If your laptop feels slower than it used to, or you noticed an unfamiliar icon in your taskbar, you might be wondering whether your employer is watching what you do on your work computer. The honest answer is that on a company-owned device, some form of oversight is common, and in most cases it is disclosed somewhere in your onboarding paperwork or IT policy. This guide is not about evading legitimate oversight. It is about telling the difference between the normal technical footprint of a managed device and the specific signs of monitoring software, so you know what you are looking at and can ask the right questions instead of guessing.
A company laptop is rarely a blank machine. IT departments run device management profiles, antivirus agents, backup tools, and update services in the background, and all of that uses some CPU and memory even when nobody is doing anything wrong with it. The goal here is to separate that ordinary system load from the markers that specifically indicate activity-tracking software, and to do it without touching anything you are not authorized to touch on a work-issued device.
Start With What's Normal on a Managed Device
Before you go looking for something suspicious, it helps to know what a legitimately managed computer looks like from the inside. Most organizations enroll company devices in a mobile device management (MDM) system, which installs configuration profiles, enforces password rules, pushes software updates, and sometimes restricts what you can install yourself. None of that is monitoring in the sense of watching your screen or logging your keystrokes; it is device administration, and it is usually mentioned explicitly in an IT policy or employment contract.
On a Mac, this administrative layer typically shows up as system extensions and background login items used to manage and control the device, which is a standard part of how macOS handles enterprise deployment. Seeing an entry like this in your system settings is not evidence of covert surveillance. It is evidence that your company's IT team has enrolled the machine in a management platform, which is expected on hardware the company owns.
The practical takeaway: before you interpret anything as suspicious, check your employee handbook or IT policy for language about device management, acceptable use, or monitoring. If monitoring is disclosed there, what you are looking for next is not "is this happening" but "what exactly is being tracked," which is a fair and answerable question to raise with HR or IT directly.
Check What's Actually Running
This is the part you can do yourself, on your own device, without installing anything or bypassing any security control.
On Windows:
- Open Task Manager and look through the Processes and Startup tabs for anything you don't recognize, especially entries with generic or unfamiliar publisher names.
- Check the system tray and taskbar. Windows 11 surfaces running agents in the taskbar, including third-party background applications, so a monitoring tool that is not deliberately hidden will often show up here.
- Review installed programs in Settings > Apps for anything your IT team didn't tell you about, keeping in mind that legitimate security and backup tools will also appear on this list.
On macOS:
- Open Activity Monitor and sort by CPU or memory to see what's running.
- Check System Settings > General > Login Items & Extensions for background services and system extensions, which is the same location legitimate MDM tools use, so an unfamiliar name here isn't automatically alarming on its own.
- Look in System Settings > Privacy & Security to see which apps have been granted screen recording or accessibility permissions, since a tool capturing screen activity generally needs one of these.
One caution worth flagging here: a process name alone is not reliable proof of anything. Some tools can be configured to disguise themselves under names that resemble core system services, so a suspicious-looking entry deserves a closer look rather than an immediate conclusion, and an ordinary-looking name doesn't rule monitoring out either.
Read the Resource Footprint, Not Just the Names
Here's something most people checking for monitoring software don't think to look at: how much of the machine's resources a background process is actually using. It's a more reliable signal than the process name, because names are trivial to change and resource behavior is much harder to fake convincingly.
Well-built monitoring software on a Mac is designed to run quietly in the background, typically staying under a few percent of CPU and RAM, precisely so it doesn't interfere with your work or draw attention through sluggish performance. On Windows, a monitoring agent's background service handling network data usage typically sits in the tens of megabytes range, not hundreds. If you spot a process consuming a similar, small, steady footprint that never spikes when you're idle and never drops when you're active, that pattern is more consistent with monitoring software than with a crashed update or malware, both of which tend to behave far more erratically.
This cuts against the instinct to assume monitoring software will make your computer visibly slower. If a tool is doing its job well, you likely won't feel it at all, which means a snappy, responsive laptop tells you nothing either way.
Look at Network Behavior, Carefully
Monitoring software has to send the data it collects somewhere, which means it needs an outbound network connection even when you're not actively browsing. If you have the technical means to check outbound connections through your operating system's built-in network tools, look for a process maintaining a quiet, periodic connection rather than the high-volume traffic patterns of a browser or streaming app.
This is also where you should stop if you're not confident in what you're doing. Digging into network traffic on a company-owned device can shade into behavior your IT policy prohibits, even when your intent is just to understand your own equipment. If your acceptable use policy restricts network diagnostics or firewall changes on company hardware, respect that boundary and raise your question with IT instead of working around it.
