Skip to content
Aldridge Dagos Get in touch

N°028 · 2026.07.28 · 19 MIN

Employee Monitoring Is Standard. Making It Hold Up Is the Work.

By Aldridge Dagos, operations software engineer


A set of brass calibration weights in a fitted case, one lifted out and standing in the light, the reference an employee monitoring number has to be checked against.
None of these measures anything. They exist so a measurement can be checked, which is the only thing that makes a number worth trusting.

A client emails on a Tuesday and asks you to show that their account was covered on the fourteenth. You open the tracker. It says 91 percent activity, seven hours and forty minutes, four idle gaps. That is a number, and it is the wrong artifact. It does not say who was scheduled, who approved that schedule, which account the hours belonged to, what got produced, or who reviewed it.

Now look at the same gap from the other side of the desk. The person who worked that day has exactly the same problem. They covered the account, they hit their hours, they spent two of them on a client call where nobody touched a keyboard, and the only thing standing between them and a doubt they cannot answer is a percentage that does not describe what they did. Employee monitoring gave both parties telemetry when what the moment required was a record.

I built the operations hub that a 50-person services company runs its floor on, across a dozen roles and eighteen client accounts, and the design rule that shaped all of it is this. Watching the work is the easy half. Producing evidence that survives someone questioning it is the half that pays, and it has to answer for the worker as readily as it answers for the client.

The short version: Monitoring is not the controversial part. It is the expected baseline in delegated work, and for regulated accounts it is mandatory. HIPAA marks audit controls at 45 CFR 164.312(b) and information system activity review at 45 CFR 164.308(a)(1)(ii)(D) as Required rather than Addressable, which means recording activity and regularly reviewing it are both obligations. The failure mode is different from what people expect. It is monitoring that produces a percentage instead of a defensible record, so the moment a client, an auditor, or a payroll dispute asks a hard question, the number cannot answer it, and neither can the person it is about. A real record cuts both ways: it proves coverage to the client and it makes every worked hour, approved absence, and completed task provable for the person who earned it. Get there by making every finding deterministic, freezing the evidence to it, refusing to conclude anything from stale data, and requiring a named human for any adverse call.

Why employee monitoring is already the baseline

Four reasons, and none of them is about distrust.

Clients contract for coverage, not effort. When a company delegates work to an outside team, the deliverable includes proof that the work happened on the account it was billed to. That proof has to exist independently of anyone’s word, because the client is not in the room.

Regulated accounts require it outright. If a team touches protected health information, oversight stops being a management preference. More on the exact rules below.

It is what makes pay defensible. Hours that nothing recorded are hours somebody has to take on faith, and faith does not survive a busy month or a change of manager. A measured shift stays payable long after the person who approved it has moved on.

It is already normal, and everyone in the industry knows it. The American Psychological Association’s 2024 Work in America survey found 44 percent of workers say their employer uses technology to monitor them, down from 51 percent in 2023 and 53 percent in 2022. In delegated and remote-service work the share is far higher, and it is disclosed in the contract on day one. Nobody is surprised by it.

The law treats it as normal too, and mostly asks that you say so plainly. New York Civil Rights Law section 52-c, in force since May 7, 2022, requires every private employer in the state to give prior written notice on hiring to any employee subject to electronic monitoring, have the employee acknowledge it, and post the notice in a conspicuous place. The Attorney General enforces it with escalating civil penalties. That is a disclosure regime, not a prohibition. The statute assumes you monitor and tells you to be open about it.

What regulated accounts actually require

This is where the argument ends. If your team handles protected health information, recording and reviewing system activity is not a policy choice you get to make.

HIPAA’s Security Rule splits its specifications into Required and Addressable. Addressable means you assess whether it is reasonable and document what you did instead. Required means required. Two of the ones that matter most here are Required.

