Skip to content
Recorded

All notes  /  Foundations

Recording Hours and Monitoring Activity

One is frequently a legal duty that protects the worker. The other is workplace surveillance. The same product does both, and the default often includes the second.

Analysis

This is the boundary the whole subject rests on, and it is drawn at a specific point rather than along a spectrum.

Recording

What: start time, end time, breaks, total duration, and which matter or project the time belongs to.

Why: to pay people correctly, to bill correctly, to cost work, and — in much of Europe — because the law requires it.

Whose interest: primarily the worker's. A record of hours is what allows someone to demonstrate unpaid overtime, a missed rest period, or a pattern of excessive hours.

Obligations: the record must generally be objective, reliable and accessible to the worker, and retained.

Monitoring

What: which applications, which websites, keystroke counts, screenshots, idle detection, movement, screen content.

Why: to observe what someone did during the hours they were working.

Whose interest: the employer's.

Obligations: notice, proportionality, purpose limitation, impact assessment, consultation — the full apparatus that attaches to workplace surveillance.

Why they get conflated

The same products do both. Almost every commercial time tracking tool offers activity monitoring as a feature, frequently enabled by default.

The vocabulary blurs it. "Automatic time tracking" can mean inferring duration from activity, which requires capturing the activity.

The compliance argument is borrowed. An organisation adopting monitoring sometimes cites the legal duty to record working time as the justification. The duty is to record hours; it is not a mandate to observe what happens inside them.

And once deployed, the monitoring data is there, and someone eventually asks to use it.

The test

Does the system need to know what the person was doing, or only how long?

If only how long: it is recording. Start, stop, break, project. Nothing else.

If what they were doing: it is monitoring, whatever it is called, and the analysis in the boundary section applies.

Apply this to each feature, not to the product. Most deployments need the first and acquire the second by accident.

What this means practically

Turn off activity capture unless it has been separately justified. Screenshots, application logs, keystroke counts, idle timers — each is a decision, not a setting.

Check the default. In several widely used products the monitoring features are on when the account is created.

Say which you are doing, in the notice, in terms the workforce can check.

Do not cite the working time duty as a basis for monitoring, which is both inaccurate and the kind of thing that unravels badly.

The consequence of getting it wrong

Recording is generally accepted by workforces, because it is visibly in their interest and because it is a legal requirement people understand.

Monitoring bolted onto it is not, and the reaction tends to attach to the whole system — including the part that was protective.

Which means conflating them costs you the recording too: people under-report, pad, or fill the timesheet at the end of the week from memory, and the record stops being reliable exactly when the law requires it to be.

Checking the defaults

The single most useful hour at the start of a deployment.

Open the product's settings and list every capture feature, enabled and available.

Mark each as duration or activity.

Check what is on when an account is created, which in several widely used products includes screenshots or application logging.

Turn the activity features off at account level, not per user, and record that you did.

Re-check after every vendor upgrade, because new capabilities arrive enabled and a migration is where monitoring most often appears unnoticed.

What to say in the notice

Four sentences that answer what people actually want to know.

What is recorded: start, end, breaks, and which project.

What is not: no screen capture, no application logging, no activity scoring, no location beyond the clock-in check.

What it is used for, named: pay, the statutory record, client billing, project costing.

What it is not used for: individual performance assessment.

Specific and checkable beats a policy paragraph, and where the honest version is uncomfortable to write, the design is the thing to change.

Connect policy to configuration

The practical choices behind this note can be compared with employee screen monitoring software. Keep the organisation's written purpose in control of the setup, enable only the data needed for that purpose and review the result with affected users.