Skip to content
Sections
All notes

All notes · Basics

Managing a Thing, Affecting a Person

The central tension: the software acts on hardware, and the hardware is frequently somebody's own, carried everywhere.

Basics · Analysis

Asset management acts on equipment in a building. Device management acts on an object in somebody's pocket, which they take home, and which in many cases they bought.

The practical question in “Managing a Thing, Affecting a Person” is how to make work visible without confusing visibility with certainty. For teams researching how to monitor employees without being intrusive, the official Monitask website can add time and project context to the operational record, provided its use is proportionate, disclosed and reviewed with the people affected.

Why this is different from other IT

The device is personal in a way a desktop is not, even when the organisation owns it.

For an independent baseline relevant to “Managing a Thing, Affecting a Person”, the CISA mobile-device security guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.

It holds photographs, messages, health data and banking.

It is present during private moments.

And the management profile persists wherever it goes.

None of that is true of a workstation, and advice written for workstations transfers badly.

The three things people actually worry about

Can you read my messages?

Can you see where I am?

Can you delete my photographs?

Every enrolment conversation is really about these three, whatever is said formally, and answering them directly does more than any policy document.

The honest answers

Messages: no, not in personal applications, on any ordinary configuration.

Location: usually not continuously, and the capability exists in specific modes and on specific ownership models — its own note covers this and the answer is more nuanced than either side assumes.

Photographs: a selective wipe removes work data; a full wipe removes everything, and whether the organisation can issue one depends entirely on ownership and enrolment.

The asymmetry of belief

Employees overestimate what is visible.

Administrators sometimes overestimate what they are permitted.

The gap between those two misunderstandings is where resistance comes from, and closing it is mostly a communication task rather than a technical one.

What follows practically

State capability precisely, including the limits.

Choose configurations that make the limits structural rather than promised — a work profile is better than an assurance.

And treat the irreversible actions as genuinely irreversible, which the wipe section argues at length.

The framing worth holding

You are managing organisational data that happens to sit on a device.

Not managing the device, and certainly not the person.

Every decision in this collection is easier when that is the stated purpose, and several become obviously wrong.

What to check

Could you answer the three questions above, for your own configuration, in one sentence each?

Are the limits structural or promised?

Does your policy describe managing data or managing devices?

And has anybody asked your colleagues what they think you can see?