Rule What it says Status
45 CFR 164.312(b), Audit controls Put mechanisms in place that record and examine activity in systems holding electronic protected health information Required
45 CFR 164.308(a)(1)(ii)(D), Information system activity review Regularly review records of system activity, such as audit logs, access reports, and security incident tracking Required
45 CFR 164.312(a)(2)(iii), Automatic logoff End a session after a period of inactivity Addressable
45 CFR 164.312(a)(2)(i), Unique user identification Give every user a unique name or number for tracking Required

Read the first two together and the obligation is a pair. One says record the activity. The other says somebody has to actually look at the records on a schedule, rather than pulling logs for the first time after something goes wrong. Unique user identification is what makes both of them mean anything, because activity you cannot attribute to one person is not an audit trail.

The same logic runs through finance work, where separation of duties and a reviewer trail are the entire control. On those accounts, the team that cannot produce the record is the team that loses the account.

The gap between a number and a record

Here is the failure I design against, and it is the industry default rather than anyone’s mistake. Most setups treat the tracker’s output as the answer. It is one input, and on its own it is weak in a specific way.

What a tracker gives you What a defensible record needs
Activity percentage for a day The approved schedule that day was measured against, with its version and timezone
Total hours observed Which client account and engagement those hours belong to
Idle gaps Whether an approved break, leave, or schedule exception covers each one
A session start time Whether the feed producing it was fresh at the moment of the finding
A dashboard state now An immutable snapshot of the state at the time the decision was made
A flag A named human who made the call, when, and on what reason

An activity percentage answers one question: how much input did this device see. Nobody bills that and nobody audits that, and the vendors say as much in their own documentation. Treating it as a conclusion is how a company ends up in an argument it cannot win with its own data.

The fix is not less monitoring. It is turning each observation into a record with everything attached that a reader would need to check it themselves.

What happens when the tracker records nothing

Take the worst version. A full pay period goes by and the designated tracker has no hours on any day. Not a low number. Nothing.

The lazy answer is to pay the recorded figure, because the recorded figure is defensible in the narrow sense that a system produced it. That answer is wrong, and it is wrong on the company’s side of the table before it is wrong on anyone else’s. A tracker records what a tracker saw. It does not record what happened. A machine that was off, an agent that never started, a regional outage, a second device, a client call taken on a phone, all produce the same zero, and none of them mean nobody worked.

So the burden goes the other way. When the tracker is silent, the company goes and looks. Calendar entries, call logs, delivered files, sent correspondence, meeting records, anything carrying a timestamp. Every part of the period where the work can be seen gets reconstructed and paid. Where nothing shows anywhere, nothing is credited, and that gap opens a conversation rather than a conclusion.

That is not leniency. It is the only reading of the deal that survives being questioned. A contract that prorates on hours actually worked, and gives the company a right to verify them, gives it a duty to look before it deducts. Verification is not a formality that gets waived in someone’s favour or applied against them. It is the term, and running it properly means running it in both directions.

Zero on a tracker is a question. It is never an answer.

A number that never changes was never measured

Self-reported time is not worthless. It is the fallback the whole system leans on when a tracker fails. It only works if it can be checked, and there is one tell that says it cannot.

The tell is a figure that never varies. Every entry reads the same round total, day after day, while the start and end times written on that same entry disagree with it. Nothing else in a real week behaves that way. Real shifts run long, get cut short, absorb a call that overran, lose twenty minutes to a reboot. A log reporting an identical total through all of that is not recording the day, it is repeating a habit. Add a description copied word for word across entries, or an entry written after the shift it describes had already finished, and it has stopped being evidence. It was not measured. It was assumed.

The same test tells you what a good one looks like, and this part is worth knowing if you are the person filing it:

  • Let it be uneven. Odd totals are credible. A run of identical ones is not.
  • Make it agree with itself. The total has to reconcile with the start and end times on the same entry, because that internal check is the first thing anyone reads.
  • Say what you actually did. A repeated block of text carries no information. One line naming the account and the work carries all of it.
  • File it inside the shift, not from memory later. A record written on the day is a record. One written afterwards is a recollection, and it gets weighed as one.

A record you can contradict is a record. A number that cannot be wrong cannot be right either.

