User Activity Monitoring Software Built for Productivity, Security & Compliance
Track website, app, USB, & file sharing activity across your company devices, remote, hybrid, or in-office, and Citrix/RDS environments.
- Deploy on-prem or cloud
- Privacy-first controls
- Monitor, control & protect from one agent
- Works on Citrix, VDI, RDS, remote, and offline endpoints
*No credit card required · 14-day free trial · Deploys in under 15 minutes
User Activity Monitoring, defined
User Activity Monitoring is a practice used commonly by IT departments in organizations to record & analyze what people do on their company-owned devices. It includes tracking which websites the users visit, which applications they run on the devices, which files they share, which devices they plug in, and when they sign in or sign out.
It collects user activity as a time-spend audit trail so security, IT and compliance departments can detect insider threats, investigate incidents, prove regulatory compliance, and understand how work actually happens.
The term ‘User Activity Monitoring’ may mean different things to different teams. For example:
- To the security team, it means threat detection and forensic evidence.
- To IT team, it means asset & license visibilit
- To HR, or the operations team, it means productivity & policy adherence.
A good UAM tool serves all three from a single platform, which is why it is increasingly bought as a shared infrastructure rather than an individual department tool.
Key Takeaways:
- UAM is based on user-attributed endpoint telemetry, not network logs or simple login records.
- It is legal in the US, UK, and Canada on company-owned equipment when monitoring is disclosed and proportionate. See legal & ethical practice.
- Transparency works better than secrecy. Clear monitoring programmes build trust, improve security, and reduce internal resistance.
- Where your data lives matters. Self-hosted UAM keeps employee activity records within your own environment and jurisdiction, which can be especially important for UK and Canadian organisations.
- Scope creep is the biggest risk. Monitor work systems during working hours and collect only the data needed for a clearly defined purpose.
How user activity monitoring software works
Most UAM platforms follow the same three-part setup: a lightweight agent on the endpoint, a server that stores activity data, and a console where administrators review activity and manage policies. The key difference between vendors is where the server is hosted and, as a result, who controls the data.
1. The agent
A small client is installed on each Windows endpoint, server, or virtual desktop. It records activity locally and links it to the signed-in user, allowing it to work accurately on shared machines and multi-user Citrix or RDS environments.
Offline resilient: When a device leaves the network, the agent caches activity locally and syncs it once the device reconnects.
2. The server & database
Activity is stored in a database you control, either on a server in your data centre or in your own AWS, Azure, or private cloud environment. SQL Server is also supported for larger deployments.
This is the decision that matters: CurrentWare never receives or stores employee activity data.
3. The console
Administrators use a browser-based console to view dashboards and reports, manage alerts, and set policies. Users and OUs can be synced from Active Directory, different rules can be applied to different groups, and access can be protected with role-based permissions and two-factor authentication.
The data user activity monitoring captures
Each data signal can be enabled or disabled by the user group. Configure only the data you need for a specific purpose. This supports better privacy practices and helps meet requirements under UK GDPR and Canadian privacy laws.
| Activity signal | What is recorded | Primary purpose | Optional? |
|---|---|---|---|
| Web activity | Full URLs, domains, page titles, active vs idle time, content category | Security, productivity, filtering | Yes |
| Application usage | Application name, window title, launch/close time, active duration | Licence optimisation, productivity | Yes |
| Search queries | Terms entered into major search engines | Insider risk indicators | Yes |
| USB & removable media | Device connect/disconnect, device ID, files copied, created, deleted, renamed | Data loss prevention, forensics | Yes |
| File transfers | Movement to removable media, network shares and cloud storage; uploads/downloads | Data exfiltration detection | Yes |
| Screenshots | Scheduled or event-triggered desktop captures, tagged with app/site, time and machine | Investigation evidence | Yes |
| Logon / logoff & power | Sign-in, sign-out, startup, sleep, shutdown events | Attendance, time verification | Yes |
| Active vs idle time | Duration since last keyboard/mouse input, per app and per site | Genuine utilisation data | Yes |
| Bandwidth | Upload/download volume by user and site | Network capacity planning | Yes |
| Keystrokes | Not captured. CurrentWare does not include a keylogger. | — | Not offered by design |
Why no keystroke logging: Keystroke capture hoovers up passwords, private messages, and payment data, which creates a fresh liability inside the very tool you bought to reduce risk. URL, file transfer, and screenshot evidence answers investigative questions without that exposure. See our full reading.
