Four templates an organization adapts and issues to its own people before enrolling the first endpoint. They cover the relationship between an employer and its workforce, which sits alongside — and does not replace — the Data Processing Agreement between that organization and Orchard.
Fields shown as [LIKE THIS] must be completed before issue. Several of them — retention period, who may access the data, whether staff can opt out — decide whether the deployment is defensible, so decide them deliberately rather than filling a default. Requirements differ by jurisdiction: some regions require written notice before monitoring begins, others require agreement with an employee-representative body before a system capable of monitoring behaviour is introduced at all. These are a starting point for counsel in each jurisdiction where endpoints will be enrolled, not legal advice.
Document 1 — Employee notice
Issued to everyone whose device will be enrolled, before enrollment begins.
Notice: workplace software analysis
Effective [DATE] · Issued by [COMPANY]
From [DATE], [COMPANY] is deploying software called Orchard to [WHICH TEAMS OR DEVICES]. This notice explains what it records, what it does not, how long we keep it, and what we will and will not do with it.
Why we are doing this. Much of the work here is repetitive and undocumented, and we cannot currently see which procedures take the most time or where effort is duplicated. Orchard observes how work is actually performed across applications so we can identify the tasks worth simplifying, documenting, or automating. [ADD YOUR OWN SPECIFIC REASON]
What it records — enough to understand and repeat a procedure:
- The application in the foreground and its window title, sampled every few seconds
- Whether the session is active or idle
- The on-screen control you interact with, by its accessibility name and type
- The value in that field, where the operating system exposes it
- Text pasted from the clipboard, during an active recording only
- Basic device health telemetry
What it never records — built into the software, not promised in a policy:
- No screenshots and no screen recording. Nobody can see your screen.
- No keystroke logging. It is not a keylogger, and there is no setting that enables one.
- No passwords. Fields the operating system marks as password fields are skipped on the device, before anything is sent. [IF CREDENTIAL CAPTURE IS ENABLED, DESCRIBE IT HONESTLY HERE INSTEAD]
Please read the fourth "records" item carefully: if you type a customer's address into a form, that text can be recorded. This is how the software understands a procedure well enough to document or repeat it.
Personal use of a work device. If you use this device for something personal, the application name, window title and any text you enter can be recorded in the same way as work activity. We are not looking for it and we will not go looking for it, but we cannot promise it will never appear. If you would rather keep something entirely out of scope, use a personal device. If something personal does surface and you want it removed, contact [NAME, ROLE, EMAIL] and we will delete it — you do not have to explain why.
How long we keep it. Captured activity is deleted automatically after [90] days. [COMPANY] can request earlier deletion at any time.
Who can see it. Access is limited to [NAMED ROLES OR INDIVIDUALS]. Every access is written to an audit log that cannot be edited. Orchard's own staff can reach customer data only through a separate audited system, and each read is logged.
What we will not use it for. The commitments in our Acceptable Use Statement, issued alongside this notice, are binding on [COMPANY]. In summary: this is not used to discipline individuals, rank people against one another, or make decisions about anyone's employment.
Questions. Contact [NAME, ROLE, EMAIL]. A longer question-and-answer sheet is attached. [IF APPLICABLE: This deployment has been agreed with [EMPLOYEE REPRESENTATIVE BODY].]
Document 2 — Deployment scope and configuration
The settings decided before enrollment, each with a reason that can be given to an auditor or an employee representative.
| Decision | Starting position | Reason |
|---|---|---|
| Scope | [NAMED TEAM] only | A defined first group is far easier to justify than the whole estate. Unenrolled devices are not observed at all. |
| Capture tier | The lowest tier that answers the question | Field values materially increase sensitivity. If application timing and window titles answer the question, do not collect values. |
| Credential capture | OFF | Off by default. Leave it off unless a named procedure requires it and the decision is documented — enabling it changes the lawful-basis analysis. |
| Retention | [90] days | Orchard's default, configurable per deployment. Set the shortest period that still answers the question. |
| Console roles | Read-only for all but [1–2 ADMINS] | Owner / admin / read-only are enforced per workspace. Least privilege is the most persuasive control to show staff. |
| Multi-factor | REQUIRED workspace-wide | Owners can require it for everyone; anyone not enrolled is walked through setup before regaining console access. |
| Autonomy ceiling | Supervised — not unattended | Nothing acts on a system without a person approving it. Raise this only once a procedure has proven itself. |
| Accountable owner | [NAME, ROLE] | One named person who answers questions and can order deletion. Staff need a name, not a shared mailbox. |
Removing a device or a person from scope. Unenroll the device in the console; observation stops at that point. To remove data already captured, request deletion through the accountable owner. Raw captured activity can be exported or deleted at any time under the Data Processing Agreement.
