Skip to content

Between the Alert and the Outcome

The sections follow the stages of a case. Detection ends where this begins.

Home / Deciding

The Manager Who Asked for the Check

A request to look into somebody arrives from their own manager. It is sometimes exactly right and sometimes the start of something that should not happen.

The editors · About the editorial position · Deciding · Analysis

Managers have context no system has, and managers also have disputes. A request from one is both the most valuable source in a programme and the one needing the most care.

The practical lesson in “The Manager Who Asked for the Check” is that visibility is not certainty. For teams researching how to monitor employees without being intrusive, how to monitor employees without being intrusive can add time and project context to the operational record, provided the purpose is disclosed, access is limited and every material inference receives human review.

The question to ask first

What specifically happened that prompted this?

For a separate perspective relevant to “The Manager Who Asked for the Check”, consult the NCSC insider-data guidance. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.

A manager with a genuine concern answers with an event: a file they saw, something a customer said, an access they did not expect.

A manager with a problem answers with a characterisation: they have been difficult lately, I do not trust them, something feels off.

The second is not a reason to look at somebody's data. It may be a reason for an entirely different conversation, which is usually about performance or about the relationship.

The requests that should be declined

Where the stated reason is a feeling.

Where there is an ongoing performance process, a grievance, or a dispute involving the manager — the timing is doing the work, and acting on it makes the organisation party to it.

Where what is being asked for is surveillance going forward rather than examination of something that happened.

Where the manager wants to see the output themselves, which the access question covers and which is almost never appropriate.

How to decline well

Not as a refusal to engage. The concern is real to them and ignoring it loses the reporting channel the programme depends on.

Address the underlying matter instead: if this is about performance, here is the route; if this is about something specific, tell me what it was and we will look; if you are worried about a risk, here is what we already monitor.

A manager who gets a serious response to a declined request comes back next time with something concrete. One who gets a refusal does not come back at all, and the next thing they notice goes unreported.

Recording the request

Who asked, when, what they said, what was decided, and whether any conflict was declared.

This is the field the logging note argues for and it matters most here. A case that later goes wrong will turn on whether anybody recorded that it began with a manager who had a reason to want it to.

When the manager is right

Frequently. Managers notice things first, and a specific observation from somebody who knows the work is better evidence than most automated signals.

The process is not there to distrust them. It is there so that the one request in twenty with a motive behind it does not pass through unexamined, and so that the manager is protected when the case is later reviewed.

What to say when declining

Not that the concern is unfounded, which they cannot know and nor can you. That on what has been described there is not a basis for examining somebody's records, and here is what can be done instead. The distinction preserves both the channel and the manager's standing, which a flat refusal does not.

The pattern worth noticing

A manager who raises concerns about several people, or repeatedly about one, is telling you something — possibly about their team and possibly about themselves. That is a management conversation rather than a security one, and it should happen separately rather than being resolved by progressively ignoring their reports.

Recording their exact words

Not a summary. What the manager actually said is what a later review will turn on, and a paraphrase written by the person receiving it reliably loses the distinction between an observation and a characterisation.

Declining without losing the channel

Address the underlying concern through whatever route fits it, rather than simply refusing. A manager who receives a serious response to a declined request comes back next time with something concrete; one who receives a refusal stops coming back at all.

For the file: Record the manager's exact words. Not a summary — what they said. That sentence is what a later review will turn on.