UAM vs employee monitoring, DLP, UEBA and session recording
These terms overlap, and vendors often use them interchangeably. The practical differences matter when you are creating requirements or justifying a security investment.
| Category | Core question it answers | Typical buyer | Relationship to UAM |
|---|---|---|---|
| User activity monitoring (UAM) | What did this user do on this device, and when? | Security, IT, compliance | The base telemetry layer the others build on |
| Employee monitoring | How is the workforce using company time and tools? | HR, operations, managers | A workforce-facing framing of the same data |
| Data loss prevention (DLP) | Is sensitive data leaving, and can I block it? | Security, compliance | Enforcement. UAM detects; DLP prevents |
| UEBA / behaviour analytics | Is this behaviour abnormal for this person? | SOC, threat detection | An analytics layer applied on top of UAM data |
| Session recording | Can I replay exactly what happened on screen? | Security, audit, PAM teams | A high-fidelity subset of UAM evidence |
| Keystroke logging | What exactly was typed? | Rarely justifiable | Adjacent but high-risk (CurrentWare does not offer it) |
Most teams need two of these together: monitoring to see risk, and control to stop it. The CurrentWare Suite offers all: BrowseReporter for activity monitoring, AccessPatrol for device control and DLP, BrowseControl for web and app blocking, and enPowerManager for logon and power tracking.
Use UAM to stop data leaving before it becomes a breach
Trusted insiders already have access to sensitive information. Monitoring makes that access visible, so you can detect suspicious activity, trigger alerts, and maintain evidence.
Detect insider threats and data theft
The weeks before someone resigns can be a high-risk period. UAM provides file movement and device activity history, helping you spot suspicious behaviour instead of trying to piece together what happened later.
- Track and restrict file transfers to USB drives, network shares, and cloud storage
- See which files were copied, created, deleted, or renamed on removable media
- Review historical activity for unusual patterns during offboarding
See exactly what happened with screen capture
When an activity log raises a question, a screenshot can provide the missing context. Capture screens on a schedule or only when a rule is triggered, so you are not storing images you do not need.
- Capture high-resolution or compressed screenshots at an interval you choose
- Tag each image with the site or application in use, timestamp, and machine
- Use optional live desktop viewing during active investigations
Get alerted when a policy is broken
Alerts turn activity monitoring into an active control. Send them to a security inbox, shared mailbox, or SIEM when a defined rule is triggered.
- Trigger alerts for unauthorised device connections, blocked site categories, or banned applications
- Automatically include the supporting screenshot and activity log
- Maintain evidence if an incident becomes a disciplinary or legal matter
Extend oversight to contractors and third parties
Vendors, consultants, and managed service providers can have privileged access without going through the same controls as employees. UAM helps close that gap without disrupting their work.
- Apply stricter device and web policies to third-party groups
- Compare invoiced hours with recorded activity
- Restrict data transfers to removable media and cloud storage for external accounts
Block exfiltration paths, not just log them
Monitoring shows you what happened. Controls can stop it from happening. Both can be managed through the same console and agent.
- Set full access, read-only access, or no access for USB and removable storage
- Allow only approved devices using a hardware allow-list
- Block file transfers by extension or filename, as well as uploads and downloads by file type
- Close high-risk TCP/UDP ports to reduce the potential for data exfiltration
Why insider activity is the hardest risk to see
External attackers first need to get inside. Insiders already have access, which is why detection time can have a major impact on the cost of an incident.
70%
Intellectual property theft occurs before an employee announces their resignation.1 Without device controls, sensitive files can be copied to a USB drive with a simple drag and drop.
$17.19M
average annual cost to organisations where insider incidents took more than 90 days to contain.2 Activity data can help reduce containment time.
35%
of analysed data breaches involved internal actors.3 Perimeter security tools cannot see this activity.
See UAM running on your own endpoints
Available across US, UK and Canadian time zones.
The same data pays for itself in reclaimed time and licences
UAM is often purchased for security but can also deliver operational value. Activity data shows how employees actually use websites and applications and highlights software your organisation is paying for but not using.
Separate active time from idle time
An open browser tab does not necessarily mean someone is working. CurrentWare distinguishes active use from background sessions based on keyboard and mouse activity, with an idle threshold you define.
- See active, idle, and total time by user, website, and application
- Classify sites and applications as productive, unproductive, or neutral for your business
- Compare in-office, hybrid, and remote work patterns using actual activity data
Verify time with logon and session records
Combine idle-time tracking with logon and logoff auditing to create a clearer record of when work started and stopped. This can support hybrid attendance policies and contractor invoicing.