Before the first endpoint is enrolled:
- The employee notice has been issued and its effective date has passed
- [IF APPLICABLE] The employee representative body has agreed
- The acceptable use statement has been approved by [HR / LEGAL] and published
- The Data Processing Agreement is signed, and the retention figure in it matches the figure in the notice
- An accountable owner is named and staff know who it is
Document 3 — Acceptable use statement
The employer's binding commitments about what the data is for. Issue it only if every line is true.
[COMPANY] — how Orchard data is used
We use it to:
- Identify procedures that repeat often enough to be worth documenting or automating
- Understand how work is distributed and where the load falls unevenly
- Decide which tools are actually used, and which licences we should stop paying for
- Produce written documentation of procedures that currently exist only in someone's head
- [ADD OTHER SPECIFIC PURPOSES]
We will not use it to:
- Discipline an individual, or as evidence in a disciplinary process
- Rank, score or compare named individuals against one another
- Make decisions about pay, promotion or continued employment
- Monitor anyone in real time, or check whether a person is at their desk
- Read personal messages or browsing, or act on personal content that surfaces incidentally
- [ADD OTHER COMMITMENTS YOU WILL KEEP]
If something personal appears. It will occasionally happen. Anyone who encounters personal content in Orchard must stop, not share it, and report it to [ACCOUNTABLE OWNER], who will delete it. Acting on personal content discovered this way is a breach of this statement, and will be treated as a conduct matter for the person who acted on it.
The one exception. [COMPANY] may be required to preserve or produce records in response to a legal obligation, a regulatory request, or a formal investigation into a specific and serious allegation. Where that happens it is authorised by [ROLE] and recorded. This is not a general exception and cannot be used to route around the commitments above. [CONFIRM THIS MATCHES YOUR EXISTING INVESTIGATION POLICY]
Review. This statement is reviewed [EVERY SIX MONTHS] with [HR / EMPLOYEE REPRESENTATIVES]. Anyone may raise a concern with [ACCOUNTABLE OWNER] at any time, without giving a reason.
Document 4 — Questions your team will ask
The questions that actually get asked, with answers that hold up when tested.
Is this a keylogger? No. Keystroke text is not recorded at any setting, and there is no configuration that enables it. What is recorded is the control you interacted with and, at the higher capture tier, the value in that field — which is different from a record of every key you press.
Can anyone see my screen? No. No screenshots and no screen recording, at any tier. Nobody is watching a live view.
Can you see my passwords? No. Fields the operating system marks as password fields are skipped on your device before anything leaves it. [IF CREDENTIAL CAPTURE IS ENABLED, REPLACE THIS WITH THE TRUTH ABOUT IT]
Can you read what I type into an email or a ticket? Text entered into a field can be recorded, yes — that is how the software learns a procedure. It is stored as part of a work record rather than read as correspondence, access is limited to [NAMED ROLES], and every access is logged. If that is uncomfortable for a particular task, raise it with [ACCOUNTABLE OWNER] and we will look at the scope.
What about personal banking, or a private message at lunch? On an enrolled work device the application and window title are recorded, and text entered into fields can be too. We do not look for it, and using it is a breach of the acceptable use statement. If you want something genuinely out of scope, use a personal device. If something personal has been captured and you want it gone, ask — you will not be asked why.
Is someone watching me right now? No. Activity is sampled and reviewed as patterns across a team, not as a live feed of an individual. Nobody has a screen showing what you are doing.
Will this be used to decide whether I keep my job? No. [COMPANY] has committed in writing that this is not used for discipline, ranking, pay, promotion or employment decisions. That commitment binds the company, not just the software.
Can I opt out? [ANSWER HONESTLY. IF THE ANSWER IS NO, SAY NO AND EXPLAIN THE SCOPE LIMITS INSTEAD — A SOFT "COME AND TALK TO US" WHEN YOU MEAN NO COSTS MORE TRUST THAN A CLEAR NO.]
How long is it kept, and can I see mine? Captured activity is deleted after [90] days. [STATE WHETHER AN INDIVIDUAL MAY REQUEST A COPY OF THEIR OWN RECORD. IN SOME JURISDICTIONS A SUBJECT ACCESS RIGHT APPLIES REGARDLESS.]
Who is Orchard, and can they see it? Orchard is the vendor. Their staff can reach customer data only through a separate system with its own credentials and multi-factor authentication, and every read is written to an audit log that cannot be edited. They process data on our instructions under a signed Data Processing Agreement, and are contractually barred from using it for any other purpose or selling it.
These are templates for adaptation by the deploying organization and do not constitute legal advice. Requirements for workforce notice and consultation differ by jurisdiction and should be confirmed with counsel in each territory where endpoints will be enrolled.