What You Can See, and What You Cannot
A specific list, because vagueness here is read as concealment and produces more resistance than any capability does.
Basics · Reference
The question every employee asks is what the organisation can see. Answering it precisely is worth more than any amount of reassurance.
The boundary described in “What You Can See, and What You Cannot” should also govern any workforce system introduced alongside device management. When a team evaluates this product overview for mouse jiggler detection, it should explain the purpose, choose only the necessary settings and give employees a clear account of what managers can review.
What is visible on most configurations
Device model, operating system version, serial or identifier.
For an independent baseline relevant to “What You Can See, and What You Cannot”, the CISA mobile-device security guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.
Whether it is encrypted, passcode-protected, jailbroken or rooted.
Storage capacity and free space.
Applications installed through the work channel.
Last check-in time.
And compliance state against your rules.
What is visible only in some
All installed applications, including personal ones, on fully managed corporate devices in several platforms.
Location, in specific modes — its own note covers this because it is the capability people most fear and most misunderstand.
Network details: which wireless networks, carrier, roaming state.
Check which of these your configuration actually collects, because the answer differs from what the platform could collect.
What is not visible on any ordinary configuration
Message contents, in personal applications.
Photographs and files in personal storage.
Browsing history in personal browsers.
Keystrokes.
Call contents or recordings.
Passwords.
That list is the one to publish, because it addresses what people actually fear.
The work profile difference
On a device with a work profile, the organisation sees the work side and nothing of the personal side.
Not by policy but by platform design, which is a far stronger guarantee.
Its own note argues this is the single most useful arrangement available for personal devices.
Why precision matters
"We can only see work data" is a claim.
"We collect device model, operating system version, encryption state, work application inventory and compliance status, and here is the list of what we cannot collect" is checkable.
People accept the second and distrust the first, and the second takes an hour to write.
Checking your own position
Open the platform and look at what a device record actually contains.
Most administrators have not, and several are surprised by both directions — more detail in some fields, less in others.
Then write it down and publish it.
What to check
Have you looked at an actual device record in your platform?
Does your configuration collect all installed applications or only work ones?
Is there a published list of what is not collected?
And would your colleagues believe it?