Mouse jigglers, dual employment, and the surveillance trap
Activity monitoring measures presence at a device. It does not measure work, and a twenty dollar gadget defeats it completely. Both sides of this argument are currently losing, and the way out is not a better camera.
The dashboard that knows everything and understands nothing
It is a Tuesday morning and a director of engineering is looking at a productivity dashboard she did not ask for. The rows are sorted by an activity score. At the top, glowing a satisfying green, is a developer who has been continuously active for six hours and eleven minutes. Near the bottom, in amber, is the person she would keep if she could keep only one: a staff engineer who spent yesterday reading a distributed systems paper, drawing on a whiteboard, and staring out of a window, before deleting four hundred lines of code and replacing them with forty that finally made the race condition impossible.
The green row is a USB device that costs about twenty dollars. It plugs in, presents itself to the operating system as a mouse, and nudges the cursor by one pixel every thirty seconds forever. It does not require software, so no endpoint agent will see it. It does not require permissions, so no policy blocks it. The employee who bought it is not, as it happens, doing anything else with the time. He is simply exhausted by a metric that punishes him for thinking.
The amber row is the best engineer in the company.
This is the surveillance trap in a single screenshot. The organisation has bought a system that is simultaneously invasive and useless: invasive enough to generate a formal complaint and possibly a regulatory one, and useless enough that the one population it was bought to catch is the population most likely to defeat it. Everyone involved knows this. Very few say it out loud, because the alternative on offer has always been to trust the login and hope.
There is a third option, and it is not a compromise between the two. It is a different question.
How can an employer verify remote work without spying on employees? Stop measuring hours and start signing work events. Instead of watching a screen all day, require a short cryptographic confirmation from the employee's own enrolled device at a small number of meaningful moments, such as a merged change, a submitted report, or the start of a billable shift. Each confirmation produces a receipt the worker keeps. No screenshots, no keystroke logs, no continuous camera.
What does activity monitoring actually measure?
Take the question literally, because the answer is narrower than almost anyone assumes.
Employee monitoring products from vendors such as Teramind, ActivTrak, Hubstaff and Insightful gather some combination of the following: input device events, foreground window titles, application and URL categories, periodic screenshots, idle timers derived from gaps between input events, and sometimes webcam stills. Each of these is a measurement of a machine. None of them is a measurement of a person, and none of them is a measurement of work.
Consider what a keystroke actually attests. It attests that a key on a particular keyboard attached to a particular machine transitioned from up to down while a particular user session was active. That is the whole claim. It does not say who pressed it. It does not say whether the press was meaningful. It does not say whether a human was in the room. The inference from that event to the conclusion "this employee is working" involves at least four unstated assumptions, and a twenty dollar device falsifies the first one.
The measurement problem, stated plainly
There is a well known failure mode in metrics design, sometimes summarised as the observation that a measure which becomes a target stops being a good measure. Activity monitoring is a textbook case, and it is worse than the usual version, because the metric is not merely gameable, it is inversely correlated with the behaviour the employer wants for a significant share of knowledge work.
Think about what high value cognitive work physically looks like from the outside. Reading documentation looks like an unchanging window. Thinking about an architecture looks like an idle timer counting up. Talking to a colleague at a whiteboard looks like an unattended machine. Reviewing someone else's design carefully looks like scrolling slowly. Meanwhile, the visible signature of low value work is a flurry of window switches, a lot of typing, and continuous mouse movement.
An activity dashboard therefore does not simply fail to measure work. It systematically ranks shallow work above deep work, and it does so while creating a permanent record of employees' screens. That combination is the reason this is worth writing about from a security company rather than only from a labour advocate. The privacy objection is real, but the privacy objection alone has not stopped anyone. The efficacy objection should, because it means the organisation is paying twice: once for the software, and once in the form of the engineers who quietly stop doing the hard parts of their job because the hard parts look like idling.
Why can a twenty dollar device defeat a large monitoring deployment?
Because of an asymmetry that never goes away. The monitoring vendor must observe a signal. The employee must produce the signal. Producing a signal is nearly always cheaper than validating one.
Walk the ladder of countermeasures and watch the asymmetry hold at every rung. The employer switches from mouse position to input entropy, so the simulator adds randomness. The employer adds application focus requirements, so a script rotates focus. The employer adds screenshots, so the employee runs the monitored session in a virtual machine or on a second laptop while working, or not working, on the first. The employer adds webcam checks, so the employee sits in front of the camera and reads a book. Every rung costs the employer real money and real goodwill. Every rung costs the employee, at most, an afternoon and a small purchase.
