Opus (task mining)

Task mining privacy and governance: how Opus capture is controlled

Task mining privacy starts with one rule: Opus (task mining) collects no activity data until an administrator publishes a device privacy policy. From then on, your administrators decide what Opus captures, when it captures it and who can see the results.

What does Opus record?

Opus records which applications and websites people use on their Windows desktops, the window titles, and how long each activity lasts.

Opus also counts keyboard and mouse actions per activity and marks idle periods. When employees record a task, Opus tags that activity with the task and, where entered, its case ID. Most other data types are optional and switched on or off per department. Others follow the privacy policy and settings the customer controls. Only agent health is always on: each agent reports its version, backlog and free disk. Opus keeps the agent's CPU and RAM samples only while collection is allowed.

See what Opus records and how it is controlled, data type by data type, on the Opus page.

Why we say "no activity data" Before a policy is published, only the agent-health heartbeat runs. That is why we say Opus collects no activity data, rather than nothing at all.

How is Opus capture controlled?

Your administrators control Opus capture through the device privacy policy and department settings, and employees can see what is collected about them.

  • The policy comes first

    Collection starts only after an administrator publishes the device privacy policy. Agents renew it every five minutes, and a copy that lapses after six hours pauses collection.

  • Exclusions and masking on the PC

    Excluded applications and websites are dropped, and text matching up to 100 redaction patterns is masked, before anything is uploaded.

  • Working hours and pauses

    Capture can follow working hours, and each department decides whether employees may pause it.

  • No screenshots by default

    Opus takes no screenshots or screen recordings until an administrator allows them in the privacy policy.

  • Transparency for employees

    Employees see which data categories are collected and who accessed their data, and every access to a named employee's data is recorded.

  • Governed exports

    Governed export jobs produce checksum-verified archives of Opus data.

How privacy controls apply, step by step

The controls apply at every stage, from the published policy to each employee's own view of their data.

  1. Publish the policy

    An administrator publishes the device privacy policy: collection on or off, excluded applications and websites, and redaction patterns.

  2. Agents refresh it

    Each agent fetches the current policy every five minutes. Without a valid copy, collection pauses.

  3. Filter on the PC

    Excluded activity is dropped and matching text is masked on the PC, before storage and again before upload.

  4. Queue in an encrypted store

    Records wait on the PC in an encrypted local store protected by a key for that device.

  5. Upload over HTTPS

    Records travel only over HTTPS, with revocable device credentials, into your company's own workspace.

  6. Show employees their data

    In their portal, employees see their data categories and access history, and can ask for corrections.

Task mining privacy FAQ

Short answers on lapsed policies, screenshots and checking what a PC will upload.

What happens if the device privacy policy lapses?

Collection pauses. Each agent refreshes the policy every five minutes and each copy is valid for six hours, so a PC that cannot renew its copy stops collecting activity data until it has a valid one again.

Does Opus take screenshots by default?

No: screenshots and screen recordings stay blocked until an administrator allows them in the device privacy policy. If an administrator allows images, text in them can be masked on the server by optical character recognition (OCR) before anyone views them.

Can IT check what a PC will upload before it uploads?

Yes: IT can run a preview on a PC that shows exactly what the agent would upload after privacy filtering. The preview is a command-line option of the Opus desktop agent.

Bring your privacy questions to the demo

Request a demo with your data protection and IT leads, and we'll walk through the device privacy policy, department settings and the employee view in Opus.