Skip to main content

Employees

Introduction to Employees

The Employees screen displays all users and their current status, login history, assigned computers, and other details. You can also manage users directly by enabling or disabling monitoring, locking or unlocking computers, editing profiles, and archiving or restoring accounts, etc.

1. Click the New employee button to create a new employee. See the Creating a New Employee section below for more information.

2. The report comes with three pinned filters (Monitored, Name, Online) applied by default. You can apply additional filters by clicking the Filters button. Check out the Filters section to learn more about filters.

3. Click the Grid icon to add or remove columns from the report. For instructions on organizing columns and rows within a grid widget, refer to the Adjusting Grid Columns and Rows section.

Here’s a description of each column:

  • Name: Shows the name of the employee. Clicking the name will take you to the employee's details page. If you see a Warning icon next to an employee’s name, it means they aren’t licensed. An unlicensed user’s activities will not be monitored even if you have monitoring enabled for them.

  • Email: Shows the email address of the employee.

  • Department: Shows the department the employee belongs to.

  • First Online Time: Shows the date and time the user first came online.

  • First Online From: Shows the computer the user logged in from for the first time.

  • Last Login: Depending on the computer's state, this column will display the following:

    • If the user is offline, it will show the date and time the user last logged in.

    • If the user is currently online, this column will show "Online".

  • Last Login From: Shows the computer the user last logged in from.

The First Login, First Login Computer, Last Login, and Last Login Computer are particularly useful when tracking remote and offsite staff.

  • Status: Displays the user’s status, such as: “Monitored”/“Not monitored”, "Archived", “2FA”/”No 2FA”, “Locked” (see below), etc.

  • Monitored: Shows if the user is currently being monitored or not.

  • 2FA: Shows if 2-Factor Authentication is enabled for the user.

  • Role: The Account type/ Access Level of the employee. For example, “Administrator”, “Employee”, etc.

4. Click the Three Dots at the corner to access the Dashboard Actions menu. From the menu, you can: import employees and export the employee list as a CSV file.

5. Click the Three Dots in front of a row to access the Employee Actions menu. From the menu, you can perform various actions on the employee, such as enable/disable monitoring, lock/unlock their computer, edit profile, archive/restore, etc. Check out the Single Employee Actions section to learn more.

6. You can click the Checkbox in front of employees to select multiple employees to perform batch actions on them. Check out the Multi-Employee/Batch Actions section to learn more.

Creating a New Employee

When you click the New Employee button on the Employees dashboard, a panel on the right side of the screen will let you create the profile. The profile comes with several tabs:

Personal

The Personal tab holds the employee's identity (name, email, photo), the master switch for dashboard access, and their business details (department, position, and pay rate used for cost calculations).

Personal Details

Avatar: Optionally, upload a profile photo for the employee. Click Upload and choose an image - JPEG and PNG files are supported. If no photo is uploaded, the employee's initials are shown instead. When editing an employee who already has a photo, a Remove button appears next to Upload so you can delete it.

First Name / Last Name: The employee's first and last name. These names appear throughout the dashboard - in reports, widgets, the Employees list, and screen recordings.

Email: The employee's email address. This is their login identity for the dashboard and where invitations and reports are sent. For employees using a Stealth (Hidden) Agent, the email field is locked when editing - click Change email next to the field to unlock it*.

Phone: Optionally, enter the employee's phone number.

*Important Considerations for Email Address Changes:

Exercise caution when changing an existing employee's email address. Teramind uses the email as part of the employee's unique ID. If the employee is using a Stealth Agent and you change their email address, you might encounter duplicate employee entries on your Teramind Dashboard. If this occurs, remove the employee associated with the old email ID. You can find the option to remove an employee in the Employee Actions Menu.

Account Essentials

User can login to Teramind Dashboard: Select Yes to allow the employee to log into the dashboard and view their own reports, or No to keep them as a monitored-only user with no dashboard access. This is the same setting as the User can login to Teramind Dashboard checkbox on the Account tab - changing it in either place updates the other. Click the question-mark icon next to the section title for an in-app explanation.

