WorkMonitor.

WorkMonitor for Enterprise

Your questionnaire, answered before you send it

Rollouts rarely stall in deployment. They stall in review, waiting on answers a vendor could have published. SSO, SCIM, retention, residency, audit, the DPA and support terms are all answered below — including the rows where the answer is no.

  • SAML 2.0 single sign-on
  • SCIM 2.0 provisioning
  • Retention you set, including keep-forever
  • Hash-chained audit log, reads included
Audit log
Hash-chained, including who read what
Chain verified to entry 48,210 — no gaps, no rewritesChain intactChecked 2 min ago
EVENTSOURCETIMEHASH
  • AKAria K. viewed screenshotsLena M. · 3 capturesScreen capturemacOS · London09:42a91f…4c023d7b…91ee
  • JMJon M. exported time reportDesign team · CSVmacOS · Berlin09:313d7b…91ee77c5…0ba4
  • SDSara D. opened capture reviewRavi P. · one flagged frameWindows · Manchester09:1877c5…0ba4e208…5f13
  • wm_live_7f2… read /v1/deliverablesScoped key · read onlyPublic API · allowlisted IP08:57e208…5f13b64a…2d90
  • LMLena M. viewed her own recordWhat We SeemacOS · London08:44b64a…2d901cf9…8e77
  • AKAria K. changed capture policyBlur set to alwaysmacOS · London08:261cf9…8e7705d2…ae31
Each entry carries the hash of the one before it, so an edit anywhere breaks everything after it.48,210 entries

The procurement checklist

Every line on the form, answered

The rows a questionnaire actually contains, answered from what the platform does today, each with the document that evidences it beside the answer. 17 rows, 2 of which say no.

01

Identity and access

  • 01Single sign-on

    SAML 2.0 against your identity provider, shipped and passing our own conformance suite, but not yet certified against a live Okta or Entra tenant — we run that with you during the pilot, and the site marks it beta until we have. Okta, Entra ID and Google Workspace are also directory connectors, so the roster arrives with the identity. OIDC sign-in with Google is live on every plan.

    Enterprise
  • 02Provisioning and deprovisioning

    SCIM 2.0 for users and groups. A leaver removed in your directory loses access here, without a ticket and without waiting for someone to remember. Shipped, and beta on the same terms as SAML: verified against our own suite, not yet against your IdP.

    Enterprise
  • 03Scoped roles

    A role binds to a node in your org tree, so a regional manager sees their region rather than the company. Widening a scope is a privilege change and is recorded as one.

    Every plan
  • 04Who read what

    Reads, not only writes. Data access appends to its own hash chain, so you can show which administrator opened whose record, and when.

    Enterprise
02

Data, residency and retention

  • 05Retention

    You set the window, including keep-forever, and you can always set it shorter than your plan allows. The cap is enforced server-side, not in the interface, and a deletion appends to the audit chain.

    Enterprise
  • 06Data residency

    Not offered. You cannot pick a region today. Residency arrives with self-hosted deployment, which is on the roadmap and not shipped, and bring-your-own-key encryption lands with it.

    Not yet
  • 07Encryption of secrets

    Integration credentials, single sign-on secrets, two-factor seeds and signing keys are sealed with authenticated AES-256-GCM. Production refuses to start without the key rather than falling back to plaintext.

    Every plan
  • 08Sub-processors

    Published as a document you can diff between versions, alongside the data processing addendum, rather than named on request.

    Read the list
    Every plan
  • 09Getting your data out

    A read-only v1 REST API with scoped keys, a warehouse export connector, and certificates that stay verifiable on a public page whether or not you are still a customer. Every export is itself audited.

    API reference
    Team and up
03

Evidence and audit

  • 10Tamper-evident audit log

    Governance changes, data access and our own staff actions each append to a SHA-256 hash chain, with database constraints making a forked chain impossible. Chain heads are anchored to object storage under S3 Object Lock in compliance mode, which cannot be deleted early even by the account root.

    Enterprise
  • 11Tenant isolation

    Your organisation is resolved from the verified credential, never from a URL, and the same boundary is enforced by composite foreign keys in the schema — so a cross-tenant record is a constraint violation rather than a missed code review.

    Every plan
  • 12Employee rights

    Everyone monitored gets a self-view of what was captured, a consent centre, a one-click private-time pause, and a dispute that freezes automated re-decision while it is open. This is the machinery a works council asks about.

