Skip to content
Sections
All notes

All notes · Monitoring

Aggregate Versus Individual Visibility

The same data at two resolutions supports two different activities. Choosing the resolution is the main governance decision.

Monitoring · Procedure

Monitoring data can answer "which services are in use here" or "what did this person do". The technical collection is the same; the decision is what is exposed.

Applying the boundary described in “Aggregate Versus Individual Visibility” requires a clear operational purpose and a record that can be reviewed without reading private content. Teams considering long-term time tracking software can use workload and time evidence to understand how approved processes are actually used, while keeping AI discovery, security telemetry and employee monitoring separate and proportionate.

For an independent benchmark, compare the local approach with ICO guidance on AI and data protection; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

What aggregate answers

Which services, how widely, trending how.

Which departments have a gap.

Whether an enterprise rollout actually displaced consumer use.

Whether policy changed behaviour.

Every programme-level question, which is almost all of them.

What individual visibility is for

Investigating a specific concern with a stated basis.

Responding to an incident where data went somewhere it should not.

And nothing else.

The default to set

Reports and dashboards at aggregate level, with a minimum group size.

Individual detail available only through a defined process: a named approver, a written reason, a record of the access.

Not technically impossible — that would prevent legitimate investigation — but deliberately effortful, which is what keeps it exceptional.

The minimum group size

A minimum group size below which figures are not shown. Ten is a common choice.

Applied to departments and to intersections, because site plus department plus tool narrows quickly.

Check whether somebody can reach a single person by combining filters, which most dashboards allow by default.

The access record

Who looked at individual data, when, and why.

Reviewed by somebody other than the people with access.

This is standard practice for other sensitive data and is rarely applied to monitoring tooling, which is where the drift happens.

The requests that will come

A manager asking about their team.

HR asking during a process.

Security asking during an unrelated investigation.

Each needs the same answer: through the defined process, with a stated basis, or not at all.

Having that written before the first request is what makes refusal possible.

Why this protects the programme

Beyond the obvious: once people believe individual use is visible and consequential, behaviour changes.

They move to personal devices, which removes your visibility entirely.

The aggregate picture you were relying on degrades, which is the same dynamic as every other workplace measurement.

What to check

Is individual detail available by default in your tooling?

Is there a defined process with a named approver?

Is access to individual data logged and reviewed?

And can three filters in your dashboard reach one person?

The point

Aggregate answers every programme-level question.

Individual detail is for investigating a specific concern with a stated basis, and nothing else.

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.