WorkMonitor for Enterprise
Your questionnaire, answered before you send it
Rollouts rarely stall in deployment. They stall in review, waiting on answers a vendor could have published. SSO, SCIM, retention, residency, audit, the DPA and support terms are all answered below — including the rows where the answer is no.
- SAML 2.0 single sign-on
- SCIM 2.0 provisioning
- Retention you set, including keep-forever
- Hash-chained audit log, reads included
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
- AKAria K. viewed screenshotsLena M. · 3 capturesScreen capturemacOS · London09:42a91f…4c023d7b…91ee
- JMJon M. exported time reportDesign team · CSVmacOS · Berlin09:313d7b…91ee77c5…0ba4
- SDSara D. opened capture reviewRavi P. · one flagged frameWindows · Manchester09:1877c5…0ba4e208…5f13
- wm_live_7f2… read /v1/deliverablesScoped key · read onlyPublic API · allowlisted IP08:57e208…5f13b64a…2d90
- LMLena M. viewed her own recordWhat We SeemacOS · London08:44b64a…2d901cf9…8e77
- AKAria K. changed capture policyBlur set to alwaysmacOS · London08:261cf9…8e7705d2…ae31
The procurement checklist
Every line on the form, answered
The rows a questionnaire actually contains, answered from what the platform does today, each with the document that evidences it beside the answer. 17 rows, 2 of which say no.
Identity and access
- 01Single sign-on
SAML 2.0 against your identity provider, shipped and passing our own conformance suite, but not yet certified against a live Okta or Entra tenant — we run that with you during the pilot, and the site marks it beta until we have. Okta, Entra ID and Google Workspace are also directory connectors, so the roster arrives with the identity. OIDC sign-in with Google is live on every plan.
Enterprise - 02Provisioning and deprovisioning
SCIM 2.0 for users and groups. A leaver removed in your directory loses access here, without a ticket and without waiting for someone to remember. Shipped, and beta on the same terms as SAML: verified against our own suite, not yet against your IdP.
Enterprise - 03Scoped roles
A role binds to a node in your org tree, so a regional manager sees their region rather than the company. Widening a scope is a privilege change and is recorded as one.
Every plan - 04Who read what
Reads, not only writes. Data access appends to its own hash chain, so you can show which administrator opened whose record, and when.
Enterprise
Data, residency and retention
- 05Retention
You set the window, including keep-forever, and you can always set it shorter than your plan allows. The cap is enforced server-side, not in the interface, and a deletion appends to the audit chain.
Enterprise - 06Data residency
Not offered. You cannot pick a region today. Residency arrives with self-hosted deployment, which is on the roadmap and not shipped, and bring-your-own-key encryption lands with it.
Not yet - 07Encryption of secrets
Integration credentials, single sign-on secrets, two-factor seeds and signing keys are sealed with authenticated AES-256-GCM. Production refuses to start without the key rather than falling back to plaintext.
Every plan - 08Sub-processors
Published as a document you can diff between versions, alongside the data processing addendum, rather than named on request.
Read the listEvery plan - 09Getting your data out
A read-only v1 REST API with scoped keys, a warehouse export connector, and certificates that stay verifiable on a public page whether or not you are still a customer. Every export is itself audited.
API referenceTeam and up
Evidence and audit
- 10Tamper-evident audit log
Governance changes, data access and our own staff actions each append to a SHA-256 hash chain, with database constraints making a forked chain impossible. Chain heads are anchored to object storage under S3 Object Lock in compliance mode, which cannot be deleted early even by the account root.
Enterprise - 11Tenant isolation
Your organisation is resolved from the verified credential, never from a URL, and the same boundary is enforced by composite foreign keys in the schema — so a cross-tenant record is a constraint violation rather than a missed code review.
Every plan - 12Employee rights
Everyone monitored gets a self-view of what was captured, a consent centre, a one-click private-time pause, and a dispute that freezes automated re-decision while it is open. This is the machinery a works council asks about.
Every plan - 13Certifications
None held. SOC 2 and ISO 27001 are in preparation. What exists today is the control set an audit examines, published with the open gap list instead of a badge.
The security positionNot yet
Counted from source, not from memory
- 310
- server-side checks that a record belongs to your organisation before it is returned
- 31
- composite foreign keys enforcing tenant isolation in the database itself
- 3
- independent SHA-256 hash chains: governance, data access, and our own staff actions
- 0
- keystrokes recorded: all three desktop agents count key presses and never read their content
Each of these is recomputed from the code it describes by a test in this repository, so a figure that drifts fails the build instead of quietly becoming marketing. The security page carries the same four.
Contract and support
- 14Data processing addendum
Part of the platform terms and published in full, with a separate FAQ answering the questions procurement usually returns with a week later.
Read the DPAEvery plan - 15Uptime commitment
The service level agreement commits to 99.9% monthly availability, with service credits of 10% of monthly fees between 99.0% and 99.9% and 25% below that. The exclusions are written down rather than implied.
Read the SLATeam and up - 16Support terms
Standard support is email during business hours. Priority and round-the-clock support are agreed in the Enterprise order form, alongside security review and rollout assistance.
Enterprise - 17Notice to the people monitored
A worker privacy notice written for them rather than for you, so a works council consultation does not start with drafting one from scratch.
Read the noticeEvery plan
What a checklist is for
The rows that say no — 2 of 17 — are what make the rest worth reading.
Anyone can write yes down a column. A no is the only entry that costs the vendor something to publish.
