You can edit almost every page by Creating an account and confirming your email.

OctoWatchDLP

From EverybodyWiki Bios & Wiki

OctoWatch DLP
Type of site
Employee monitoring and data loss prevention software
Available inEnglish
Founded2007-04-23
OwnerKOLIBRI LLC
Websitehttps://octowatchdlp.com/
RegistrationYes
Users1000
Current statusActive

OctoWatch DLP (also styled OctoWatch) is a commercial software product for employee monitoring and data loss prevention on Microsoft Windows workstations and Windows terminal servers. It is developed and marketed by KOLIBRI LLC and offered in both cloud-hosted and on-premises deployments.[1]

The platform records user activity through a local agent (the Grabber) and presents collected data in a browser-based Web Console for administrators. Typical use cases include workforce productivity analysis, insider-risk investigation, policy enforcement on removable media and web access, and attendance or timesheet reporting.

Overview

OctoWatch sits in the mid-market category of unified user activity monitoring (UAM) tools that combine time-and-activity reporting with endpoint DLP controls. Unlike lightweight time trackers that focus mainly on clock-in and screenshots, the product is positioned as a full endpoint suite: visual surveillance, application and website metering, communication capture, file and device controls, and rule-based alerts.

Licensing is based on the number of actively tracked users (floating seats). Operators of the Web Console are not counted against the license pool. Organizations may choose a narrower Time Tracking edition or a broader Employee Monitoring edition; both are available as cloud service or self-hosted server.

History and company

Public materials associate the product with KOLIBRI LLC, with a founding date of 23 April 2007. The commercial website and cloud console are published under the OctoWatch DLP brand. Technical documentation and installer paths still reference the legacy product name SPM in some filesystem locations and binaries, reflecting an earlier branding generation of the same agent–server lineage.

Architecture

Components

  • Grabber — Windows endpoint agent that collects monitoring telemetry and applies local filtering or blocking where configured. Deployment methods include manual install, Active Directory Group Policy, installation utilities, and remote tooling such as PsTools. Silent installation switches and optional PIN parameters are supported.
  • Web Console — central operator interface for configuration, live observation, analytics, investigation views, and reporting. In the cloud model the console is reached at a vendor-hosted URL; on premises it is served from the customer’s server.
  • Server (on-premises only) — backend that stores monitoring data, typically on Microsoft SQL Server (Express and higher editions are documented; PostgreSQL is described as experimental). Optional Recognition Server components can run OCR and speech-related processing on a separate machine.

Deployment models

Mode Typical footprint Data residency
Cloud Grabber on endpoints; vendor-hosted console and storage Encrypted hosted environment operated for the customer account
On-premises Server + database + Web Console + Grabbers Fully under customer control; outbound connectivity mainly for license activation

Cloud signup and account management are handled through the application portal. On-premises rollouts generally follow the sequence: install server and database, configure the administrative console, then distribute Grabbers to endpoints. Vendor guidance discourages routing agents solely over unstable VPN links, because intermittent tunnels can interrupt data delivery.

Features

Activity and productivity

The Settings Profile controls what the Grabber records. Documented capability areas include:

  • Active and idle time, application launches, websites, and search queries
  • Productivity categorization and analytics dashboards
  • Chronometry and timesheet views for attendance-style reporting
  • Day Viewer timelines that reconstruct a user’s workday from captured events

Visual and live monitoring

Operators can open Live sessions for remote screen viewing and optional remote control (VNC-related ports are documented in product materials). Historical evidence is available through screenshots and video recordings. Webcam and microphone monitoring can be enabled where policy allows.

Communications and content channels

Captured or inspected channels include keystrokes, email and instant messaging, clipboard contents, printed documents, file operations, removable (USB) media activity, network interface and traffic summaries, and web-form submissions (URL-encoded and multipart POSTs).

Data loss prevention and risk

A separate Rules Profile defines conditions and actions such as notification, website blocking, or file/USB restrictions. Hits surface in a Risks view and can trigger email alerts. Blocking of internet traffic or file operations additionally depends on Computer Profile filtering options. Anomalies views cover formal schedule deviations and related alerts (for example geolocation change when location tracking is enabled).

Stealth and transparency

Monitoring runs in stealth by default. Administrators may enable a visible monitoring warning, allow users to toggle monitoring, or restrict recording to timetable-defined work hours. Product documentation does not claim invisibility in Windows Task Manager as a marketed guarantee.

Location

Optional location tracking uses IP-based geolocation on a recurring interval, with GPS/GLONASS when a receiver is present on the PC. Location appears in overview widgets and can raise geolocation anomalies; the product is not a phone-centric GPS workforce tracker.

API and reporting

A REST API (JWT authentication) supports programmatic access to users, reports, and data export in the cloud environment. The console also provides report delivery, report generation, and background job tooling for scheduled or ad-hoc exports.

Editions and licensing

Commercial packaging distinguishes:

  • Time Tracking — oriented toward hours, attendance, and activity metrics with a softer privacy framing in marketing materials
  • Employee Monitoring — full visual, communication, and DLP feature set

Both editions can be purchased for cloud or on-premises terms (including multi-month and lifetime options via the public pricing calculator on the vendor site). Licenses float across active tracked users; blocked users do not consume seats.

System requirements and scale

The Grabber targets Windows Vista and later, including multi-session Windows Terminal Server / RDS environments (no separate Citrix module is marketed). Typical agent traffic is described on the order of a few hundred megabytes per user per day, depending on enabled modules. On-premises sizing guidance roughly allocates CPU and disk budget per tracked user under default retention settings. Express SQL databases have practical size ceilings that limit very large fleets unless upgraded.

Privacy, compliance, and market positioning

OctoWatch is marketed to organizations that need Windows-endpoint visibility for hybrid and office workforces, including regulated verticals (healthcare, finance, government, BPO, and similar). Compliance messaging emphasizes customer control of monitoring scope, role-based console access, encryption of stored data, and the availability of on-premises hosting for data-sovereignty requirements. Dedicated marketing landings discuss GDPR- and HIPAA-oriented deployment patterns; these pages describe product configuration options rather than formal certification claims unless separately attested.

In competitive taxonomies the product is grouped with full EMS+DLP suites (peer class often compared to Controlio, KeepActive/Kickidler, Teramind, and FalconGaze SecureTower) rather than with timer-only SaaS tools.

See also

External links

  1. "OctoWatch DLP". Retrieved 2026-09-04.