Thirty years ago, when the web arrived on every desk in the workplace, I watched organizations gain an extraordinary tool and, almost immediately, start looking for ways to see what people were doing with it. I have spent the time since then building software that answers that question, and I have watched the answer change shape more than once. Right now it is changing again, and I think it is changing for the better.
For most of those thirty years, the instinct ran in one direction: capture more.
When the web first reached every employee, the concerns were real and they were reasonable. Time disappeared into activity nobody could account for. Networks were exposed to threats that arrived through ordinary browsing. Legal and HR teams worried, rightly, about liability for what happened on company systems. Wanting visibility into all of it was not paranoia. It was responsible management of a powerful and unfamiliar tool.
So as monitoring tools grew more capable, many organizations reached for the most capable ones they could find. If a little visibility was good, total visibility seemed better. Screen recording, keystroke logging, and continuous activity capture promised to show everything, and for a while everything sounded like exactly what a careful employer should want.
What I have watched since is the slow arrival of the bill for that approach.
The more you capture, the more you have to carry. Screen and keystroke capture does not politely collect only the misconduct you were worried about. It sweeps up passwords, private messages, health information, and the personal lives of people who were doing nothing wrong. That is sensitive data you now own, have to secure, and may have to account for. In a growing number of states it comes with notification requirements. And it produces something no HR team I have ever met can actually use: hours of recordings per person per day that nobody has time to watch. A tool bought to create clarity ends up creating a liability to store and a haystack to search.
Meanwhile the thing organizations actually needed was sitting in plain view the whole time.
Every firewall, proxy, and secure web gateway already generates a record of the web traffic on the network. It is standard log data, the same kind of business record a company keeps as a matter of course. Read properly, it answers the question that started all of this, what are people doing on the web, without installing anything on anyone’s device and without recording a single screen or keystroke. I have come to describe this as analytics without surveillance, and I mean it precisely. You get the visibility, built on records you already keep, and you leave the surveillance behind.
That approach has three qualities the heavier model never had. It is agentless and less invasive by design, because it installs nothing on employee machines and captures no screens, no keystrokes, no audio, and no video, which means far less sensitive data collected and far fewer questions to answer about it. It produces defensible business records, consistent and repeatable, because it is built from the log data the organization already generates rather than from a recording someone has to vouch for. And it lets HR act on its own. When the records are already readable, an investigation does not have to wait in an IT queue, and the people responsible for policy can see what a person actually did without asking anyone to interpret raw logs for them.
That last point matters more than it sounds. For years the practical bottleneck was never capturing enough data. It was turning what had been captured into something a non-technical person could act on, cleanly and independently. Solve that, and you no longer need to watch people to understand what is happening. You only need to read, accurately, the record they already leave behind.
This is the work we have been doing at Wavecrest since 1996. Cyfin exists to take the web-use records your firewall already produces and turn them into clear, human-only web use reports that HR and management can read and act on themselves, with the automated background noise filtered out so what remains reflects what a person actually did. It was a somewhat contrarian idea for a long stretch of those thirty years. It looks less contrarian every month.
Here is where I think this goes. The next decade of employee monitoring will be less about watching people and more about reading the records you already keep. The organizations that get there first will carry less risk, review less noise, and make better decisions from cleaner information. After three decades of watching this field reach for more, I find it encouraging that the direction now is toward less. Less capture, less exposure, less intrusion, and, in the end, more of the clarity everyone was after in the first place.
Learn more about Cyfin web use reporting from Wavecrest Computing.