Where the line sits
Which plan clears your checklist
Most of the platform is on every plan. Enterprise is where the sign-off items live. Here is that boundary, drawn rather than described.
| Requirement | Free | Team | Business | Enterprise |
|---|---|---|---|---|
| Price per user / month | $0 | $8 | $14 | Custom |
| Screenshot retention | 30 days | 180 days | 365 days | Custom |
| Analytics history window | 7 days | Unlimited | Unlimited | Unlimited |
| Hash-chained, tamper-evident audit log | Not included | Not included | Not included | Included |
| Consent evidence with IP, agent & version | Not included | Not included | Not included | Included |
| Dedicated support with an agreed SLA | Not included | Not included | Not included | Included |
Prices are per user per month on monthly billing; annual billing takes two months off Team and Business. The full comparison is on the pricing page.
Not a description of the product
Every control on that list is a screen
Retention, scope, consent, export and keys are pages an administrator opens, with a history and an owner. Pick a row to open the one it lives on.
- AKProof LedgerClient-grade proof.Search or ask…
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
Northlight StudioControlsCapture policy, applied on the deviceCONTROLSCOPESTATE- Screenshot captureEvery 15 min, working hours onlyWhole orgOn
- Blur before uploadBlurred on the device — the sharp frame never leaves itWhole orgOn
- Keystroke contentNot collected, and cannot be switched onWhole orgUnavailable
- Private timeAnyone can pause capture; the pause is logged, the screen is notDesign teamOn
App deny listDesign team · 3 apps1PasswordMessagesWhatsAppAdd appNothing from these apps is recorded — no screenshot, no window title.Rules are applied on the device before anything is transmittedChanged by Aria K. · 28 Aug
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
- Screenshot captureEvery 15 min, working hours onlyWhole orgOn
- Blur before uploadBlurred on the device — the sharp frame never leaves itWhole orgOn
- Keystroke contentNot collected, and cannot be switched onWhole orgUnavailable
- Private timeAnyone can pause capture; the pause is logged, the screen is notDesign teamOn
What we cannot do yet
Four reasons to walk away
A gap found in month three of procurement costs you the quarter. Here are ours, in the order they get discovered. If one of them is a hard requirement, stop reading and keep your afternoon.
- 01
No certifications
SOC 2 and ISO 27001 are in preparation. We publish the control inventory, each claim naming the code that implements it, and the open gap list beside it.
- 02
No data residency
Regions are not selectable. If your policy fixes processing to one region today, we are not the vendor for that policy yet.
- 03
No self-hosted deployment
It is on the roadmap rather than shipped, and bring-your-own-key encryption lands with it. If self-hosting is a hard requirement, this is the paragraph that saves you a quarter.
- 04
No customer reference to offer
WorkMonitor is pre-launch, so there is nobody to put you in touch with. What we can put in front of your reviewers is the control set, the gap list, and a session with the people who wrote it.
Straight answers
The questions we would ask in your position
Every answer here is the one you would get on a call. Open as many as you like; they stay open, so two can be held side by side.
Agents install and enrol without a hand on every machine, and the device inventory shows which ones have not checked in yet, so the long tail is visible rather than assumed. Identity comes from the provider you already run: Okta, Entra ID or Google Workspace, with roles scoped to a node in your org tree so a regional manager sees their region and not the company.
Two independent layers. Roles are scoped to a node in the org tree, and beneath that, isolation is enforced by the schema itself: 31 composite foreign keys tie every record to its organisation, so a cross-tenant join is a constraint violation rather than a missed code review. On top, 310 server-side checks confirm a record belongs to your organisation before it is returned, with the scope taken from the credential rather than the request path.
Not yet, and we will not imply otherwise. Both are in preparation. What exists today is the underlying control set an audit examines: credential-derived tenant isolation, tamper-evident audit chains anchored to immutable storage, role-scoped access with the access itself recorded, and documented employee data rights. The security page states the current position precisely.
Consent, notice and retention rules apply per jurisdiction rather than globally, with the record to show which policy version each person accepted and when. Employees get a self-view of what was collected and a route to appeal a specific capture, the machinery a works council asks about. Local law still varies on automated evaluation, so what the data may be used for is a policy you set explicitly.
It is exportable while you are a customer and not held hostage on the way out: a read-only v1 REST API with scoped keys, a warehouse export connector, and issued Proof Ledger certificates that stay verifiable on a public page whether or not you are still a customer. Retention and deletion are governed by the policy you set, not by us.
No. It is on the roadmap rather than shipped, and data residency and bring-your-own-key encryption land with it. If a self-hosted deployment is a hard requirement today, this is the honest place to find that out rather than three months into procurement.
For the file
The pack to forward to your team
Everything a reviewer asks for is already written and already public. Send the links; nobody has to wait on us for a PDF.
- Data processing addendumThe processor terms in full, published rather than sent on request.
- DPA FAQsThe questions procurement returns with, answered once.
- Sub-processorsWho else touches the data, and for what.
- Service level agreementThe availability commitment, the credits, and the exclusions.
- Worker privacy noticeWritten for the people being monitored, ready for a works council.
- Security overviewThe control set, the counts behind it, and the gaps still open.
- Monitoring law, country by countryWhat each jurisdiction requires, and the control that meets it.
- Public API and webhooksScoped keys and a read-only v1 — the exit route as well as the integration one.
Bring your questionnaire. We will answer it in writing.
A review call with the people who wrote the controls, a scoped pilot, and terms on your paper where they need to be. If you would rather look first, two seats are free for as long as you like.