When employees find out about monitoring by accident, the tool stops being about work and becomes about suspicion. When they hear about it from their manager first, with a clear reason and clear limits, most people shrug and get back to work. The difference is almost entirely in how you introduce it.
This post walks through a plan we use with our own clients. It works for a five-person office and for a fifty-person company with remote staff.
Start with your reason, in one sentence
Before you tell anyone anything, write down why you want activity data. Keep it to one sentence. Good reasons sound like this:
- "We're hiring and need to know whether our current team is overloaded or under-used."
- "Half of us work remotely now, and I want a fair way to see workload that doesn't depend on who's loudest on Teams."
- "We need to know when files leave the company on USB drives, for security reasons."
If your honest sentence is "I think someone is slacking and I want proof," stop. Talk to that person first. Monitoring rolled out to catch one person will feel like an accusation to everyone, and they will be right.
Decide what you will and won't collect before you announce it
Employees will ask what you can see. You need a precise answer on day one, so make the decisions first. A typical setup for a small business looks like this:
- Active and idle time on company Windows computers during the workday.
- Which applications are in use and the names of websites visited, such as "quickbooks.com", without full addresses or page content.
- Alerts for a short list of security events, such as large USB file copies.
Then write down what you are not doing. With CyberWall Insights, that list is fixed: no keystroke logging, no reading email, documents or chat, no full URLs, and no screenshots unless you specifically ask us to turn on the add-on. If you do add screenshots, say so in the announcement. Leaving it out and having someone discover it later is the fastest way to lose trust.
Check the law where your people work
Several states require written notice before you monitor, and some require a signed acknowledgment. New York, Connecticut, Delaware and Maine all have specific rules. Our guide to U.S. monitoring notice laws summarizes them, and our monitoring policy template gives you a starting draft. Neither is legal advice, so have your attorney review your final policy.
Tell people in person first, then in writing
Announce it in a team meeting or a short video call. Email alone reads as cold and invites people to fill the gaps with worst-case guesses. A five-minute talk can cover:
- The reason. Your one sentence from above.
- What is collected. Active time, apps, site names, the specific alerts.
- What is never collected. Keystrokes, message content, personal devices.
- Who sees it. Name the roles. "Me and the office manager" is a real answer.
- How it will be used. For example: to balance workload, to plan hiring, and to spot security problems. Say plainly that a number on a report is a starting point for a conversation and never an automatic judgment.
- When it starts. Give at least a few days of notice.
Follow up the same day with the written policy and an acknowledgment form. In Insights, the agent can also show employees a monitoring notice on their computer, so the message is consistent everywhere.
Answer the hard questions honestly
You will hear a few questions almost every time. Prepare answers ahead.
"Do you think we're not working?"
Say what is true. If you are planning capacity, say that. If you have a real concern about someone, that is a private conversation and not a reason to monitor the whole team.
"Will this count against me when I'm on the phone or in a meeting?"
This one matters. Activity tools measure computer input. A phone call with a client, a whiteboard session or reading a printed contract can show as idle time. Tell people you know this, and that you will look at patterns over weeks rather than any single afternoon. Then actually do that.
"Can you see my personal stuff?"
Explain that the agent runs only on company Windows computers, and that it records site names, never the content of a page or message. Encourage people to keep personal browsing on personal devices, the same as you would without any tool.
"Who else gets this data?"
Nobody outside the company, other than the provider that runs the system. With Insights, each company's data is kept separate, every login requires multi-factor authentication, and we never sell data.
Show employees their own picture
People trust what they can see. Share team-level trends in a staff meeting after the first month. Offer to walk any employee through their own daily metrics on request. When people see that the reports show the same thing they already know about their week, the mystery goes away.
Use the data the way you said you would
The first time a manager uses a report to embarrass someone in public, the trust you built is gone. Set a few ground rules for anyone with access:
- Look at trends over at least two weeks before drawing conclusions.
- Ask before you assume. "I noticed your mornings look lighter lately, is something getting in the way?" opens a conversation. "Your numbers are bad" ends one.
- Never share an individual's data with peers.
- Use the data to fix workload and process problems, too. If a whole team is idle every afternoon because a system is slow, that is your problem to solve.
Revisit it after 90 days
Put a review on the calendar. Ask your team what has felt fair and what hasn't. Check whether you are still using every alert you set up, and turn off what you don't need. Collecting less is almost always the right adjustment.
A short checklist
- Write your one-sentence reason.
- Decide what is collected and what is not.
- Check state notice rules and draft a written policy.
- Announce it live, then send the policy and acknowledgment.
- Turn on the employee notice in the agent.
- Set ground rules for managers.
- Review after 90 days.
Handled this way, monitoring becomes one more source of facts about how work gets done. That is all it should ever be.