Who does a defensible record actually protect?

Both sides, and the worker more than people assume.

When the only artifact is a percentage, every ambiguous day lands on the person to explain. They spent the morning on a client call, the number dipped, and now they are answering a question with nothing to point at. Doubt flows downhill to whoever has the least evidence, and in delegated work that is always the person doing the work.

A real record reverses that. Eight things change for the person being measured:

  • Work outside the schedule stops disappearing. Observed intervals outside the shift are preserved as their own record and reconciled through an approval path with hours and a reason attached. If you worked it, it exists, and it exists in a form that pays.
  • Approved leave and exceptions attach themselves. Once approved, the day is covered at evaluation time. Nobody relitigates a Tuesday in March because the approval lives on the shift instead of in a chat thread somebody deleted.
  • A late start stays a late start. The case resolves as a documented late start with the history intact rather than hardening into a permanent question mark, and nothing is quietly deleted to make either version look better.
  • Low activity is never a verdict. Reading a contract, sitting on a call, and reviewing a document all produce a low number. The rules refuse to convert that number into a conclusion, so it cannot be used against anyone.
  • Nobody can move the goalposts backwards. Schedules are versioned with effective dates, so the hours you agreed to are the hours you are measured against, and a later edit cannot retroactively make you late.
  • A new standard starts the day it is announced. When the way something gets measured changes, the period that already ran is reconstructed under the old understanding and the new rule applies forward. Nobody gets held to a bar that did not exist while they were working.
  • Every decision has a way back in. An adverse finding arrives with a deadline and a list of exactly what would change it. Produce the record and it reopens. A company willing to be corrected has to say so before the disagreement, not after it.
  • Every adverse call has a name and a reason on it. That is the difference between a decision you can respond to with specifics and a vague sense that somebody is unhappy. One is answerable. The other is not.

The company gets an account it can defend. The person gets paid for everything they did and stops having to argue for it. Those are the same feature.

What to do on the day your tracker dies

Machines fail, power goes, the agent will not start, you end up working from a second device somewhere with a borrowed connection. None of that is misconduct and none of it should cost anybody money. One step makes sure it does not, and it has to happen on the day.

Report it in writing, the same day, to whoever handles pay. Not at cutoff. Not when someone asks. That single message is what turns an invisible stretch of work into hours that can be verified and paid.

Send four things:

  • What broke, and when. One line. The agent would not start, the power went at two, the connection dropped for the afternoon.
  • Exact start and end times for the affected stretch, not a rounded total.
  • What you worked on, named per item. The account, the call, the deliverable.
  • One artifact with a timestamp. A calendar entry, a screenshot, a sent message, a delivered file. Anything a second person can open.

Then the other half of the deal runs. The time gets verified rather than assumed, it lands in the next disbursement, and if the fix is a second install under the same login, somebody walks you through it. A report filed on the day gets processed. A report filed a fortnight later still gets looked at, and it takes longer while it holds up your money.

This is the part that goes missing whenever oversight is described as something done to people. The protocol exists to protect the hours. Using it is how you make the system carry you.

Make every finding deterministic

If a finding can be produced two different ways, it is not evidence, it is an opinion with a timestamp. Write the rule as an explicit set of conditions, put every condition in the record, and let the code be the only thing that decides.

// Attendance findings are all-or-nothing. Every predicate is stored with the case
// so anyone reading it later can re-derive the same answer.
function absenceCandidate(shift, now, obs, feeds) {
  const checks = {
    activeShift:     Boolean(shift?.approvedVersionId),
    twoFullHours:    now - shift.startsAt >= 2 * 60 * 60 * 1000,
    noSession:       !obs.sessions.some((s) => s.overlaps(shift)),
    noLeave:         !shift.coveredByApprovedLeave,
    noException:     !shift.coveredByApprovedException,
    feedsFresh:      feeds.schedule.ageMs <= FRESH && feeds.observed.ageMs <= FRESH,
    notPrivileged:   !shift.person.isAdmin,
    noOpenDuplicate: !shift.hasOpenCase('possible_absence'),
  };

  return { open: Object.values(checks).every(Boolean), checks };
}

Three details in there carry the weight. The threshold is two full hours, not “a couple of hours”, so there is a defined instant either side of which the answer differs and both sides get a test. The checks object ships with the case, so the record carries the verdict and every condition that produced it. And the function never confirms anything. It opens a candidate. A human confirms.