Business Details

Department: Select the department the employee belongs to. Departments are used for grouping and filtering in reports and dashboards (for example, comparing work time or spend by department). If the department isn't listed, add it first on the Departments page. You can also assign or update an employee's department on the Departments page itself - updating a department from either place will overwrite the previous assignment.

Position: Select the employee's job position. The list is searchable - start typing to filter it. To create a new position on the spot, click the small Plus (+) button next to the field, type the position name, and confirm; the new position is added to the list and selected. Positions can also be managed on the Positions page.

Rate: Optionally, enter the employee's pay rate as a number, then choose the rate type: per hour or per year. The rate is used to calculate labor cost - the system multiplies it by the employee's recorded work time to produce the wage/spend figures shown in dashboards and reports (for example, the Spend by Department and Spend by Employee widgets, and payroll reports). A yearly rate is converted to an hourly rate using 2,000 working hours per year (40 hours/week × 50 weeks). Maximum allowed values are $10,000,000 per hour or $100,000,000 per year.

Account

The Account tab controls the employee's working context (default task), their access level (role), what they can see and do in the dashboard (permissions), their interface language, and their password.

Default Task

Allows you to set the default task. This is applicable if the employee is using a Stealth Agent. Check out the Configurations > Tasks section to learn how to create tasks for your employees.

Access Level

Allows you to select the employee's access level (role) / account type. A short description of the selected level is shown below the field (for example, "User has access only to their own tasks" for the Employee level). There are four types of access levels you can choose from:

  • The Administrator is the most powerful access level. They can monitor all employees, other admins, and change any settings with no restrictions.

  • The Infrastructure Administrator has access to the system settings but cannot browse any recordings.

  • The Operational Administrator has access to the system settings, rules, computers, other users, and access control settings of other users.

  • The Employee cannot change any settings.

Check out this article to learn more about account access levels.

Permissions

User can login to Teramind Dashboard: If enabled for a regular user, the user will be able to log into the dashboard and view their own reports.

Allow viewing activity reports: If enabled, the employee can view their own activity reports in the dashboard. This also controls access to Apps & Web activity data in widgets and dashboards, since the underlying data source is gated by the same permission. Requires the User can login to Teramind Dashboard to be enabled.

External User: Enabling this option designates this user as an Active Directory user. By default, their domain password will be synchronized from Active Directory using LDAP. If you are using the LDAP confirmation method for authenticating dashboard changes, you must mark the user as an External user. Note that when you enable this option, an additional setting, Don't synchronize from LDAP - becomes available (see below for details).

Can see own online presence: If enabled, the employee can see their own online/presence status (whether they are shown as online) in the dashboard.

Allow self-history playback: If enabled, the employee can play back their own recorded sessions (screen recording history) in the dashboard.

User can clock in and out using Web interface: If enabled, the employee can clock in and clock out from the web dashboard, for time tracking purposes.

Don't synchronize from LDAP: Available for External users. If you enable this option, the following will happen:

  • The user's password will no longer be synchronized.

  • The "New Password" option will not be visible when you subsequently edit the user.

  • The "Forgot your password?" option on the Dashboard login screen will also not function for these users.

Disable Self Snapshots Report: If enabled, the employee will not be able to access the Snapshots dashboard.

Disable Self Productivity Report: If enabled, the employee will not be able to access the Productivity dashboard (including Time Worked). This also removes work-time and input-activity data from widgets and dashboards, since the underlying data sources are blocked as well.

Disable Self Session Report: If enabled, the employee will not be able to access the Login Sessions dashboard. This also removes Sessions data from other places it could appear - for example, the Sessions event type in All Events grids and any custom widget built on the Sessions data source.

