Of all the features in an endpoint monitoring platform, screen checking is the most direct — and the most sensitive. It is also the one that raises the most questions about how far a company may go.
This article explains how the feature works, where it is justified and what has to be settled before switching it on.
How it works
The agent installed on the device captures the screen image and sends it to the platform. There are two modes, with distinct purposes:
- Periodic capture. Records at a defined interval, forming a searchable history.
- On-demand check. The screen at that moment, requested from the dashboard.
The first serves follow-up and later investigation. The second serves diagnosis and situations that require immediate verification.
In both cases the capture is of the corporate device and follows the configuration the company defines — interval, hours and which groups are subject to the feature.
When the feature is justified
Some uses are clear:
- Technical support. Seeing the screen shortens diagnosis and avoids the endless "describe what you are seeing" call.
- Incident investigation. Where there is a concrete, bounded suspicion, history helps establish what happened.
- Regulated operations. Areas where recording activity is part of the obligation itself.
- Critical shifts. Operations where an interruption has immediate consequences.
When it is not justified
It is worth being explicit about the other side too:
- As a generic measure of distrust, with no declared purpose
- Outside working hours
- On a personal device
- As a substitute for management — if the problem is unclear deliverables, the screen will not fix it
A feature switched on without purpose does not produce useful information. It produces a volume of sensitive data and friction with the team.
What to define before switching it on
- 1Which groups are subject to the feature — rarely the whole company.
- 2What interval between captures, if periodic.
- 3What time window — generally working hours only.
- 4Who may consult the history, and on what justification.
- 5How long records are kept.
- 6How the team is informed — beforehand, in writing, accessibly.
Those six points are the difference between an operational feature and a compliance problem. The full subject is in employee monitoring and data protection.
How it works in Vigilioo
In Vigilioo, screen checking is part of the monitoring module, alongside application and website logging and activity indicators. In practice:
- The feature is enabled per device group, not globally
- The capture interval is configurable, including on-demand checking
- Images are tied to the device and to that machine's timeline
- Access to the history is controlled inside the platform
- Data is encrypted in transit and at rest
The design goal is to let a company switch on exactly what its policy provides for — and nothing beyond it.
Combining with other signals
A screen capture on its own rarely answers a question. Combined, it does:
| Question | Signals that answer it |
|---|---|
| What happened at this hour? | Activity timeline + captures from the period |
| Is this software being used? | Application inventory + time in use |
| Is the equipment where it should be? | Location + device state |
| Was there an attempt to copy data? | USB policy log + activity |
Conclusion
Screen checking is a legitimate feature inside a clear policy and a problem outside one. The technology is the same in both cases — what changes is purpose, scope and transparency.
Write the policy before switching it on. Review whether it still makes sense after.