WorkMonitor for public sector
Accountability that survives an FOI request
A tamper-evident record of what was collected and who looked at it, retention you set per jurisdiction, and a published gap list instead of a badge nobody earned.
Free for two seats, no card.

Government
What changes in a public body
Pick a line and the page it happens on opens on the right.
- AKProof LedgerClient-grade proof.Search or ask…
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
Northlight StudioCertificatesVerifiable without an accountSigned from a finalised invoice. Your client checks it at verify.workmonitor.aiNo login, no back-and-forth. The verdict shows the signature, the hours and anything withheld — and neither you nor the worker can alter the record.540hCERTIFIED · 90 DAYSCERTIFICATECOVERSHOURSCLAIMSSTATE- cert_8f2a91verify.workmonitor.ai/c/cert_8f2a91Copy verify linkInvoice #2041 · August148h 20m24Valid
- cert_5d70c4Invoice #2038 · August96h 45m17Valid
- cert_1b93e7Shared redacted — 3 of 21 claims withheld, and the client is told soInvoice #2035 · July132h 10m21Valid
- cert_47c0aaInvoice #2031 · July74h 30m12Valid
- cert_e2d115Revoked 28 Aug — the reason is on the audit log, never on the public linkInvoice #2027 · June118h 05m19Revoked
- cert_9a64f3Invoice #2024 · June88h 15m14Valid
Revoking never deletes a certificate — it stays verifiable and reads as revoked.5 live · 1 revoked
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
- cert_8f2a91verify.workmonitor.ai/c/cert_8f2a91Copy verify linkInvoice #2041 · August148h 20m24Valid
- cert_5d70c4Invoice #2038 · August96h 45m17Valid
- cert_1b93e7Shared redacted — 3 of 21 claims withheld, and the client is told soInvoice #2035 · July132h 10m21Valid
- cert_47c0aaInvoice #2031 · July74h 30m12Valid
- cert_e2d115Revoked 28 Aug — the reason is on the audit log, never on the public linkInvoice #2027 · June118h 05m19Revoked
- cert_9a64f3Invoice #2024 · June88h 15m14Valid
Rollout
Deploying inside a public body
- 1
Start from the statutory position
Notice, legal basis and consultation duties come before the technology. There is written guidance for 32 jurisdictions, and it is guidance rather than legal advice.
- 2
Scope access to the structure
Roles bind to a node in the org tree, enforced on the server against the session rather than the URL, with multi-entity roll-up for arm’s-length bodies.
- 3
Make the trail tamper-evident
A hash-chained audit log and a data-access record that includes administrators, because the threat model here includes the person holding the credential.
- 4
Keep the exit open
Bulk data export and portability are shipped features, so the record survives a change of supplier rather than being hostage to one.
A system you have to vouch for vs. one that evidences itself
workmonitor.vsPublic-sector monitoring today
Answering an FOI request
With WorkMonitor
A hash-chained trail where an alteration breaks the chain and the break is detectable.
Public-sector monitoring today
Reconstruct what happened from logs nobody can prove were not edited.
Notice and objection
With WorkMonitor
Consent recorded against a version, a transparency view, and appeal with a right to human review.
Public-sector monitoring today
A policy circulated once, with no route to contest a decision.
Access scope
With WorkMonitor
Roles scoped to a node, with multi-entity roll-up across arm’s-length organisations.
Public-sector monitoring today
Admin or nothing across the whole body.
Retention
With WorkMonitor
Windows set per jurisdiction, with erasure and subject-access handling.
Public-sector monitoring today
A single default applied everywhere regardless of regime.
Vendor claims
With WorkMonitor
A published gap list. We do not claim certifications we do not hold.
Public-sector monitoring today
A wall of certification badges.
Leaving
With WorkMonitor
Bulk export and portability, shipped.
Public-sector monitoring today
An export request, a quote, and a delay.
