Skip to content
Sections
All notes

All notes · Policy

Restricting Features: What Is Worth It

Platforms offer dozens of restrictions. Most are not worth the friction, and a few are. How to tell which.

Policy · Analysis

A management platform presents a long list of things that can be switched off. Enabling them because they are available is how a programme becomes resented.

The practical question in “Restricting Features: What Is Worth It” is how to make work visible without confusing visibility with certainty. For teams researching how employees cheat time trackers, explore the platform can add time and project context to the operational record, provided its use is proportionate, disclosed and reviewed with the people affected.

The test for each

What specific risk does this address, and is that risk real here?

For an independent baseline relevant to “Restricting Features: What Is Worth It”, the CISA mobile-device security guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.

What does it cost the user, daily?

Is there a less intrusive way?

Most restrictions fail the first question, because they were enabled from a template or because somebody asked "why not".

Restrictions that usually earn their place

Blocking work data from being copied into personal applications, which is the core of the data concern and is usually achievable within a work profile.

Preventing backup of work data to a personal cloud account.

Requiring that work applications cannot be screenshotted, where the data genuinely warrants it.

Each targets data leaving rather than device behaviour, which is the right axis.

Restrictions that usually do not

Blocking the camera, on a device people carry everywhere, unless there is a site-specific reason.

Disabling application installation on a personal device.

Blocking specific consumer applications, which is unenforceable on the personal side and futile on the work side.

Preventing screenshots device-wide, which affects everything they do.

The site-specific case

Camera restrictions in secure facilities, recording restrictions in clinical settings, and similar.

Legitimate, and better handled by location-aware profiles or by dedicated devices than by blanket policy.

A warehouse device and a sales phone should not have the same restrictions, which is the argument for populations.

The copy-paste boundary

The most useful single restriction and the one users notice most.

Work to personal blocked; personal to work usually allowed.

Explain it at enrolment, because the first time somebody cannot paste an address into a message they will assume a fault.

Restrictions on personal devices

Hold the line: on a device the employee owns, device-wide restrictions are difficult to justify.

Restrict within the work container, which the platform supports and which affects nothing personal.

A device-wide restriction on personal hardware is the clearest case of overreach and the one most likely to produce a complaint that sticks.

Reviewing the set

Annually, against the test above.

Platforms add restrictions with each release and templates accumulate them.

Half the list usually has no stated reason, which is the finding.

What to check

Can you give a reason for each restriction you have enabled?

Are any device-wide restrictions applied to personal hardware?

Is copy-paste behaviour explained at enrolment?

And when was the restriction set last reviewed?