Skip to content
Sections
All notes

All notes · Monitoring

Detection Without Interception

Most of what a programme needs can be learned without reading anything. The techniques, and why they are usually enough.

Monitoring · Analysis

There is a persistent assumption that useful visibility requires inspecting content. For almost every programme-level question, it does not.

The recommendations in “Detection Without Interception” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating the official resource can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.

For an independent benchmark, compare the local approach with ICO guidance on AI and data protection; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

What destination data answers

Which services are in use and how widely.

Adoption trend after a policy change or a rollout.

Which departments have a gap in provision.

New services appearing.

That is most of the programme's information need, from logs you already hold.

What inventory answers

Which extensions are installed, and which can read page content.

Which approved tools have AI features enabled.

Which developer tooling is present.

The extension finding alone usually justifies the exercise, and it requires no content inspection at all.

What finance answers

Which tools people pay for, which indicates dependence.

Which departments, and how long.

Covered in its own note and worth repeating here: it finds the serious cases that network data cannot distinguish.

What asking answers

Why. Which task, which gap, what would make them switch.

No technical method produces this and it is the most actionable output of the whole exercise.

Where interception genuinely adds something

Preventing a specific classified pattern from leaving: card numbers, client identifiers, regulated markings.

That is a narrow, automated, pattern-matching purpose with no human reading unless there is a match.

And it is better served by client-side blocking than by boundary inspection, which the prompt note argues.

The question to ask of any proposal

What will we learn from this that we cannot learn from destination, inventory, finance and asking?

If the answer is "which specific documents were pasted", ask whether that is the purpose or a by-product.

If it is a by-product, it is a reason not to collect it.

The cost of interception beyond privacy

It is expensive to deploy, generates false positives that consume analyst time, and produces a data holding you must then protect.

Its own note covers false positives, which are the practical reason many of these deployments are quietly turned down after a year.

The position worth taking

Collect destination and inventory as standard. Add pattern-based prevention where regulated data genuinely warrants it. Do not retain content.

Defensible, proportionate, and it answers the questions a programme actually has.

What to check

What question is your content inspection answering?

Could destination, inventory, finance and asking answer it?

Is prevention done at the client or at the boundary?

And is any content retained after a non-match?

The point

Ask of any monitoring proposal what it will reveal that destination, inventory, finance and asking cannot.

If the answer is a by-product, that is a reason not to collect it.

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.