Most of this section has discussed trade-offs, spectrums, and context-dependent judgment calls. This page is intentionally different: a short list of practices that don't belong in this category of software at all, regardless of context, stated as hard lines rather than considerations to weigh.

The hard lines

Covert or invisible monitoring — any mode designed specifically so the monitored person can't know it's active — has no legitimate place in workplace monitoring software, independent of the underlying justification offered for it. Content capture beyond what's needed for the stated purpose — keystroke logging, screen recording, or webcam and microphone capture bundled into general productivity tools — goes meaningfully beyond activity-level tracking and belongs, if anywhere, in narrowly scoped, explicitly disclosed, security-specific tools rather than default productivity features. Monitoring an employee's personal device or personal accounts, or personal activity on a work device clearly outside working hours and unrelated to work, oversteps the legitimate boundary of workplace monitoring regardless of the device's ownership. Readers can compare this approach with guidance from EFF's privacy resources.

Why each line is stated the way it is

Each of these four lines is phrased to close a specific loophole that a less carefully worded version might leave open. “No covert monitoring” rather than “minimal covert monitoring” closes off the argument that a small, limited amount of hidden tracking is acceptable if the underlying purpose is good enough — the transparency guide elsewhere in this section explains why the harm of covert monitoring is tied to its covertness itself, not just to its scope, so scaling it down doesn't meaningfully address the core problem. “No content capture beyond what's needed for the stated purpose” rather than a blanket ban on all content capture leaves room for the narrowly scoped, security-specific case discussed in the insider-threat guide elsewhere in this section, while still ruling out content capture bundled casually into a general productivity feature. An additional walkthrough is available the full discussion.

Why these are framed as absolutes rather than trade-offs

Nearly everything else discussed in this section involves genuine, reasonable trade-offs — how much detail to collect, how granular reporting should be, how to configure retention. These lines don't, because each one removes something that makes the rest of the trade-off conversation meaningful in the first place: transparency, proportionality, personal-life boundaries, human judgment in consequences, and the basic expectation that data collected for one stated purpose won't quietly be repurposed for another. A monitoring practice that violates one of these isn't a more aggressive point on a spectrum of reasonable options — it's a different, worse category of practice.

How this list functions as a filter for the rest of this site

Every other guide across this site's Employee Monitoring Software section, and several guides in the Solutions and Resources sections that touch on monitoring in a specific context, are written consistent with these lines rather than in tension with them. Where a specific use case (insider-threat detection, field-service location tagging) might seem to push against one of these boundaries, the relevant guide explains specifically how that use case stays within the line rather than treating the boundary as flexible for a sufficiently good reason — because a boundary that bends for a good enough reason isn't really a hard line at all.

Most of what makes monitoring software trustworthy or not is genuinely a matter of degree and configuration. A small number of specific practices aren't a matter of degree — they're lines a legitimate workplace tool shouldn't cross regardless of the business justification offered.

Read alongside the choosing-ethical-monitoring-software checklist elsewhere in this section, these lines are the specific things worth checking first, before evaluating anything else about a given tool — a product that fails any one of them isn't made acceptable by strong performance on the rest of the checklist.