That last point matters more than the rest combined. Automated systems are good at noticing and bad at judging. Let the system be relentless about noticing and keep the judgment with a person whose name goes on it.

A finding is only as good as the data’s freshness

The most damaging conclusion a monitoring system can produce is one drawn from a feed that had already gone quiet. The system looks confident, the record looks complete, and the underlying data was two hours stale.

So freshness gets a state of its own, and that state gates whether a finding is even allowed.

-- Freshness is stored with every case, not computed at read time.
create table attendance_cases (
  id                bigserial primary key,
  shift_instance_id bigint      not null references shift_instances(id),
  case_type         text        not null,
  opened_at         timestamptz not null default now(),
  predicates        jsonb       not null,   -- the exact checks that produced this
  schedule_age_ms   int         not null,
  observed_age_ms   int         not null,
  confirmed_by      uuid,                   -- null until a human decides
  confirmed_at      timestamptz,
  confirm_reason    text
);

-- One case per shift instance per type. A retried job cannot double-open.
create unique index attendance_cases_one_open
  on attendance_cases (shift_instance_id, case_type)
  where confirmed_at is null;

The classification is worth being blunt about:

  • Fresh, five minutes or less. The feed can support a finding.
  • Delayed, up to fifteen minutes. Show it, flag it, and do not let it drive anything adverse.
  • Stale, past fifteen minutes. State becomes Unknown. No finding opens.
  • Unavailable. State becomes Unknown, and the health panel says which source is down and who owns it.

Unknown is a real state with its own neutral treatment, not a quiet fallback to a green dot. A board that reports a calm ordinary morning while a feed is dead is worse than one that says it cannot see, which is the same principle as a dashboard that fails safely instead of silently. The partial-truth problem is general: the first signal to arrive is often incomplete, and the settled record has to win.

The fairness consequence is direct. When your data feed breaks, that is your outage, and it must never land on someone’s record as a missed shift. Unknown is how you stop an infrastructure failure from being charged to a person.

What to check before you trust your own oversight

  • Pick one instant, not a range. “Two full hours past the scheduled start” has a testable boundary. “Persistently late” does not.
  • Freeze the evidence to the finding. Store the schedule version, timezone, source ages, and every predicate on the case itself. A record that has to be recomputed later is a record that can change its mind.
  • Attribute everything to one identity. HIPAA requires unique user identification precisely because unattributable activity proves nothing.
  • Never let a percentage be a verdict. Low input is not idleness, and idleness is not absence. Each of those is a separate question with a separate answer.
  • Look before you deduct. A right to verify hours is also a duty to go looking when the tracker is quiet. Reconstruct from calendars, call logs, delivered files, and correspondence before a silent feed becomes a number on a payslip.
  • Distrust a self-reported figure that never moves. Identical totals across a period, descriptions copied word for word, and entries filed after the shift all point at a number that was assumed rather than measured. Check the total against the start and end times on the same entry.
  • Announce a standard before you measure against it. Reconstruct the period that already ran, apply the new rule forward, and say plainly in writing which is which.
  • Keep a human on every adverse call. The system opens the case. A named person closes it, with a reason, at or after the shift ends.
  • Make retries idempotent. A unique constraint on the open case is what stops a rerun from opening a second case and sending a second accusation.
  • Preserve work nobody asked for. Hours outside the schedule get their own record and an approval path. Dropping them because they are inconvenient to categorise is how a system quietly stops paying people.
  • Show people their own record. The person a finding is about should be able to open it, see the conditions that produced it, and respond to something specific. A record only they cannot read is not evidence, it is a file.
  • Disclose it plainly and early. New York already requires notice on hire with acknowledgement. Doing that everywhere costs nothing and removes the only real objection.

