Disclosure
Employee monitoring notice — template
A starting-point notice your client can adapt and give to staff before SnitchOS is deployed. Not legal advice — monitoring-disclosure and consent rules vary by state and country. Have the client's counsel review before use.
SnitchOS records input counts, not the keys or typed content. The agent runs as a visible Windows service that a local administrator can uninstall. Customers should still explain screenshots and other monitoring clearly before deployment.
Notice of Workplace Activity Monitoring
To support productivity, security, and the protection of company resources, [COMPANY] uses workforce-analytics software (SnitchOS) on company-owned devices. Effective [DATE], the following work activity may be recorded during working hours on managed devices:
- Applications used and the active window title, sampled every 10 seconds
- Websites visited, recorded as the site address and page path only — the query string and page fragment are removed before anything leaves the device
- Active vs. idle time and aggregate input volume (counts of keystrokes and mouse activity, never the actual keys typed)
- Screenshots of the work desktop, about one every 60 seconds while the device is in active use (skipped while idle, and an image identical to the one before it is discarded)
What is not intentionally extracted as separate fields: keys pressed or typed content, clipboard or file contents, message bodies, audio, webcam data, saved passwords, URL query strings, or URL fragments. Screenshots, window titles, and URL paths may still display sensitive information.
Data is accessed only by authorized administrators for legitimate business purposes and is handled per [COMPANY]'s data-protection policy. Screenshots are held for 30 days in primary storage, then in archive storage until they are 365 days old, and are then deleted. Records of application and website activity are kept indefinitely by default. Questions: contact [HR / IT CONTACT].
By continuing to use company devices on or after [DATE] you acknowledge this notice.
Deployment checklist for the MSP
- Have qualified counsel confirm the notice, acknowledgement, consent, and worker-rights requirements in every applicable jurisdiction.
- Distribute the approved notice and record any required acknowledgement or consent before monitoring starts.
- Check the retention figures above against the current published defaults before you send the notice, and note that they are platform-wide rather than something you set per client.
- List anyone whose monitoring is paused, since pause is the only way to take a person out of scope.
- Keep the signed notice on file with the engagement record.
See also: Deploy with your RMM · Security & disclosure posture