##Why this exists
Device management tooling sits one design decision away from staff surveillance. We have made that decision in the agent - there is no screen capture, no input capture and no file reading - but the policy matters too, because it tells you what we will not build next and what we will act on if a customer tries to get there another way.
##Devices you may enrol
You may enrol a device where all three of the following are true.
- Your organisation owns it, or you administer it under a written agreement with whoever does.
- The person who uses it has been told the agent is there and what it collects. The never collected list in the privacy notice is written to be quoted directly in an internal note.
- Any obligation you have to consult staff representatives before deploying monitoring software has been met.
Personal devices are the awkward case. Enrolling someone's own laptop requires their informed and freely given agreement, and "freely given" does a lot of work in an employment relationship. Our view is that a personal device is better recorded as a manual asset, which costs nothing and carries no agent.
##Not for watching people
You must not use the service, or attempt to use it, to monitor individual behaviour, productivity or activity. Specifically:
- Do not use check-in timestamps or uptime as a proxy for working hours or attendance. They exist to tell you whether a device is reachable.
- Do not use the installed software list to investigate a person's private interests.
- Do not use diagnostic actions to gather information about an individual rather than a fault.
- Do not combine exported data with other systems to build an activity or performance profile of a named person.
We cannot see inside your workspace to police this, and we are not pretending otherwise. What we can do, and have done, is leave out the capabilities that would make it easy. There is no activity score to export because there is no activity score.
##Using approvals properly
An approval is a statement that a named person authorised a named action on a named device. It is the record you will rely on if an action goes wrong, and it is worth nothing if it is rubber-stamped.
- Do not share an admin account so that approvals cannot be attributed to a person.
- Do not use a standing approval to cover a scope you have not actually considered. They are bounded by product, ring and severity for exactly this reason.
- Do not approve an action against a device you have no authority over, including a client's device outside your contract with them.
##Prohibited use
You must not use the service to:
- Enrol devices you have no authority over, or enrol a device covertly
- Attempt to reach another customer's workspace, or to probe for a way in
- Circumvent the approval requirement, or attempt to extend the agent's capability set
- Remove, alter or disable the agent's certificate pinning or version reporting
- Attempt to delete or alter audit log entries
- Store unrelated personal data in ticket or asset fields because they are convenient free-text boxes
- Resell, sublicense or white-label the dashboard itself as your own product
- Breach any law applicable to you, or help anyone else do so
- Interfere with the service's operation, including load testing against our infrastructure without written agreement
##Intake channels
Intake addresses and WhatsApp numbers are for your organisation's own IT requests. They are not for marketing lists, bulk inbound mail, or forwarding a general-purpose mailbox that receives unrelated correspondence.
If you forward a mailbox that also receives customer enquiries or invoices, that content ends up in a ticket system your technicians can read. That is a problem you have created for yourself, and the fix is a dedicated address rather than a filter.
##Fair use of capacity
There are no published rate limits on normal use, because normal use does not need them. We do reserve the right to throttle or ask you to change behaviour where usage affects other customers - for example API polling far in excess of the fifteen-minute agent cycle, or automated exports of the entire workspace on a loop.
If you have a legitimate need for a higher rate, tell us. It is nearly always possible, and asking is faster than being throttled.
##Service providers
If you manage client organisations through the service, every obligation on this page applies to each client org you operate, and you are the one who has to be able to demonstrate it.
- Hold written authority from each client to deploy the agent and process their data before you enrol a single device.
- Assign technicians to the client orgs they actually work on. Access starting at nothing is deliberate.
- Remove departing technicians from every org promptly. Your own leaver checklist does this in one pass, and each client org records that it happened.
- Do not use aggregate cross-client views to share one client's information with another.
##Reporting a problem
If you believe the service is being used against this policy - including by your own employer or a service provider managing your devices - get in touch through the contact page. Tell us what you have observed. We will look into it and we will not identify you to the workspace concerned.
If you have found a security vulnerability, report it the same way with enough detail to reproduce it. We will acknowledge within two business days, and we will not pursue anyone who reports a genuine finding in good faith without accessing or altering other customers' data.
##How this is enforced
Most of this policy is enforced by what the product does not do. Where we need to act, the response is proportionate: a conversation first, then a specific requirement to change something, then suspension if it is not changed.
We will suspend immediately and without notice only where use is unlawful, where it puts other customers at risk, or where devices have clearly been enrolled covertly. In every other case you will hear from us before anything is interrupted.
