creates new records of a named person's activity at their computer, continuously, including keystrokes in many configurations.

That is workplace surveillance, with notice, proportionality, purpose limitation, consultation and retention obligations in most jurisdictions.

It cannot be aggregated away at source in the same manner, because the capture is per-person by design.

When it is worth deploying

When the process demonstrably runs outside instrumented systems and the gap has been measured rather than assumed.

For a bounded study period, on a volunteer sample, rather than as continuous estimate-wide monitoring.

With the scope, exclusions and retention agreed before deployment.

Not as a first move, and not because a vendor bundled it. Establish what the system logs cannot answer, then decide whether the answer justifies the capture.

Measuring the gap first

The check that determines whether task mining is justified at all, and it costs nothing.

Take your process log and compute the time between consecutive events, per case.

Sum the intervals where nothing was recorded anywhere.

Express it as a proportion of total case duration.

A small proportion means the process runs inside instrumented systems, and desktop capture will add little.

A large proportion means the work is happening somewhere you cannot see, which is the legitimate case for looking.

Do this before proposing deployment, because it converts an assumption into a number and frequently ends the discussion.