Disable Daily Digest Report: Applicable to users with the Administrator access level. By default, all administrators receive a daily digest email that shows all the users' activities, such as emails sent, rules violated, etc. If you enable this option, then the admins will not receive the daily digest report. The report looks like this:

Disable Self Edit: This option allows you to toggle whether an employee can edit their own profile information - specifically their name, avatar, phone number, and email address. This restriction does not apply to users with an Administrator access level.

Language

Sets the dashboard interface language for this employee. The default option, Instance's Default, follows the instance-wide language setting.

New Password

This feature allows you to reset or change the password. For new employees, leave the field blank and the system automatically generates a temporary password. Any new password must adhere to the complexity rules defined under Configurations > Settings > Authentication > Password. Failure to meet these requirements will result in an "Invalid value" error.

Access Control

The Access Control tab allows you to turn a regular user (Employee access level) into a privileged user by assigning a Role-Based Access Control (RBAC) Policy to them.

Assign Roles

To assign roles:

1. Click the + Add role button to add a role. You can add multiple roles if needed.

2. Select a Role Access Control Policy from the Role dropdown list (see the Creating a Role Access Control Policy section to learn how to create new roles).

3. Click the Select targets button. You will now be able to select targets to grant access to:

4. Select targets (such as Employees, Computers, or Departments) from the Add target dropdown list. These entities define what the privileged employee (whose profile you are currently editing) can access. Selected targets (e.g., “Rob Dcruse”, “macbook air m1”, “Sales” in the example screenshot above) appear as removable tags above the dropdown.

5. Click the Remove button to delete a role along with its assigned targets.

6. To add more roles and targets, repeat steps 1 – 5.

Attributes

The Attributes tab displays synced attributes from your directory integrations (Active Directory, Entra ID, etc.) in read-only format. It gives administrators a quick, centralized view of the identity attributes associated with an employee from your organization's directories - helpful for validating that the right attributes were synced after an import, troubleshooting group or policy assignment issues, and supporting audit, compliance, or forensic reviews without needing direct access to your directory.

Identity Attributes

Each synced directory attribute appears as a key/value pair. For example: “accountType: Service”, “givenName: Abigail”.

Which attributes appear here is controlled by the directory integration's Import attributes setting on the Configurations > Settings > Active Directories integration screen. Only attributes selected there are synced and shown under this section.

LDAP Groups

Lists the directory groups the employee belongs to. For example: "Domain Users", "Project D039", etc. The groups shown here reflect the employee's group memberships in your directory, synced by the integration on the Configurations > Settings > Active Directories screen, and update with every import or scheduled sync. If you don't see expected groups here, check the integration's Import users and computers from OUs selection on that screen. Groups outside the imported OUs won't sync.

Note: If the employee was imported from Active Directory, Entra ID, etc., their attributes and groups are listed here. If the employee was added manually, has not been synced with any directory, or is newly created, the lists appear empty.

Authentication

The Authentication tab shows the employee's two-factor authentication (2FA) status and lets an administrator turn 2FA off if needed. It is available only when editing an existing employee.

2-factor authentication via authenticator app: Shows whether the employee has enabled app-based two-factor authentication. If enabled, click the Disable button to disable it.

2-Factor authentication via Email: Shows whether the employee has enabled email-based verification. If enabled, click the Disable button to disable it.

How to Set Up 2FA

There are two ways 2FA can be configured:

Monitoring

On this tab, you can configure the monitoring settings for the employee.

1. You can specify which monitoring profile to apply to this employee.

2. Several sub-tabs allow you to adjust individual monitoring options. If you manually change any of these settings, a "Custom profile" will be automatically created and assigned to the employee. Each employee can have their own unique custom profile. A custom profile will override any other monitoring profile(s) the employee is part of.

For more detailed information about monitoring profiles and settings, please refer to the Monitoring Profiles section.

Saving & Inviting the Employee

You can click the Submit button anytime from the Create Employee or Edit Employee panel to save the employee's profile (provided you have filled out all mandatory fields).

To save the employee's information and send them an email invitation to install the Teramind Agent at the same time, click the Send Invite & Submit button.