This is the same structural problem that shows up everywhere in this field, and it has a name in our Identity Failure Map: it is Detection Debt. You are buying an ever more expensive detector for a signal that is ever cheaper to fake, and the gap widens on a schedule you do not control.
The arrival of capable agents closes what little was left. The visible artefacts of many jobs, replying in chat, updating a ticket, drafting a status note, opening a pull request, can now be produced continuously by software on the employee's behalf. Every signal an activity monitor collects can be generated without a human being present at all. A monitoring product purchased in 2021 to detect absence is, in 2026, detecting the presence of automation.
| Signal | What it actually measures | What defeats it | What it proves about work |
|---|---|---|---|
| Mouse movement | Cursor position deltas | A twenty dollar USB jiggler, no software needed | Nothing |
| Keystroke cadence | Key up and down events in a session | A short input script | Nothing |
| Active window and app category | Which process has foreground | Scripted focus rotation, a second machine | Nothing |
| Idle timers | Gaps between input events | The same jiggler | Nothing |
| Periodic screenshots | Pixels on one display | A virtual machine, or a second laptop | That a screen was on |
| Webcam stills | A face in frame at an instant | A photo, a loop, or simply sitting there | Presence at that instant, if genuinely live |
| VPN and device telemetry | A device on a network | A second device | That a machine connected |
| Signed work event | A human authorised a specific artefact | Handing your unlocked device to a proxy | That this human stood behind this output |
Is dual employment a real problem or a moral panic?
Here is where an honest post has to make its own side uncomfortable, so let us do that in both directions.
The case that it is real
It is real. There is a large, public, and entirely unembarrassed online community organised around holding two or more full time jobs simultaneously without disclosure, and its members exchange practical advice on calendar management, meeting avoidance, and exactly the kind of activity simulation described above. The most common defence offered, that the work gets done and therefore nobody is harmed, does not survive contact with several ordinary situations.
It does not survive a regulated context. In a broker dealer, supervision obligations under rules such as FINRA Rule 3110 assume the firm knows who is performing supervised functions and where. It does not survive government contracting, where hours billed under Defense Contract Audit Agency rules are a representation about a specific person's time. It does not survive conflict of interest, since two employers in the same market have a legitimate interest in not sharing an employee. It does not survive information security, because the second employer's laptop is on the same desk, sometimes on the same network, occasionally receiving the same copy and paste buffer.
And in its extreme form it stops being an employment dispute at all. United States Treasury and Department of Justice actions have described a systematic programme in which operatives obtained remote technical roles at Western companies under stolen or fabricated identities, with domestic facilitators hosting company issued laptops so that the work appeared to originate locally. Public materials describe revenue in the hundreds of millions of dollars annually, and the operational pattern is documented across a substantial number of affected companies. We covered the mechanics separately in the laptop farm playbook. The point for this post is narrow: the identity gap that lets someone hold two jobs is the same gap that lets someone hold a job under another person's name.
The case that the panic is overdone
Also true. The prevalence figures that circulate in this area are unreliable to a degree that should embarrass everyone repeating them, and we are going to name one rather than quietly omit it, because seeing how a number decays teaches more than a clean citation.
Search for the cost of time theft and you will quickly meet a figure attributed to the American Payroll Association. In some articles it appears as roughly three hundred and seventy three million dollars a year. In others, citing the same claim, it appears as three hundred and seventy three billion. That is a factor of one thousand, sitting in plain sight, propagated by content marketing on both sides of the argument. A separate widely repeated pair of figures puts annual United States time theft at four hundred and fifty to five hundred and fifty billion dollars, a number large enough to represent a meaningful slice of national payroll, offered without a traceable primary publication that a reader can open and check.
Treat all of these as marketing. The honest position is that undisclosed dual employment certainly exists, is certainly non trivial in fully remote knowledge work, and has no credible public prevalence estimate. Any vendor quoting you a precise national figure for it, very much including anyone selling a fix, is quoting a number nobody measured.
The second honest point is that the overwhelming majority of remote employees are simply doing their jobs, and every monitoring deployment is a tax levied on that majority to address a minority nobody has counted. If your control catches the few by degrading the many, you have chosen the most expensive available option.
What did the Wells Fargo dismissals actually establish?
In May 2024, Wells Fargo dismissed more than a dozen employees from its wealth and investment management division. The reporting at the time, drawing on disclosures filed with the Financial Industry Regulatory Authority, quoted language describing simulation of keyboard activity creating the impression of active work. The firm did not publicly detail the underlying conduct, and the regulatory disclosures are the primary record rather than a narrative account.