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
- Active app and windowThe app in front, and its title
- Activity levelAn intensity number, 0 to 100
- ScreenshotsAbout every 5 min, blurred on device
- Idle detectionGaps over 10 min show as idle
- What you typeThe number only, never the words
- Apps on your deny list6 apps: no capture while in front
- Time you mark privateLeft out of measurement entirely
- Live screen viewOff for Northlight Studio
- JMJon M. opened your timelineWeek 36 · check-in1 Sep, 09:14
- SDSara D. opened your screenshots3 captures · 28 Aug28 Aug, 16:02
- JMJon M. exported your dataTimesheet CSV · August25 Aug, 11:30
- LMLena M. generated an AI summary of your dayCopilot · sent to our AI provider22 Aug, 14:47
What a public body gets to work with
- Consent management
- Employee transparency ("What We See")
- Capture controls / policy engine
- Scope Sentinel
Ask AI
Ask AI what the record shows
Answers drawn from the access chain, the notice record and the retention policy.
Pick a question above and WorkMonitor AI will answer from your team's real numbers.
- Today
- Insights
- Activity board
- Live screens
- Team
- Agents
- Integrity
- App categories
- Reports & digests
- Capacity
- AKAria K.Figma92Active
- JMJon M.Terminal78Active
- SDSara D.Slack61Active
- RPRavi P.Notion34Idle 11m
- LMLena M.Teams55In a call
- TVTomas V.Off shift0Off
The status meeting, already written
Status is normally assembled by asking. Here it is already: hours, activity, attendance and risk on one board, for one person or the whole company. Set the thresholds once and it tells you who needs you.
Jobs to be done
The jobs a public body runs here
- Monitor legally & stay compliantVersioned consent, a capture scope that cannot quietly widen, retention and DSAR handling, and written guidance for 32 jurisdictions before you roll out in one.
- Catch insider threats earlyEgress signals, anomaly detection and integrity checks on a hash-chained trail that records the investigators too, so the finding survives being examined.
- Track time automaticallyNo timer to start, no Friday reconstruction. Idle is split out rather than estimated, and approved hours reach payroll and invoicing without a re-key.
- Capture screenshots on your termsA randomised cadence, exclusions applied on the device, retention that expires, and the consent record and appeal route that keep the programme standing.
Where you operate
Public-sector monitoring law, country by country
- United States (federal)Federal law is permissive; the real constraints are state law and the NLRA.
- United KingdomThe ICO's 2023 monitoring guidance is the operative document, and it expects a DPIA.
- Canada (federal)Reasonableness is the statutory test, and the OPC applies a four-part necessity analysis.
- OntarioA written electronic monitoring policy is mandatory at 25+ employees, refreshed annually.
- GermanyThe works council holds a veto, and a productivity dashboard is enough to trigger it.
- FranceConsult the CSE first. Skipping it is the criminal offence of obstruction.
Straight answers
The questions we would ask in your position
Every answer here is the one you would get on a call. Open as many as you like; they stay open, so two can be held side by side.
No. WorkMonitor is pre-launch and holds no certifications of any kind; SOC 2 and ISO 27001 are in preparation. If accreditation is a procurement gate for you, this is the honest place to discover that rather than at stage two. What exists is a published control inventory with source references and an open gap list.
Not yet. Self-hosting is on the roadmap, not shipped, and data residency and bring-your-own-key encryption land with it. Stating that plainly is more useful to you than a maybe.
A self-view of what was collected, the notice version they were served, and a route to appeal a specific capture. Access to their data is itself recorded, so "who looked at this" is answerable to them as well as to you.
The audit chain is designed for exactly that: every access and governance change is attributable and re-verifiable through the API, and an altered or deleted entry breaks the chain visibly rather than disappearing. What is disclosed is a record, not a reconstruction.
Nearby
Teams with the same problem, from another angle
Take these with you
The software is the easy part of a rollout
Here is what we would send a manager doing one for the first time: how to read a productivity number, what to say to a remote team before anything is installed, and a policy you can adopt as written.
Point it at one team for a week.
Create the account, put the agent on a handful of desks, and leave it alone. On Friday you read the week instead of reconstructing it: hours against their projects, focus and idle per person, and the timesheets already filled in.
Free for two seats. No card, and no sales call to sit through.