You can also invite the employee from these places:

Editing an Employee / Employee's Profile

You can edit an employee's profile by selecting the Edit Profile option from the Employee Actions Menu.

Editing a profile is similar to the process of creating a new employee.

Importing Employees

Import Guideline

Review your CSV file against these requirements before importing:

  • Use the official template: Download the sample template first - it shows exactly how each field must be formatted and gives you the correct header row.

  • Check the file format: Save the file as .CSV before uploading.

  • Use unique email addresses: Every employee must have a unique email. A row fails if its email is already in use by an existing employee, or if the same email appears twice in the CSV file. The import is create-only - it never updates an existing employee.

  • Positions and departments are matched by name - and created if missing: You do not need to create them first. If a position or department in the CSV doesn't exist yet, the import creates it automatically. Note that matching is case-sensitive: Manager and manager are treated as two different positions, so an inconsistent value creates a duplicate rather than failing. Keep the spelling and capitalization consistent with your existing entries (manage them under Configurations > Positions and Configurations > Departments).

To add several employees quickly, you can import their information from a CSV file instead of entering each one manually.

1. Click the Three Dots at the corner of the Employees dashboard to access the Context Menu. From the Context menu, select Import employees. The Import Employees panel will open:

2. Click the Upload a file or drag and drop link or drop a CSV file directly onto the Upload CSV section.

3. (Optional but recommended) Click the Download Template (CSV) button to download a sample CSV file that shows you how the CSV file should look like.

4. Once the upload is completed, Teramind will automatically try to map its internal fields (e.g., First Name, Last Name, etc.) with the fields from your uploaded CSV. You can override the mapping by selecting the fields from the Uploaded Field column.

5. You can turn on the Email the invitation to the employee option to send out email invitations to the employees to install the Teramind Agent. The email will look like this:

Note that the password will be automatically generated for the employee. The user will be asked to change their password when they log in for the first time.

6. Click the Add Employees button to begin the import process.

If the import succeeds, a message shows how many employees were imported. If there are errors in your CSV file, an error message explains what went wrong and, where applicable, the line (row) of the CSV that caused it. Errors are reported per row: valid rows are still imported, and only the problem rows are rejected. For example, if an employee with the same email address already exists in the system, that row fails with an "Email is already in use" error and the existing employee is left unchanged:

Employee Details: Viewing an Employee’s Monitoring Reports

Click on an employee’s name on the Employees dashboard to access the employee’s detailed monitoring reports.

Activity

The Activity tab shows a chronological record of the employee's app and web activity for the selected date range. If the employee is monitored on multiple computers, it shows combined data from all of them. The tab comes with an activity % chart, an hourly keyboard/mouse heatmap (activity % by hour), and top tasks performed (measured in total work hours), followed by a detailed event grid logging timestamp, computer, app/domain accessed, duration, and other details for each recorded session.

1. At the top-left corner, you will see the employee’s name and their online/offline status. If the employee is online, you can click the Live button to watch their desktop live on the Session Player. If the computer is offline or Live View is unavailable for any reason (e.g., missing Mac screen recording permissions) - you will see when the employee was last online instead.

Under the employee’s name, you will see their basic profile information such as email address, department, phone number, etc.

2. You can turn monitoring on/off for the employee by clicking the Monitor toggle button. Turning monitoring off for an employee frees up a license.

3. The Actions menu lets you perform several actions:

  • View Active Behavior Policies: Select this option to open the Active Policies panel where you can see what behavior policies and rules are currently being enforced on the employee:

    • Click a tab at the top to filter the list by computer: All shows every policy applying to the employee across all computers, or select an individual computer to see only the policies in effect on it. Note that tabs appear only when the employee is monitored on more than one computer.

    • Click a policy name to expand it and view its rules. Each rule is listed with its Category (for example, Activity rule, Schedule rule, etc.) and Action (for example, Warn user, Block user's action, etc.). Click the policy name again to collapse it.

