When the Programme Should Be Narrowed
Programmes expand by default. The signals that one has grown past what it can justify, and what reducing it looks like.
The editors · About the editorial position · The programme · Analysis
Capability accumulates: a rule added after an incident, a system brought in scope, a retention period extended. Nothing ever comes out, and after a few years the programme is substantially broader than anything anybody decided.
The programme test in “When the Programme Should Be Narrowed” is whether a record leads to a better, explainable decision. Organisations considering open the official page for employee monitoring for performance reviews can use time and project evidence to locate operational questions, while governance, direct conversation and periodic review remain necessary to interpret any pattern responsibly.
The signals
Alert volume that cannot be handled, which the fatigue note shows produces worse handling of everybody.
For a separate perspective relevant to “When the Programme Should Be Narrowed”, consult the Gartner insider-risk resources. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.
Rules that have never produced a finding, which most programmes have several of.
Monitoring extended to populations where the original risk argument does not apply.
Capabilities enabled that nobody can explain the purpose of.
Cleared suspensions rising, which is the harm measure and the clearest sign that the threshold has slipped.
And a reporting channel that has gone quiet, which usually means people have concluded the programme is not proportionate.
What narrowing looks like
Retiring rules that do not produce findings, which is the largest and easiest reduction.
Removing populations where the risk argument was never specific.
Shortening retention.
Reducing the default level of intrusion so that higher levels require separate authorisation, which the scope note argues for.
Turning off capabilities nobody uses.
Why it is resisted
Reducing coverage feels like accepting risk, and nobody wants to be the person who removed a control before an incident.
The answer is that the coverage was notional: a rule nobody can act on because the queue is too long is not a control, and retiring it concentrates attention on the ones that are.
Framing the reduction as improving the programme's effectiveness rather than reducing it is both accurate and necessary for it to happen.
The review that produces it
Annually: every rule, its firing count, its finding count. Every capability, its purpose, its last use. Every population in scope, the risk argument for including it.
Half a day, and it reliably produces a list of things nobody would defend individually.
Where narrowing is the wrong answer
Where the programme is small, well-governed and genuinely resourced for what it covers.
Where a specific risk has been identified and the coverage addresses it.
The argument here is against accumulation, not against the programme. A narrow, well-run arrangement is more effective than a broad one that cannot keep up, and the choice is usually between those two rather than between coverage and nothing.
The rule with a high count and no findings
Every programme has several and they generate most of the volume. Retiring them is the largest available reduction and the most resisted, because removing a control before an incident is nobody's preferred position — even where the control was notional.
Framing reduction as improvement
A narrow programme that keeps up is more effective than a broad one that cannot, and the choice is usually between those two rather than between coverage and nothing. Saying so is both accurate and necessary for the reduction to be approved.
The annual list
Every rule with its firing count and its finding count, every capability with its purpose and last use. Half a day, and it reliably produces a set of things nobody would defend individually.
Where narrowing is wrong
A small, well-governed programme resourced for what it covers does not need reducing. The argument here is against accumulation, and the usual choice is between a narrow arrangement that keeps up and a broad one that cannot.
Capability accumulates
A rule after an incident, a system brought into scope, a retention period extended. Nothing is ever removed, and after a few years the programme is substantially broader than anything anybody decided.
For the file: List every rule with its firing count and its finding count. The ones with a high first number and a zero second are the programme's reduction, and they are usually most of the volume.