- Track sign-in, sign-out, startup, sleep, and shutdown events by machine
- Compare timesheets with recorded sessions
- Confirm that remote staff are active during agreed working hours
Cut software spend with real usage data
Most licence renewals are based on estimates. Application usage reports provide actual usage data, including last-used dates and utilisation rates for each application.
- See utilisation rates for individual applications and SaaS tools
- Find subscriptions that have not been used in 90 days
- Right-size licence counts before renewal discussions
Deploy it where your data is allowed to live
Many UAM vendors are SaaS-only, meaning employee activity data leaves your environment and is stored in the vendor’s cloud. For regulated US organisations, UK businesses completing a DPIA, and Canadian public-sector organisations with provincial data residency requirements, this can become a procurement issue.
CurrentWare offers three deployment options and does not hold your activity data in any of them.
On-premises
Host the server and database inside your own data centre. Nothing leaves your environment. Fully air-gapped networks with no outbound internet access are supported, which can be important for defence, research, and critical infrastructure environments.
Self-managed cloud
Install the CurrentWare Server in your own AWS, Azure, or private cloud tenant. You choose the region, keeping data residency under your control, including UK-only or Canada-only hosting.
Hybrid & remote
Monitor office, hybrid, and fully remote users from one console. Offsite endpoints continue enforcing policies and cache activity while disconnected. Once they reconnect, activity syncs through VPN, port forwarding, or your cloud instance.
Built for Windows, Citrix, RDS and VDI
CurrentWare monitors Windows desktops, servers, and virtual machines. The agent identifies individual users on shared and multi-session hosts, allowing different policies to be applied to different groups on the same server.
Physical & remote endpoints
Monitor Windows desktops and laptops whether they are on or off the network, including devices connected through VPN or DirectAccess.
Citrix & Terminal Server
Support for Citrix Virtual Apps & Desktops, Remote Desktop Services, and Terminal Servers with activity attributed to individual users.
VDI, persistent & non-persistent
Support self-hosted VDI as well as DaaS platforms such as Amazon WorkSpaces and Azure-hosted desktops.
Hypervisors
Support for VMware, Hyper-V, Parallels, VirtualBox, Oracle VM, and Virtual-PC.
Also supported
- Active Directory integration: Import users, OUs, and security groups directly into the console.
- SQL Server: Support enterprise-scale deployments and existing DBA-managed backups.
- Air-gapped networks: Run a fully standalone installation with no outbound internet requirement.
- SIEM export: Send activity data to your existing security stack. SIEM integration →
- Transparent or stealth mode: Run visibly with user notice or silently when required for an investigation.
Where user activity monitoring supports a compliance obligation
Most security frameworks require audit logging and accountability for user actions on systems containing regulated data. UAM can provide a direct way to support these controls on endpoints.
The table below maps common requirements to the CurrentWare capabilities that can provide evidence. Use it as a starting point for discussions with your assessor, not as legal advice.
| Framework | Region | Relevant requirement theme | How UAM helps |
|---|---|---|---|
| NIST 800-171 | US (CUI/DoD supply chain) | Audit & accountability; media protection | Per-user activity logs, removable media control and transfer records |
| CMMC | US (defence contractors) | Audit logging, media protection, incident response | Retained audit trail, USB allowed-lists, alerting and evidence export |
| HIPAA Security Rule | US | Information system activity review; device & media controls | Reviewable access and file-movement logs on endpoints handling ePHI |
| PCI DSS | US · UK · CA | Track and monitor all access to cardholder data environments | Endpoint activity logs, session evidence, restricted media use |
| ISO/IEC 27001 | Global | Logging, monitoring and removable-media controls | Continuous activity capture with role-based console access |
| Cyber Essentials | UK | User access control; secure configuration | Group-based policy enforcement and usage verification |
| UK GDPR / EU GDPR | UK · EU | Lawful basis, proportionality, data minimisation, DPIA | Granular on/off per data type, retention limits and self-hosted residency |
| PIPEDA & provincial acts | Canada | Reasonable purpose, notice, accountability for personal information | Configurable scope plus in-country hosting under your own control |
| NERC CIP | US · CA (bulk power) | Access monitoring and transient device controls | Monitoring and device control on operator workstations, incl. air-gapped |
How to implement user activity monitoring in six steps
The technical installation can take minutes. The programme design is what determines whether the implementation works. This is the approach we see across US, UK, and Canadian deployments.
Step 1: Define the purpose before the policy
Start by documenting what you want to achieve, whether that is reducing insider risk, cutting licence waste, verifying contractor activity, or addressing an audit finding. Every decision about what to collect should follow from that purpose.
A clearly defined purpose is also important under UK GDPR and Canadian privacy laws.