  • Add/Remove Time: Select this option to manually add or remove time. This works similarly to how you add/remove time on the Time Cards dashboard.

  • Resend Invitation: Select this option to invite the employee to install the Agent again.

  • Disable 2FA: This option appears if an employee has Two-Factor Authentication (2FA) enabled, allowing you to disable it.

  • Lock / Unlock Access: The Lock Access option locks the employee's computer. The "Locked" column in the employees list will update to reflect this status. When an employee's account is locked, they will be unable to log back into the monitored computer. The Unlock Access option will unlock the employee's computer.

  • Archive / Restore: Choose Archive to remove the employee from all dashboards and reports. The Restore option will bring the employee back.

  • Employees aren't permanently deleted when archived; instead, they are hidden from computer lists and filters.

  • Archiving an employee will free up a license.

  • Archiving automatically disables monitoring. Restoring an archived employee won't turn monitoring back on - you'll need to re-enable it manually.

4. The Export menu (where available) lets you export the dashboard:

  • Export CSV: exports the data from the grid widget as a CSV file.

  • Export PDF: lets you export the charts/grids displayed on the dashboard as a PDF file.

Some tabs like Snapshots do not have the CSV and PDF export options.

5. Click the Edit profile button to edit the employee’s profile, such as their personal information, account, and monitoring settings.

6. Below the employee’s info, you will see several tabs. These tabs are similar to the Preset dashboards available under the Dashboards menu. For more information about each tab, check out the sections below.

7. On top of the main widget area is the filters section. Each tab on the dashboard comes with a few pinned filters applied by default. You can apply additional filters by clicking the Filters button. Check out the Filters section to learn more about filters.

8. On the grid widget, click the Three Dots in front of a row to access its Context Menu. You can also access it by right-clicking directly on a row. From the Context Menu, you can:

  • Show details record: will open an Activity panel on the right side of the screen, where you can see detailed info about an activity. You can also view the screen recording of the activity or print the details by using the View Record and Print buttons on this panel.

  • View Record: will launch the Session Player so that you can view the video recordings. Note: you can also click the Movie Camera icon next to a timestamp to view the screen recording.

  • Classify: will open the Classify Activity panel, where you will be able to classify the apps/websites. See the Classifying Applications and Domains as Productive/Unproductive section to learn more.

  • View classification profile: to view the classification rules under the currently assigned profile. See the Classifying Applications and Domains as Productive/Unproductive section to learn more.

9. Hover over a widget to reveal the actions you can apply to the widget:

a. Click the Grid icon at the top right corner of a grid widget to open/close its settings panel. From this panel, you can select which columns to show on the grid, create row groups, sum the number of items, etc. See the Adjusting Grid Columns and Rows section to learn more.

b. Click the Filter icon to apply filters to a widget independently of the dashboard filters. The filters work similar to the Dashboard Filters but the scope is applied to the sleeted widget only.

c. Click the Expand icon to expand/maximize the widget in a pop-up window.

Session Log

This tab shows the employee’s login session activities, such as which computer they logged in from, IP, login time, etc. It’s similar to the Login Sessions dashboard.

Time Worked

Tracks an employee's work time, idle time, activity level, and compensation. For in-depth hour tracking, use the Time Cards dashboard; for productivity and performance analysis, head to the Productivity dashboard. Simply filter either dashboard by employee name to view individual metrics or compare results across team members.

Alerts

This tab shows behavior rule violation alerts. It’s similar to the Behavior Alerts dashboard.

Snapshots

This tab shows screen recordings of the employee. The tab come with a few additional options:

1. Use the Computer selection drop-down list to select the computer whose recordings you want to view.

2. Use the Snapshot per row selection to choose how many thumbnails or previews are displayed.

3. Click the Add/Remove Time button to manually add or remove time from the employee’s records. This functions similarly to adding or removing time from the Time Cards dashboard.