    Every plan
  • 13Certifications

    None held. SOC 2 and ISO 27001 are in preparation. What exists today is the control set an audit examines, published with the open gap list instead of a badge.

    The security position
    Not yet

Counted from source, not from memory

310
server-side checks that a record belongs to your organisation before it is returned
31
composite foreign keys enforcing tenant isolation in the database itself
3
independent SHA-256 hash chains: governance, data access, and our own staff actions
0
keystrokes recorded: all three desktop agents count key presses and never read their content

Each of these is recomputed from the code it describes by a test in this repository, so a figure that drifts fails the build instead of quietly becoming marketing. The security page carries the same four.

04

Contract and support

  • 14Data processing addendum

    Part of the platform terms and published in full, with a separate FAQ answering the questions procurement usually returns with a week later.

    Read the DPA
    Every plan
  • 15Uptime commitment

    The service level agreement commits to 99.9% monthly availability, with service credits of 10% of monthly fees between 99.0% and 99.9% and 25% below that. The exclusions are written down rather than implied.

    Read the SLA
    Team and up
  • 16Support terms

    Standard support is email during business hours. Priority and round-the-clock support are agreed in the Enterprise order form, alongside security review and rollout assistance.

    Enterprise
  • 17Notice to the people monitored

    A worker privacy notice written for them rather than for you, so a works council consultation does not start with drafting one from scratch.

    Read the notice
    Every plan

What a checklist is for

The rows that say no — 2 of 17 — are what make the rest worth reading.

Anyone can write yes down a column. A no is the only entry that costs the vendor something to publish.

Where the line sits

Which plan clears your checklist

Most of the platform is on every plan. Enterprise is where the sign-off items live. Here is that boundary, drawn rather than described.

WorkMonitor plans against the requirements a security review asks about
RequirementFreeTeamBusinessEnterprise
Price per user / month$0$8$14Custom
Screenshot retention30 days180 days365 daysCustom
Analytics history window7 daysUnlimitedUnlimitedUnlimited
Hash-chained, tamper-evident audit logNot includedNot includedNot includedIncluded
Consent evidence with IP, agent & versionNot includedNot includedNot includedIncluded
Dedicated support with an agreed SLANot includedNot includedNot includedIncluded

Prices are per user per month on monthly billing; annual billing takes two months off Team and Business. The full comparison is on the pricing page.

Not a description of the product

Every control on that list is a screen

Retention, scope, consent, export and keys are pages an administrator opens, with a history and an owner. Pick a row to open the one it lives on.

  1. Controls
    Capture policy, applied on the device
    CONTROLSCOPESTATE
    • Screenshot captureEvery 15 min, working hours onlyWhole orgOn
    • Blur before uploadBlurred on the device — the sharp frame never leaves itWhole orgOn
    • Keystroke contentNot collected, and cannot be switched onWhole orgUnavailable
    • Private timeAnyone can pause capture; the pause is logged, the screen is notDesign teamOn
    App deny listDesign team · 3 apps
    1PasswordMessagesWhatsAppAdd app
    Nothing from these apps is recorded — no screenshot, no window title.
    Rules are applied on the device before anything is transmittedChanged by Aria K. · 28 Aug

What we cannot do yet

Four reasons to walk away

A gap found in month three of procurement costs you the quarter. Here are ours, in the order they get discovered. If one of them is a hard requirement, stop reading and keep your afternoon.

  1. 01

    No certifications

    SOC 2 and ISO 27001 are in preparation. We publish the control inventory, each claim naming the code that implements it, and the open gap list beside it.

  2. 02

    No data residency

    Regions are not selectable. If your policy fixes processing to one region today, we are not the vendor for that policy yet.

  3. 03

    No self-hosted deployment

    It is on the roadmap rather than shipped, and bring-your-own-key encryption lands with it. If self-hosting is a hard requirement, this is the paragraph that saves you a quarter.

  4. 04

    No customer reference to offer

    WorkMonitor is pre-launch, so there is nobody to put you in touch with. What we can put in front of your reviewers is the control set, the gap list, and a session with the people who wrote it.

Straight answers

The questions we would ask in your position

Every answer here is the one you would get on a call. Open as many as you like; they stay open, so two can be held side by side.

6 questions
Ask us something else

Bring your questionnaire. We will answer it in writing.

A review call with the people who wrote the controls, a scoped pilot, and terms on your paper where they need to be. If you would rather look first, two seats are free for as long as you like.