Step 2: Decide what you will and will not collect
Match each data type to a specific purpose. If screenshots are not needed, do not enable them. Define a retention period and automatically delete older records rather than keeping everything indefinitely.
Step 3: Write and publish an acceptable use and monitoring policy
Explain what is monitored, why it is monitored, who can access the data, how long it is retained, and how it will be used. Our workplace monitoring policy template and internet use policy template can provide a starting point.
Step 4: Notify employees before you switch it on
Brief managers first, then notify the wider team in writing before deployment. In several US states, across the UK, and in Canada, notice is either legally required or considered best practice. It can also make the rollout much smoother.
Step 5: Pilot on one group, then expand
Start with one department or Citrix host. Check that reports are accurate, adjust productivity classifications and alert thresholds, then roll the deployment out to the rest of the organisation through Active Directory groups.
Step 6: Review at a cadence, not on impulse
Review aggregated trends weekly or monthly. Investigate individual activity only when a rule is triggered or an investigation is opened.
Protect access to the console with role-based permissions and two-factor authentication so the monitoring data is controlled properly.
User activity monitoring law in the US, UK and Canada
For monitoring laws in the US, UK, and Canada, the specific requirements vary by jurisdiction, and getting them wrong can create a compliance issue for both security and HR.
Disclaimer: This is general information, not legal advice. Consult legal counsel in your jurisdiction before deploying monitoring software.
United States
Monitoring employer-owned equipment is broadly permitted at the federal level, with the Electronic Communications Privacy Act governing the interception of communications. Several states have specific written-notice requirements for electronic monitoring, including New York, Connecticut, and Delaware. Other states regulate areas such as biometric or location data separately.
Practical rule: Provide written notice to employees and obtain acknowledgement during onboarding, regardless of the state where you operate.
United Kingdom
Monitoring can be lawful under UK GDPR and the Data Protection Act 2018 when you have a valid lawful basis, usually legitimate interests, and can demonstrate that the monitoring is necessary and proportionate.
The ICO’s guidance on worker monitoring emphasises transparency and data minimisation. Higher-risk monitoring may also require a Data Protection Impact Assessment.
Practical rule: Complete a DPIA, document your legitimate interests assessment, and be prepared to explain why each type of data is necessary.
Canada
PIPEDA requires organisations to collect personal information for purposes that a reasonable person would consider appropriate, with knowledge and consent. Provincial privacy laws add further requirements, including Alberta and British Columbia PIPA, Québec’s Law 25, and Ontario’s requirement for employers above a specified headcount to maintain a written electronic monitoring policy.
Practical rule: Publish a written monitoring policy, keep data collection tied to a reasonable business purpose, and check applicable provincial data residency requirements.
6 Best User Activity Monitoring Practices
Notify, don't surprise
Covert monitoring should be the exception and tied to a specific investigation, not the default approach.
Monitor work systems during work time
Personal devices and activity outside working hours can create additional privacy concerns.
Collect the minimum
Disable data types that are not needed for a stated purpose.
Control access to the data
Monitoring records can contain sensitive personal information. Use role-based permissions, 2FA, and access logs.
Set retention and enforce it
Indefinite retention can be difficult to justify to regulators and increases storage costs.
Aggregate before you individualise
Use team-level trends for management decisions and individual records when there is a specific reason to investigate.
How CurrentWare compares on the things buyers actually shortlist on
Capability-level comparison based on publicly documented product information at the time of writing. Vendors can change their capabilities, so verify current functionality directly before purchasing.
| Capability | CurrentWare | ActivTrak | Teramind | Insightful |
|---|---|---|---|---|
| True on-premises deployment | Yes | Cloud only | Available | Available |
| Self-hosted in your own cloud tenant | Yes | No | Varies by plan | Varies by plan |
| Vendor never receives activity data | Yes | No | On-prem only | On-prem only |
| Air-gapped / offline network support | Yes | No | On-prem only | No |
| Citrix, RDS & multi-session VDI | Yes | Partial | Yes | Partial |
| USB & removable device control | Yes | No | Yes | No |
| Web & application blocking | Yes | Limited | Yes | No |
| Screenshot & live desktop view | Yes | Limited | Yes | Yes |
| No keystroke logging (by design) | Yes | Yes | Keylogging offered | Yes |
| macOS & Linux agents | Windows only | Yes | Yes | Yes |
Monitoring Citrix Workspace activity at The Coding Network
“There was a gap in the data we had and we wanted to get something in place before there was an incident. CurrentWare has really made our Citrix rollout a lot easier from a tracking and management perspective.”