Watch the work. Then prove it.

Most oversight setups stop at the tracker, because a number feels like an answer. Then a client asks about a specific day, the number cannot answer, and the company discovers it has been collecting data without producing evidence.

Build the record instead. Same monitoring, same tools, one extra discipline: every finding carries the rule that produced it, the freshness of the data behind it, and the name of the person who decided. That is the version a client audit accepts, a payroll dispute survives, and a compliance review closes. The same idempotency spine keeps a burst of provider events from becoming lost or doubled records.

It is also the version the team wants, once they have worked under it for a month. Nobody enjoys being a number. Everybody prefers a system where the hours they worked are on the record, the leave they were granted is honoured without a conversation, the call that flatlined their activity graph cannot be held against them, and any concern arrives with a name and a reason they can answer. Oversight that produces evidence is not the price of the job. It is what makes the job fair to both people in it.

One last thing separates a record from a verdict, and it is whether you can reopen it. Say out loud, before anybody disagrees with you, that producing the evidence gets the decision looked at again. A company that would rather be corrected than be wrong has to commit to that in advance, because saying it afterwards costs nothing and proves nothing.

Telemetry is what you collect. Evidence is what you can hand someone, including the person it is about.

Frequently asked questions

In the United States, yes, with disclosure obligations that vary by state. Since May 7, 2022, New York Civil Rights Law section 52-c has required private employers to give prior written notice on hiring to employees subject to electronic monitoring, obtain their acknowledgement, and post the notice conspicuously, enforced by the Attorney General at up to 500 dollars for a first offense rising to 3,000 for repeats. Connecticut and Delaware have their own notice requirements. The pattern across all of them is disclosure rather than prohibition, so write it into the contract and the handbook and post it.

Does HIPAA require monitoring of staff who handle patient data?

It requires the two halves that make monitoring meaningful. 45 CFR 164.312(b) requires audit controls that record and examine activity in systems holding electronic protected health information, and 45 CFR 164.308(a)(1)(ii)(D) requires regular review of those records. Both are marked Required rather than Addressable. Unique user identification under 164.312(a)(2)(i) is also Required, because activity nobody can attribute is not an audit trail.

Can idle time or low activity prove someone was not working?

No, and building a system on that assumption creates disputes you will lose. Low keyboard and mouse input is equally consistent with reading a long document, being on a client call, or reviewing a contract, and monitoring vendors say so in their own documentation. The same holds at zero. A tracker recording no hours at all does not establish that nobody worked, because a machine that was off, an agent that never started, a regional outage, a second device, and a call taken on a phone all produce that identical reading. Treat activity as one observation among several, and require a human with a stated reason for any adverse conclusion.

Does employee monitoring benefit the worker or only the employer?

Both, when it produces a record rather than a score. Without one, every ambiguous day lands on the person to explain and doubt falls on whoever has the least evidence. With one, hours worked outside the schedule are preserved and paid instead of dropped, approved leave attaches to the shift so nobody reopens it months later, a late start resolves as a documented late start rather than a lasting question mark, a versioned schedule stops anyone moving the goalposts backwards, and any concern arrives with a named person and a stated reason that can be answered with specifics. A silent tracker also obliges the company to go looking through calendars, call logs, and delivered work before it deducts anything, and a change to how work gets measured applies forward from the day it is announced rather than backward over a period somebody has already worked.

What happens if your time tracker stops working during a shift?

Report it in writing the same day to whoever handles pay, and send four things: what broke and when, the exact start and end times of the affected stretch, what you worked on named per item, and one artifact carrying a timestamp such as a calendar entry, a sent message, or a delivered file. The hours then get verified against those records and paid. A tracker outage is an equipment problem rather than a pay problem, provided it is reported on the day instead of at cutoff, because a report filed weeks later still gets reviewed and simply takes longer to clear.