What that episode establishes is narrower than the headlines suggested, and more interesting. It does not establish how widespread simulation is. It does not establish that the employees were working elsewhere, and the public record does not say so. What it establishes is that a large, sophisticated, heavily regulated employer with every monitoring capability available concluded that the honest answer to "was this person working" was unavailable to it, and that the observable proxy had been falsified. The control failed at exactly the organisation best resourced to run it.
That is the lesson worth taking. Not that employees cheat, but that watching does not answer the question.
What is the difference between monitoring and attestation?
Here is the analogy, and then the mechanism it opens the door to.
Imagine two ways to know whether a night watchman patrolled a building. In the first, you install cameras in every corridor and pay someone to review the footage. This is expensive, it records everyone who walks through the building including visitors, and it tells you where a body was, not whether anything was checked. In the second, you place a small reader at each of eight doors, and the watchman touches a key to each one as he passes. At the end of the night you have eight records. You know nothing at all about the minutes in between, and you do not want to.
The second system is smaller, cheaper, more private, and more probative. It is more probative precisely because it is discrete. It captures the moments that carry meaning and deliberately captures nothing else, so the record is short, unambiguous, and hard to argue with. Continuous footage produces an enormous amount of data and almost no evidence.
Now make the key cryptographic, and make the watchman the owner of the record, and you have the shape of the alternative.
A work event is a moment where something of consequence is produced or committed to: a change merged, a design approved, a report filed, a trade recorded, a shift started, a patient visit completed, a deployment released. At that moment, and only at that moment, the person confirms from their own enrolled device that they are the human behind it. What comes out is a receipt: a small signed object binding a person, an artefact, and a time, which anyone can verify later without contacting the employer or the vendor who issued it.
Between those moments, nothing is collected. That is not a limitation of the design. It is the design.
What does a signed work event look like?
Concretely, this is the object. Nothing is compressed for the article; this is the shape of the thing.
{
"type": "work_event",
"event": "pr.merge",
"ref": "github.com/acme/ledger#4821",
"artifact": "sha256:9f2c41a0d7b3e58c1f0a6d2b884e37c95ab1e0f2...",
"actor": "did:manav:7Hq2VtPn4x",
"org": "acme",
"assurance": "glance",
"signed_at": "2026-09-12T14:22:07Z"
}
Read it field by field, because each one is doing a job.
event and ref say what happened and where, so the receipt is anchored to something the employer already tracks. artifact is the digest of the actual output, so the receipt cannot later be pointed at a different change; it is bound to those exact bytes. actor is a stable identifier for the human, not for an account, which matters because accounts are issued by employers and this record is supposed to outlive the employment. assurance records how the person was confirmed at that moment, and signed_at is when.
The signature covers a canonical serialisation of that object, so that everybody computes the same bytes before hashing. This is not a detail you can skip. If the renderer and the verifier serialise the JSON differently, they hash different things and the whole exercise becomes theatre.
canonical = jcs(payload) // RFC 8785 canonical JSON
digest = sha256(canonical)
valid = ed25519_verify(
key = published_key(payload.actor),
message = digest,
sig = receipt.signature
)
// valid == true means: this human, this artefact, this moment.
// It verifies offline. No call to the employer. No call to us.
What the assurance field is for
Not every work event deserves the same ceremony, and pretending otherwise is how good controls die of fatigue. Three levels are enough for most organisations.
Place is the light one. The person is on a device already enrolled, in a setting already established, and confirming takes a single tap. This is appropriate for routine events, which is most of them.
Glance adds a brief on device face match with a liveness challenge, so that the confirmation is bound to the person and not merely to possession of an unlocked laptop. The match happens on the device. No image is transmitted and no template is stored anywhere; what remains is a one way key that cannot be turned back into a face. This is appropriate for a random sample of events and for anything of real consequence.
Beam covers the case where the work happens on a machine the person does not control, such as a client site or a shared terminal. The desktop displays a rotating pattern, the person's own phone claims it, and the confirmation comes from the phone. The untrusted machine never holds anything worth stealing.
A workable policy is not "sign everything". It is: sign the events that matter, sample the rest, and let the worker see exactly which is which. A developer might produce four or five receipts in a week. A field carer might produce one per visit. A trader might produce one per exception. The rate is a policy decision that the employer and the workforce should make together and write down, and the fact that it is visible and negotiable is a feature that no monitoring deployment can offer.