The Coding Network, medical coding services
Frequently asked
Frequently Asked Questions About CurrentWare’s User Activity Monitoring Software
-
No, CurrentWare cannot access your employee’s computer monitoring data. CurrentWare’s software does not send your user’s computer usage data to CurrentWare. They are installed and managed by your organization.
All of the data collected by CurrentWare’s software is stored on a database that is installed in your organization’s data center or cloud service provider.
With CurrentWare’s on-premises & self-managed cloud deployment options, you’re in complete control of your data.
- Sensitive employee data stays secured to your standards rather than being sent to a third party.
- Maintain data localization and residency compliance requirements by keeping employee data exactly where it needs to be.
- Retain auditable records of user activity for as long as you need
For more information please refer to our Terms of Service.
-
The CurrentWare Suite can be deployed on-premises or on a cloud platform of your choice. Both deployment option are compatible with remote workers with a few configuration changes.
Learn More:
-
Yes. CurrentWare’s software client collects user activity data independent of the browser’s browsing history.
Internet browsing data will remain intact for use in reports and dashboards even if the user deletes their web browsing history in their browser or uses a private browsing function such as Incognito Mode On Google Chrome, Private Browsing On Mozilla Firefox, and InPrivate Browsing Window On Microsoft Edge.
-
Yes. CurrentWare’s computer monitoring software allows you to monitor remote workers through a variety of deployment options such as an offsite mode that works without access to the internet, connecting through a VPN, port forwarding, or by installing it on a cloud platform of your choice.
-
The free trial for all of CurrentWare’s computer monitoring software solutions are fully functional. You can deploy it on up to 10 computers for 14 days. If you need more time or more computers to properly evaluate CurrentWare in your organization, reach out to our sales team.
-
CurrentWare is committed to the security of its platform, its users and their data.
- All of the data collected by CurrentWare’s solutions is stored in your organization’s data center or cloud service provider; the data is not sent to CurrentWare.
- The web console cannot be accessed without a username and password. For an added layer of authentication security you can enable two-factor authentication.
- You can selectively enable/disable what data is tracked and delete old records automatically.
For a complete overview of the security measures that CurrentWare has in place, check out the CurrentWare platform security overview page.
-
Yes! Since CurrentWare runs on your own server, and doesn’t ping back to a remote server elsewhere, CurrentWare can run on air-gapped networks without access to the outside internet. This means it an excellent fit in research facilities or other high security environments.
To deploy CurrentWare without internet access you can do a Standalone Setup with all components on the same PC, or you can install the central management software within your intranet to centrally manage PCs within an air-gapped network.
When your employees disconnect from your network the client agent will store their activity data locally on their computer. Once they reconnect to your network their data will be synced to the CurrentWare server.
Note: If you wish to get activity data from employee computers that are outside of the network, they will need to be able to communicate with the CurrentWare Server. Once a connection is reestablished you will receive your employee’s computer usage data and any CurrentWare policy updates will take effect.
Learn More: Will CurrentWare work if someone is not connected to our network or the internet?
-
No. Keyloggers are a security risk due to their ability to capture sensitive information such as passwords. CurrentWare’s UAM tools provide less invasive and more secure alternatives that provide more valuable insights such as URL tracking, file transfer monitoring, and desktop screenshots.
Learn More: Should You Use Keyloggers on Employee Computers?
-
CurrentWare uses a client-server model where the client is installed on the desktop that you’d like to track and apply security policies to. The client communicates with the management server that you install on a computer, server, or virtual machine you control.
The client agent can differentiate the users logged into the remote desktop servers so that you can apply different internet and device restrictions on different groups of users.
CurrentWare’s Citrix user activity monitoring software is supported on desktop computers, virtual machines (VMs), and servers running the Windows operating system.
In addition, all CurrentWare components are compatible with Remote Desktop Services (RDS) or Terminal Servers (TS).
So long as the underlying operating system is a version of Windows that is supported by CurrentWare, your users can be monitored.
This means that you can audit user activity on Desktop as a Service (DaaS) providers such as Amazon Workspaces and Citrix, self-hosted Virtual Desktop Infrastructure (VDI), or physical endpoints that are being accessed through remote desktop, DirectAccess, or a VPN.
CurrentWare is known to be compatible with the following virtualization software:
- VMware
- Parallels
- VirtualBox
- Oracle VM
- Virtual-PC
- Hyper-V
In addition, CurrentWare integrates with Active Directory, allowing you to import your Windows users and OUs directly from your Active Directory onto the CurrentWare Console.
Learn More: CurrentWare for Terminal Server/VDI/Remote Desktop Services Compatibility