WorkMonitor.

Use case · Insider risk & data egress

See the exfiltration while it is still a pattern

You usually hear about a leak from somewhere else. Egress signals, anomaly detection and integrity checks land on a trail an admin cannot quietly edit, so a suspicion becomes a case.

Free for two seats, no card.

Catch insider threats early
Doing itself, one step at a time.
0 of 4
  1. Collect the signalsEgress signals, access patterns and integrity checks stream in alongside ordinary activity, under the same consent and capture policy.
  2. Surface the anomalyThe anomaly feed raises what departs from the pattern, with the day reconstruction available to see the context around it.
  3. Investigate on the recordEvery step of the investigation is itself recorded on the hash-chained access log, which is what makes the finding usable later.
  4. Hand it to the security stackSIEM export, in beta, carries the signal into the tooling your security team already works in.
What it leaves behind

Catch insider threats early

Insider risk work that survives being audited itself

Every line here opens the screen it happens on. Judge the job on what it puts in front of a manager, not on the sentence describing it.

  1. Export
    Data out, and every export audited
    New exportDaily rollupsCSV3 Aug – 2 Sep (UTC)Owner onlyDownload export
    EXPORTREQUESTED BYSIZESTATE
    • Daily rollupsCSV5 Aug – 2 Sep · 1,260 rowsAKAria K.412 KBReady
    • Subject data export · Lena M.Subject requestJSONHer whole footprint · 2,140 rowsAKAria K.1.8 MBReady
    • Activity samplesConsent-gatedNDJSON19 Aug – 2 Sep · 486,220 rowsAKAria K.68%Running
    • TimesheetsCSVWeeks 33–36 · 168 approved rowsJMJon M.46 KBReady
    • Data egress · Ravi P.CSVLast 90 days · 74 rowsSDSara D.12 KBExpired
    • Daily rollupsCSV1 – 31 Jul · 1,302 rowsAKAria K.430 KBExpired
    A finished file is held for 24 hours, then removed — an expired export is requested again, not recovered. No export reaches past the capture retention window.Range capped at 366 days
    Taking data out is itself an access event: every export writes an audit entry, and one row per person in it.6 exports in 7 days

How it works

How a signal becomes a case

  1. 1

    Collect the signals

    Egress signals, access patterns and integrity checks stream in alongside ordinary activity, under the same consent and capture policy.

  2. 2

    Surface the anomaly

    The anomaly feed raises what departs from the pattern, with the day reconstruction available to see the context around it.

  3. 3

    Investigate on the record

    Every step of the investigation is itself recorded on the hash-chained access log, which is what makes the finding usable later.

  4. 4

    Hand it to the security stack

    SIEM export, in beta, carries the signal into the tooling your security team already works in.

Start free

A log you have to trust vs. a trail that proves itself

workmonitor.vsConventional activity logging

  1. If an admin covers their tracks

    With WorkMonitor

    The trail is hash-chained and append-only. A removal breaks the chain, and the break is detectable.

    Conventional activity logging

    They can. Deleting rows from a log table leaves no evidence that rows were deleted.

  2. Who watches the investigator

    With WorkMonitor

    Every access to a person’s record is logged, investigators included, and shown to the subject.

    Conventional activity logging

    Nobody. Investigative access looks identical to no access at all.

  3. Signal quality

    With WorkMonitor

    An anomaly feed built on the same analytics as the productivity picture, so unusual is measured against a baseline.

    Conventional activity logging

    An alert per event, which trains everybody to close the tab.

  4. Tampering with the evidence

    With WorkMonitor

    Integrity and anti-cheat signals detect it, and downgrade the tier of any proof record built on that activity.

    Conventional activity logging

    A cooperative user can idle-jiggle or spoof activity and nothing notices.

  5. Fitting the security stack

    With WorkMonitor

    SIEM export in beta, plus a typed v1 API and partner webhooks, so this is a source rather than a destination.

    Conventional activity logging

    One more console with its own login and its own notion of an incident.

  6. Investigating without creating a second problem

    With WorkMonitor

    Subjects keep a transparency view and a dispute route with a right to human review, which is what stops a finding being thrown out along with the process that produced it.

    Conventional activity logging

    The investigation runs entirely outside anything the subject can see or contest, and the dismissal it supports is argued on process rather than on facts.

Integrity
Anomalies flagged for a person to weigh
TeamYou
All kindsAll severities

We record only the flag itself — a matched tool name or a synthetic-input pattern. Never a list of what is running on a device.

6signals, most serious first
  • HighMouse JigglerCheat-tool detectedLMLena M.14:02
  • HighImpossible cursor velocitySynthetic inputRPRavi P.11:48
  • HighAuto ClickerCheat-tool detectedTVTomas V.09:26
  • MediumZero variance cadenceSynthetic inputSDSara D.Sep 1 22:41
  • MediumPeriodic cadenceSynthetic inputJMJon M.Sep 1 18:20
  • MediumZero variance cadenceSynthetic inputLMLena M.Aug 31 16:54
Everyone sees the checks raised on them the moment they happen — high signals notify them at once.One signal per pattern, per person, per 6 h

Everything behind insider-risk detection

  • Alerts & anomaly feed
  • Integrity / anti-cheat signals (also raises Proof Ledger tier)
  • Reports & delivery channels + verified-hours digests

Ask AI

Ask AI what looks unusual

Answers grounded in the anomaly feed and the access log, including a record of this question having been asked.

What departed from the pattern this week?

Pick a question above and WorkMonitor AI will answer from your team's real numbers.

Activity board
Who is working, on what, right now
PERSONINFOCUSSTATE
  • AKAria K.Figma92Active
  • JMJon M.Terminal78Active
  • SDSara D.Slack61Active
  • RPRavi P.Notion34Idle 11m
  • LMLena M.Teams55In a call
  • TVTomas V.Off shift0Off
4 of 6 active · 42 apps seen todayUpdated just now

The status meeting, already written

Status is normally assembled by asking. Here it is already: hours, activity, attendance and risk on one board, for one person or the whole company. Set the thresholds once and it tells you who needs you.

Where you operate

Investigating lawfully, by jurisdiction

Straight answers

The questions we would ask in your position

Every answer here is the one you would get on a call. Open as many as you like; they stay open, so two can be held side by side.

5 questions
Ask us something else

Take these with you

The software is the easy part of a rollout

Here is what we would send a manager doing one for the first time: how to read a productivity number, what to say to a remote team before anything is installed, and a policy you can adopt as written.

Point it at one team for a week.

Create the account, put the agent on a handful of desks, and leave it alone. On Friday you read the week instead of reconstructing it: hours against their projects, focus and idle per person, and the timesheets already filled in.

Free for two seats. No card, and no sales call to sit through.