How does this actually address dual employment?
Carefully, and less dramatically than a vendor would claim.
Signed work events do not tell an employer what an employee does with the rest of their day, and they are not designed to. What they produce is something no monitoring product can produce: a portable, verifiable, worker held record of specific outputs at specific times.
The consequence for undisclosed dual employment is structural rather than investigative. Today, a person holding two full time roles is invisible to both, because each employer sees only its own telemetry and neither can see the other. Telemetry is trapped inside the organisation that collected it. A receipt is not: it lives in the worker's own wallet and can be presented, by the worker, to whoever they choose.
That changes what an employer can reasonably ask for. Instead of demanding surveillance of the whole day, an employer with a genuine concern, a regulated firm with supervision duties, say, can ask for something narrow and checkable: confirm that during contracted hours on these dates, no conflicting attestations exist. The worker discloses what they choose to disclose. The employer receives an answer to the question it actually needed answered, rather than a video of someone's living room.
Be clear eyed about the boundary. This is not automatic detection and we are not going to pretend it is. Overlapping receipts from two employers at the same instant are strong evidence of simultaneous employment. Sequential work at two jobs in one day produces no overlap and will not be caught. A worker who declines to present receipts has simply declined, and what an employer does with that is a policy and legal question, not a technical one. What has changed is that the evidence, when it exists, is portable and verifiable, rather than being a screenshot in a vendor console that proves a screen was on. We wrote about the longer arc of this in identity continuity from interview to offboarding, and about the same primitive in shift work in who is actually driving.
Is any of this legal, and where does it get complicated?
Worth addressing directly, because the legal exposure of the current approach is one of its least discussed costs, and this is not legal advice.
Continuous employee monitoring sits inside a growing body of restriction. In the European Union, Article 88 of the General Data Protection Regulation allows member states to set their own rules for processing in the employment context, and several have, with works council consultation frequently required before monitoring can be introduced at all. In the United States, a 2022 General Counsel memorandum from the National Labor Relations Board raised the concern that pervasive electronic monitoring and algorithmic management could interfere with employees' protected rights, though a General Counsel memorandum reflects enforcement priorities rather than binding law and can be withdrawn by a later General Counsel. Several states impose notice requirements. Biometric statutes in some jurisdictions attach specific consent and retention duties to face and fingerprint data, which is precisely why a design that stores no biometric template is easier to defend than one that stores one.
Attestation is not automatically exempt from any of this. It is personal data, it requires notice, and in some jurisdictions it requires consultation. What it does have is a far better answer to the two questions a regulator or a works council will ask first. What do you collect? A few signed records of specific work events. What do you do with the rest of the day? Nothing, because we never collect it.
That is a defensible conversation. "We take screenshots every ten minutes and score everyone's activity" is a harder one, and it is being lost in an increasing number of jurisdictions.
What this cannot do
The honest limits, because a control whose limits are hidden fails at the worst possible moment.
- It does not measure quality, effort, or intensity. A receipt proves a specific human stood behind a specific artefact. It says nothing about whether the artefact was any good. No identity technology provides a productivity metric, and any vendor who tells you otherwise is selling you activity monitoring with extra steps.
- It does not catch sequential dual employment. Two jobs worked in alternating blocks produce no overlapping attestations. The technique surfaces simultaneity, not divided attention.
- A determined proxy with your device and your face defeats it. Liveness and continuity raise the cost substantially, and the person must now be physically present and complicit, which is a materially different proposition from posting a laptop to a facilitator. It is not impossible. It is expensive and it does not scale, which is the realistic goal.
- Sampling too sparsely proves too little. If one event a month is signed, the receipt trail is not meaningful evidence of anything. If everything is signed, people will resent it and route around it. The rate is the design, and getting it wrong in either direction breaks the control.
- It does not resolve the underlying management problem. If a team cannot tell whether someone is contributing without instrumenting their mouse, the deficiency is in how work is defined and reviewed. Receipts give you better evidence. They do not give you judgment.
- Employers will ask for more. This is the honest political risk. An organisation that adopts attestation because it is proportionate may be tempted to add sampling until it becomes surveillance by increments. The safeguard is to write the rate and the event list down, publish it internally, and require the same process to change it as to introduce it.
What to do this week
- Pull your own monitoring efficacy numbers. Ask the team that runs the tool how many confirmed cases of absence or dual employment it has surfaced in twelve months, versus how many hours went into administering it. Ask for the count, not a demo. In many organisations this single question ends the programme.
