Recording People Is Monitoring People
Session recording is workplace monitoring, with obligations attached in most jurisdictions. What to settle before deployment rather than after.
Analysis
Session recording is deployed as a security control and is, factually, surveillance of named employees at work. Treating it otherwise creates legal exposure and destroys trust with the people you most need to cooperate.
General orientation. Requirements differ substantially by jurisdiction and change; take advice for yours.
What it is
Continuous capture of a named person's work, including keystrokes in many implementations.
Retained, frequently for years.
Reviewable by people the recorded person may not know.
Capable of capturing far more than intended: personal messages typed in a session, credentials for unrelated systems, health information visible in an administered application.
The obligations that commonly apply
Notice. Employees generally must be told that monitoring occurs, what is captured, why, and for how long it is kept. Buried consent in an induction pack is usually insufficient.
Purpose limitation. Data collected for security should not be repurposed for performance management. This is where most organisations quietly fail, and where the trust damage is largest.
Proportionality. The monitoring must be justified against the risk, and less intrusive alternatives considered.
An impact assessment is required in some jurisdictions before deployment of systematic monitoring.
Consultation with employees or their representatives, which is a requirement in several jurisdictions rather than good practice.
Access rights. The recorded person may have a right to see data about themselves.
Special categories. Recordings may incidentally capture sensitive personal data, which carries stronger requirements.
What to settle before deployment
Scope. Which sessions, which systems, which people.
What is captured, specifically, including whether keystrokes are logged.
Retention period, with a justification.
Who may review, under what trigger, with what authorisation.
Whether the recorded person is notified of a review.
What it will not be used for, stated explicitly and honoured.
How exclusions work — a way to avoid capturing genuinely unrelated content.
Telling people properly
Before deployment, not after.
Specifically: what is recorded, when, who can see it, how long it is kept.
In plain terms, not in a policy nobody reads.
With the reason, which administrators generally accept when it is stated honestly.
Session banners at connection, which is both a legal safeguard and a deterrent.
Answer the obvious question honestly: yes, this could show that you made a mistake. Say what will and will not happen as a result.
The performance management line
The most consequential boundary.
If recordings are used to assess individual performance, administrators will behave accordingly: avoiding the recorded path, working around it, and treating the security team as adversarial.
State the limitation in writing, and enforce it. Where an exception is genuinely needed — a serious misconduct investigation — define who authorises it and record that it happened.
An organisation that quietly repurposes security recordings will find out once, and the loss of cooperation is permanent.
Protecting the recordings
They contain credentials, typed during sessions.
They contain data from every system administered.
Access controlled tightly and itself audited.
Retention enforced by deletion, not by policy alone.
Treat the recording store as a tier zero system, because functionally it is one.
The impact assessment
Required before systematic monitoring in several jurisdictions, and useful regardless.
What is being monitored, specifically, including whether keystrokes are captured.
Why, with the risk it addresses.
Who is affected and how many.
What less intrusive alternatives were considered and why they were rejected.
What safeguards apply: access restriction, retention limits, purpose limitation, review triggers.
What the residual impact on those monitored is.
Reviewed when the deployment changes, and retained as evidence that the proportionality question was actually asked.
The session banner
A short notice at connection that does more work than any policy document.
States that the session is recorded.
States what is captured.
States where to find the full policy.
Appears at every privileged connection, not once at induction.
Serves two purposes: the legal notice requirement in many jurisdictions, and the deterrent effect, which depends on people being aware at the moment rather than having read something once.
Keep it short, or it becomes something people dismiss without reading, which defeats both purposes.