I found an application simply called "Agent" requesting access to my screen on a work Mac. It appears to be made by Veriato, whose products are marketed for employee activity monitoring. I'm trying to understand what it can actually collect, whether removing its permissions would stop anything, and how Windows users could verify what is installed and active.
Can it capture keystrokes, screenshots, applications, websites, or live screen activity? If the computer is managed through MDM or other corporate tools, would disabling permissions be blocked or reported? I'm not looking for advice to immediately quit—I'd like a practical explanation of what this software generally does, how to confirm whether my employer is using it, and what privacy expectations apply on company equipment.
5 Answers
On a managed Mac, the important permissions may be delivered through MDM configuration profiles and Apple’s privacy controls. Check System Settings for device-management or configuration profiles, and review the privacy permissions for screen recording, accessibility, input monitoring, and full disk access. If a permission is centrally approved, the control may be locked or may revert after you change it. If a change sticks, that only shows the permission was locally controllable—it does not prove the agent has been fully removed or is inactive.
The safest assumption is that anything done on a company-owned computer can be monitored. Don’t use it for personal browsing, private messages, financial accounts, or anything you would not want the employer to know about. On Windows, Task Manager, installed-program lists, services, scheduled tasks, security software, and the company’s management console may reveal components, but a normal user account may not show the full picture. Network traffic can also be encrypted or routed through corporate systems, so lack of an obvious connection is not proof that monitoring is absent.
Veriato deployments can be configured to record or report several types of activity, including application and website usage, keystrokes, mouse activity, screenshots, and sometimes live screen viewing. The exact behavior depends on the modules and policies enabled by the company, so finding the agent alone does not prove that every feature is active. Some organizations use it for focused investigations or alerts rather than continuously reviewing every employee’s screen.
Some installations are limited to particular teams or events. For example, screen capture may be enabled for customer-service review while other users only generate application or security telemetry.
The practical separation is simple: use a personally owned computer for personal activity and treat the work device as observable. Whether the employer is measuring productivity, investigating suspicious behavior, or merely collecting security telemetry, you generally cannot guarantee privacy on equipment and accounts they control. Monitoring also does not automatically mean a person is watching every keystroke in real time; many systems collect events and generate alerts according to configured rules.
First confirm that the software is company-approved. Ask IT or security what the Agent process is, which features are enabled, what data is collected, and how long it is retained. An unexpected monitoring tool could be a legitimate deployment, an old component, or a security incident. Don’t tamper with it while investigating; disabling an endpoint agent can trigger alerts, cause management settings to be reapplied, or violate company policy.

Monitoring is not necessarily unlimited or lawful everywhere. Notice, retention, and permitted collection vary by country and workplace policy, so checking the employment agreement or asking HR, IT, or a works council what is collected is reasonable.