- Write down the work events that actually matter for two or three roles. Aim for three to eight per role per week. If you cannot list them, that is the real finding, and no tool will fix it.
- Delete one signal. Screenshots are the usual candidate: highest privacy cost, lowest evidential value, easiest to defeat with a second machine. Removing one signal is a cheap way to test whether anything downstream actually depended on it.
- Check the legal position in every jurisdiction where you employ people, specifically whether works council consultation or employee notice was completed for the tooling you already run. A surprising number of deployments cannot answer this.
- Pilot attestation on one high value event with one willing team. A merged change or a submitted report is ideal. Measure the time cost per confirmation, which should be seconds, and ask the team afterwards whether they preferred it to the dashboard.
- Give the receipts to the worker. If the record lives only in your console, you have built a nicer surveillance product. The portability is the point, and it is also what makes the control acceptable to the people subject to it.
- Publish the policy. Which events are signed, at what assurance, at what sampling rate, retained for how long, and what process is needed to change any of that. A control people can read is a control people comply with.
If you want to see the mechanism rather than read about it, the dual employment demo and the phantom shift demo both run in a browser with no signup, and the developer documentation covers the signing and verification calls. The longer argument for why the worker should hold the record is in the verified work passport.
Frequently asked questions
Are mouse jigglers illegal? The device itself is an ordinary consumer product and is legal to buy and own almost everywhere. Using one to misrepresent hours worked is a different matter and is generally treated as a disciplinary and potentially a fraud issue, particularly where hours are billed to a client or a government contract. The relevant question is rarely the hardware, it is the representation being made about time.
Can an employer detect a second full time job? Not reliably with monitoring software, which sees only its own device. Background checks are a point in time and do not see concurrent employment. Signed work events change this only in the specific case of simultaneous attestations at two employers, and only where the worker presents them. There is no technology that detects sequential moonlighting.
Is signing work events just surveillance with better branding? The difference is measurable rather than rhetorical. Monitoring collects continuously, stores what it collects with the employer, and produces data about periods when nothing happened. Attestation collects at a small number of defined moments, stores the receipt with the worker, and produces nothing in between. If a deployment collects continuously, it is monitoring, whatever it is called.
What did Wells Fargo dismiss employees for in 2024? Reporting in May 2024, drawing on disclosures filed with the Financial Industry Regulatory Authority, described more than a dozen dismissals in the wealth and investment management division in connection with simulation of keyboard activity creating the impression of active work. The firm did not publicly detail the conduct, so the regulatory disclosures are the primary record.
Does this work for hourly and shift workers as well as knowledge workers? Yes, and often better, because shift work has natural events. Shift start, shift end, and visit completion are unambiguous moments to bind. The design constraint is different: the confirmation must work on an inexpensive phone, take seconds, and never penalise someone for poor signal or traffic.
What stops an employee from simply handing their phone to someone else? Nothing stops it entirely. A liveness challenge means the proxy must be physically present and willing at each confirmation, which is a very different economic proposition from mailing a laptop to a facilitator. The goal is to make the cheap attack expensive, not to claim an unbreakable one.
Does an employer see the worker's other receipts? No. Receipts live in the worker's wallet and are disclosed by the worker. An employer can ask for a specific attestation about a specific period, which the worker can provide or decline. There is no employer facing view of a person's history across other organisations, and building one would recreate the problem this is meant to solve.
Sources
- Financial Industry Regulatory Authority, BrokerCheck disclosure records, the primary record for the May 2024 dismissals discussed above: brokercheck.finra.org
- FINRA Rule 3110, Supervision: finra.org/rules-guidance/rulebooks/finra-rules/3110
- National Labor Relations Board, General Counsel memoranda, including the 2022 memorandum on electronic monitoring and algorithmic management: nlrb.gov/guidance/memos-research/general-counsel-memos
- General Data Protection Regulation, Article 88, processing in the context of employment: gdpr-info.eu/art-88-gdpr
- Defense Contract Audit Agency, timekeeping and labour charging guidance: dcaa.mil
- United States Department of the Treasury press releases on North Korean information technology worker schemes: home.treasury.gov/news/press-releases
- United States Department of Justice, Office of Public Affairs, indictments and actions concerning remote information technology worker fraud: justice.gov/opa/pr
- RFC 8785, JSON Canonicalization Scheme, the serialisation used before hashing a receipt payload: rfc-editor.org/rfc/rfc8785
- The r/overemployed community, a public primary source for the practices described: reddit.com/r/overemployed
The employer who monitors the most knows the least. Stop watching the hours and start signing the work.