When the Signs Point to Something, Here's How to Handle It
Suppose you've gone through the checks above and found a background process with an unfamiliar name, a small but constant resource footprint, and a permission grant for screen recording you don't remember approving. What now?
- Don't uninstall or kill the process yet. If it turns out to be an IT-sanctioned tool, disabling it can violate your acceptable use policy and create a bigger problem than the one you're trying to solve.
- Check your onboarding documents and employee handbook for any mention of monitoring, device management, or acceptable use. Many companies disclose this in writing even if nobody mentioned it verbally.
- Ask HR or IT directly, framed as a request for clarity rather than an accusation: "I noticed a background process I don't recognize on my work laptop, can you tell me what it is and what it monitors?" A legitimate program has nothing to hide behind that question.
- Separate personal activity from the device entirely. Whatever the answer, treat a company laptop as a company laptop: keep personal browsing, messaging, and accounts off it, on any device where monitoring is a live possibility.
- If disclosure seems absent where you believe it's legally required, that's a question for an employment lawyer, not a technical one. Notice obligations around workplace monitoring exist in a number of jurisdictions, and what they specifically require varies by location, so this is worth confirming with counsel rather than guessing.
If you want a broader sense of what monitored work actually looks like day to day, beyond the technical fingerprints, a companion piece on bossware signs walks through the behavioral and workplace indicators rather than the system-level ones.
The Employer's Side of This, Briefly
It's worth understanding why a company monitors in the first place, because it changes how you interpret what you find. Legitimate employee monitoring software is generally installed to give managers visibility into how work happens across a team. With a tool like CleverControl, that visibility comes through a secure web account where a manager reviews activity data rather than watching anyone in real time by default: which applications and websites get used during work hours, where a workflow is breaking down, or how a team's time is actually being spent versus how it's assumed to be spent. Managers using tools like this typically review data such as application activity, website activity, and screenshots through a secure web account, not by watching a live feed of an individual's every keystroke without cause.
That distinction matters because it tells you what a reasonably run monitoring program is actually for. A manager reviewing aggregate activity trends to spot a burned-out team or a broken process is doing something very different from a manager fixated on one employee's every click, and a program built around the former should come with a written policy that tells you it exists, even if it doesn't spell out every technical detail. The absence of any disclosure at all, on a device you know is subject to some form of IT policy, is the actual red flag here, more than any single process name.
If your workplace does disclose monitoring, the fair response isn't to hunt for ways around it. It's to understand what's tracked, hold your employer to using that data for legitimate performance and security purposes rather than as a surveillance exercise, and raise concerns through HR if the program feels disproportionate to what the company is actually trying to solve.
A company laptop will always carry some background processes you didn't personally install, and that alone isn't cause for alarm. What's worth your attention is the combination: an unfamiliar process, a small but constant resource footprint, a permission grant you don't remember approving, and no mention of any of it in your company's policies. Check calmly, ask directly, and let the answer from IT or HR settle the question rather than the process name alone.
Frequently Asked Questions
How can I check if my work computer is being monitored without violating company policy?
Use built-in system tools like Task Manager on Windows or Activity Monitor on macOS to review running processes and startup items, and check your login items or extensions list. These are standard system views available to any user and don't require bypassing security controls or IT restrictions.
Is a slow computer a reliable sign of monitoring software?
Not on its own. Well-built monitoring tools are designed to run with a very small resource footprint, so a general slowdown is a weak signal on its own; check the resource footprint of specific background processes, as described above, rather than judging the whole machine's speed.
What if I ask IT about a process and they refuse to explain it?
Ask again in writing, and reference your company's acceptable use or device policy directly, since most organizations are expected to disclose monitoring somewhere in that documentation. If the response still feels evasive, that's a reasonable point to escalate to HR or, if you believe disclosure requirements aren't being met, to consult an employment lawyer.
Can a monitoring process hide itself under a normal-looking system name?
It's possible for monitoring software to be configured with a name resembling a core system service, so an ordinary-looking process name doesn't fully rule out monitoring. This is why resource usage patterns and permission grants are more useful signals than the process name alone.
Does finding monitoring software mean my employer distrusts me personally?
Not necessarily. Many monitoring programs are set up to review team-wide patterns like application usage or workflow bottlenecks rather than to track one specific person, and a policy applied evenly across a team is a very different situation from targeted surveillance of an individual.
Should I try to disable or remove monitoring software I find on my work laptop?
No. On a company-owned device, disabling a monitoring tool without authorization can violate your acceptable use policy regardless of your reasons for doing it. Raise the question with IT or HR instead and let them explain or address it through the proper channel.




