Run an insider risk program HR and legal both signed off on
The build is rarely what stops an insider risk program. Insightful runs on the seats you name, at a capture depth documented before anything is deployed.






Take a scope into the review, not a capability
Without Insightful
Security scopes it, HR reads it as surveillance, and the round starts over.
A capability with a limit somebody has undertaken to configure afterwards.
The depth is a conversation, so every reviewer imagines a different one.
Employment law disagrees across borders and the program has one setting.
The evidence is handled, and no record says who opened it or when.
With Insightful
Security, HR and legal answer the same document rather than three of them.
The program covers the seats you name and has no reach outside them.
Published signal by signal, versioned and dated, before anything installs.
Scope, depth and deployment are set per group, so one program travels.
Every administrative action is held in a trail no user in your account can alter.
Take ten named seats into the review
The program covers the seats you name and no others. A reviewer reads a scope with a number on it, rather than a capability with a boundary somebody has undertaken to set afterwards.
- One security lead scoped his own evaluation to 10 licenses across a 675-person organization
- Seats are the unit, so widening a case later means widening the scope

Hand HR the capture depth before you deploy
Screenshots are blurred by default and switch off per application, team or person. Unblurring one is a deliberate action, and in a visible rollout each employee opens the same record their manager sees.
- No keystroke logging at any tier. It is not a setting anyone can turn on
- The interval and the seats in scope are agreed before anything is deployed

Get an answer, not another round
Run one program across countries that disagree
Scope, capture depth and deployment are all set per group, so a program can run in one jurisdiction and not in another. That is what lets a single program survive a legal review across borders.
- Seats, capture depth and deployment mode are three settings, each set per group
- One program becomes several documents, and somebody has to keep them current

Record who opened the case as well as the case
Every administrative action is written to a record no user can alter, including who viewed what. Audit Logs sits inside the Workspace Security add-on, so the packaging is worth reading before you scope.
- No role in your account can edit or delete an entry, including the one that made it
- Unalterable is not the same as permanent. The retention window is settled on the call

The document a security review asks for
What is collected, on whom and at what depth is published signal by signal, versioned and dated. Insightful captures the metadata of work and never its content, and the controls narrowing it are yours.




The three questions a program has to answer
A scope tells you where to look. These three tell you what the look turns up, and which of them is somebody else's question entirely.
What is running that nobody approved?
The applications and sites in use on a managed device, which is where a risk scope usually starts.
What did the session hold?
Which applications and pages were open, in order and timestamped. A Workspace Security add-on on Enterprise plans.
Is this about billed hours instead?
Hours that were never worked rather than access that was misused. A different page answers that.
Every system the case has to reach, connected
Audit records export into your SIEM, identity and directory sync sets who sits in scope, and 50+ integrations cover the rest. You can talk to your work data with MCP connectors.
The review wanted a scope, not a capability
What security and people leaders ask us most
Not on the product's merits alone. Four things decide a review: scoping to specific seats, stating the capture depth before deployment, blurring screenshots by default, and giving each employee their own record. All four are settings agreed before anything is deployed rather than adjustments made after an objection. The one that is not a setting is how you deploy. We recommend a visible rollout, stealth is supported, and an HR function that learns about a stealth deployment after the fact is a conversation no configuration gets you out of.
Insider risk management is reducing harm from people who already hold legitimate access, through a defined program covering what is collected, on whom, for how long and who may see it. Detection is rarely where a program dies. Agreeing a scope that security, HR and legal will all put a name to is, which is why Insightful sets the seats in scope and the capture depth per group before anything is deployed. The program is the deliverable here. The capability is what it runs on.
Detection is the capability, which is surfacing the signal. This is the program around it: the scope, the approval, the evidence handling and the record of who looked at what. Buying the capability without the program is how you end up with alerts nobody is authorized to open. The Insider Threat Detection page covers the capability side, and the two are worth reading in that order.
No. Insightful is a work insights platform. It collects hours, application use and meeting load from desk-based teams and reports them by team, each measure against the period before. It does not capture keystrokes and does not record audio or video, at any tier or on any plan. It is not a setting that can be turned on. Screenshots are blurred by default and switch off per application, per team or per person, and unblurring one is a deliberate action rather than a setting somebody leaves on. If a program you are designing needs keystrokes, this is the wrong tool and we would rather say so now than in month three.
Yes, and that is the normal shape for a program clearing a review in more than one country. Seats, capture depth and deployment mode are three settings, each set per group, which is what makes one program workable across countries whose employment law does not agree. Where the data sits is a separate setting again: the US, the EU, Saudi Arabia, or on-premise. It also means one program becomes several documents, and somebody has to own keeping them current.