4. Hover over an empty time slot and click Add Time to add manual time to the employee’s record, similar to how you would add time from the Time Cards dashboard.

5. Hover over an time slot and click the Trash Can icon remove time from the employee’s record, similar to how you would remove time from the Time Cards dashboard.

Click a thumbnail to launch the Session Player, where you can view the video recording for the session.

Emails

This tab shows the employee’s email activities. It’s similar to the Emails dashboard.

File Transfers

This tab shows the employee’s file activities, such as Access, Read, Write, Upload, etc. It’s like a combined dashboard of File Events and Web File Events dashboards.

Printing

This tab shows the employee’s printing activities. It’s similar to the Printing dashboard.

Keystrokes

This tab shows the employee’s keystroke activities. It’s similar to the Keystrokes dashboard.

Online Meetings

This tab shows the employee’s online meeting sessions. It’s similar to the Online Meetings dashboard.

Computers

This tab shows the history of all computers used by the employee. It’s similar to the Computers dashboard.

Employee Actions Menu

Single Employee Actions

To access an employee's Actions menu, click the Three Dots icon next to their name. The menu offers the following actions:

  • Open Profile: This option lets you view the employee's activity reports.

  • Open Profile in a New Tab: Similar to the above but opens the employee's activity reports in a separate tab.

  • Edit Profile: Select this option to modify an employee's profile. You can also achieve this by clicking directly on the employee's name. A panel will appear on the right, allowing you to edit their personal information, account settings, access control, monitoring options, etc. Editing a profile is similar to the process of creating a new employee.

  • View Live: If the employee is currently online, this option will be available, allowing you to view their desktop in real-time. This opens the Session Player in Live View mode.

  • Enable Monitoring / Disable Monitoring: Use these options to turn monitoring on or off for the employee.

  • Disable 2FA: This option appears if an employee has Two-Factor Authentication (2FA) enabled, allowing you to disable it.

  • Archive / Restore: Choose Archive to hide the employee. The Restore option will bring the employee back.

  • Employees aren't permanently deleted when archived; instead, they are hidden from computer lists and filters.

  • Archiving an employee will free up a license.

  • Archiving automatically disables monitoring. Restoring an archived employee won't turn monitoring back on - you'll need to re-enable it manually.

  • Lock Access / Unlock Access: The Lock Access option will lock the employee's computer. The "Locked" column in the employees list will update to reflect this status. When an employee's account is locked, they will be unable to log back into the monitored computer. The Unlock Access option will unlock an employee's account that was previously locked either by the "Lock" option or by a Behavior Rule's Lock User action.

The Lock Access/Unlock Access action only works on the Stealth Agent. By design, these actions will not be enforced on the Revealed Agent. Please also note that the lock feature isn’t full protection from user tampering. It has the following limitations:

  • Only the selected user account will be locked out. If there are other users on the computer, they will be able to log in.

  • The user may be able to log in using the recovery mode.

  • The user may be able to take out the disk and connect it to another computer and access data.

Multi-Employee/Batch Actions

1. Select one or more employees by clicking the Checkbox in front of an employee's name.

2. An Actions menu will be shown near the top-left corner. From the menu, you can select an action such as enable/disable monitoring, archive the employees, etc. The actions are the same as the Single Employee Actions except for the Bulk edit option – it’s only available when you select employees via the checkboxes.

Editing an Employee's Profile

You can edit an employee's profile by selecting the Edit Profile option from the Employee Actions Menu:

Editing a profile is similar to the process of creating a new employee.

Editing Multiple Employee Profiles Together (Bulk Edit)

You can use the Bulk Edit feature to update common profile attributes such as department, position, account access level, etc. for multiple employees together - saving time on repetitive edits, especially for large teams and departments.

1. Select the Checkboxes next to the employees you want to update.

2. Click the Actions menu to open it, and then select Bulk Edit.

3. Click a tab (e.g., Personal or Account) to edit the information for that section of the profiles.

4. Make your changes and click the Apply changes button.

Did this answer your question?