Workplace Surveillance and Insider Threat Risk Management: Legal Limits and Privacy Harms. In 2026, Haywood Gelman and colleagues made this research available through arXiv. They examine a security-design problem: organizations use surveillance for legitimate purposes, including insider-threat detection, but excessive monitoring can violate legal requirements and privacy principles. Insider-threat detection can serve a legitimate security purpose, while focused and proportionate monitoring addresses the legal and privacy concerns raised by excessive surveillance. An insider threat involves someone with authorized access whose intentional or unintentional actions may damage corporate assets. Workplace monitoring can include cameras, software and hardware that observe activity or network use, and personal devices connected to corporate infrastructure. Organizations use these capabilities to monitor productivity, protect sensitive assets, enforce policy, and meet legal obligations. That creates tension: employees often view software and hardware monitoring of activity and network use as an expression of employer distrust and a violation of their data-subject rights. The review asks what electronic and physical surveillance organizations use, where legal limits and privacy harms arise, and how monitoring could be refined to address current gaps. It reframes focused surveillance around the insider-threat personas responsible for risk. This is presented as a descriptive argument, not a measured comparison. The listener should therefore treat it as a framework for monitoring rather than a quantitative comparison. Gelman and colleagues conducted a descriptive literature review. They searched academic databases and Google Scholar. They also searched the wider web for research and public materials about security, privacy, and law. After applying consistent criteria and removing irrelevant or duplicate material, they read the selected sources in full. The review drew on 120 sources. This method brings legal, privacy, and security literature together, but it is a synthesis of existing material rather than a controlled test of monitoring systems. The analysis groups insider risk into accidental actions, deliberate actions, and actions driven by an available opportunity. It argues that the prospect of insider threats within an organization should be the target of employee surveillance. The review also draws on earlier work describing behavioral and psychological patterns that may precede insider risk, including difficulty following policy and online oversharing associated with stress or time pressure. It identifies excessive alerts that may obscure meaningful insider-threat indicators. The legal and privacy discussion uses representative cases involving productivity monitoring, biometric technologies, and sensitive employee information. The researchers identified examples where collection exceeded its stated purpose or created significant privacy risks. They also examined how surveillance tools collect, analyze, and distribute information for different purposes. Aggregating records, identifying individuals, and reusing data for a secondary purpose were treated as particularly problematic. In this framing, risk depends not only on what is captured, but also on how the information is combined and reused. This is descriptive research, and its discussion should not be read as a quantitative comparison. Its discussion of insider factors should not be interpreted as a quantitative comparison. Pandemic-era employee monitoring is outside scope. The analysis says a gap in insider-threat training could benefit from empirical research. For security and privacy teams, the recommendations cover three themes. For governance, examine transparency around the existence and extent of surveillance programs. For people, educate employees about insider risk. For detection, tune systems toward relevant behavioral and psychological indicators while keeping collection focused and proportionate. Also check whether alert volume may be obscuring meaningful signals. These are policy, training, and technical recommendations within a descriptive review, not a quantitative comparison. Gelman and colleagues connect workplace monitoring to insider risk and its legal and privacy harms. Their recommendations call for more focused and proportionate monitoring, better surveillance transparency and insider-threat education, and detection tuned to relevant behavioral and psychological indicators. Because the work is descriptive, it should not be read as a quantitative comparison of monitoring approaches. It contributes policy, training, and technical recommendations while noting that a gap in insider-threat training could benefit from empirical research.