What is collected
The agent reports keyboard and mouse activity, programs and sites used during the shift, network usage, device location and screen captures — always within what the company policy authorises.
| Signal | What it is for |
|---|---|
| Keyboard and mouse activity | Telling time on from time worked |
| Programs and sites | Understanding where the shift's time went |
| Network usage | Spotting traffic outside the operation's pattern |
| Location | Confirming the device runs inside its geographic boundary |
| Screen captures | Audit and computer-vision risk detection |
How often
The default telemetry cycle is 15 seconds: that is how often the dashboard knows whether the device is online, what is running and where it is. Screen captures have their own interval, set by the plan.
Device offline
With no network, the agent buffers events locally and sends the backlog once the connection returns — no shift goes unaccounted for because of an internet drop.
How the data travels
The agent always opens the connection from inside the device, over TLS 1.3 and with an HMAC signature on every payload. There is no port to open and no VPN to run on the company network, and a request without a valid signature is discarded before it reaches any data.
At the destination, the record is encrypted at rest with AES-256 and isolated per company. Retention follows whatever policy you set.
Frequently asked questions
- Does monitoring run outside working hours?
- That depends on the policy. Collection can be limited to the configured shift window, and that is the recommended setup.
- Can I monitor only some devices?
- Yes. Policies are applied per group, so each set of devices can have a different level of collection.
Up next
Screen monitoring
Automatic captures, per-device history and the computer-vision analysis.
Keep reading