Skip to main content

Irregular Behaviour Alert

Learn how Insightful flags automated activity like mouse jigglers and auto-clickers, with the evidence to back every case

K
Written by Katarina Dakic

Spot irregular or fake work activity with the help of Irregular Behavior Alert to understand when time theft happens. Some employees rely on tools that make a computer look busy when nobody is actually working — mouse jigglers, auto-clickers, and similar utilities that generate fake keyboard and mouse input. When that happens, the activity data behind your reports stops reflecting real work.

Irregular Behaviour Alert is a type of Attendance Alert that catches this for you. Once a shift ends, Insightful checks the activity recorded during it, flags anything that looks automated rather than human, and gives you the evidence to review the case yourself.

You'll find it alongside your other alert types in Settings → Alerts, with flagged cases reviewed in Alerts → Logs.

What it detects

An Irregular Behaviour Alert looks for three kinds of automated input once a shift is complete:

  • Keyboard jamming — repetitive, automated keystrokes

  • Mouse click jamming — repetitive, automated clicking

  • Input-simulation software — known activity-simulation applications detected during the shift, such as mouse jigglers and auto-clickers

Insightful compares the activity from the finished shift against a maintained list of known activity-simulation applications, then validates the case before an alert is raised — so a case only reaches you at the end of the day, once it clears that check.

Setting up an alert

You create an Irregular Behaviour alert the same way as any other alert:

  1. Go to Settings → Alerts and click New Alert.

  2. Under Attendance Alerts, select Irregular Behaviour.

  3. Give it a descriptive name — this is what appears in the Alerts list and in Logs.

  4. Set the Scope — the employees, teams, or org groups it applies to. This is required; Managers can only choose from within their own scope.

  5. Choose Recipients — e.g. yourself, specific Admins and Managers, or all Admins.

  6. Click Save.

Two things work differently here than on other alert types: there's no Condition field, since the detection logic is fixed rather than configurable, and no Take Screenshot toggle — screenshots in a flagged case come from the employee's existing screenshot settings (if applicable), not from the alert itself.

Every alert you create, edit, or delete is recorded in Audit Logs.

Who can manage an alert

  • An Admin can manage their own alerts and any alert created by a Manager, but not one created by another Admin.

  • An Admin who is a recipient of an alert can open and edit it, but not delete it.

  • A Manager can only manage the alerts they created themselves.

How and when you're notified

Detection only runs once a shift is genuinely finished, never mid-shift, so two things happen on different schedules:

  • The Logs entry appears roughly two hours after clock-out — the fastest place to look if you're investigating something specific.

  • The in-app notification arrives at 08:00 in your organization's time zone, as a single digest covering everyone flagged that day.

The notification names the employee directly if only one person was flagged, or gives a count if there's more than one. Clicking Review takes you straight to Logs, pre-filtered to that day and those employees.

A shift that starts after midnight rolls into the following day's 08:00 digest, so you'll see it a day later than you might expect.

You will also receive an email notification if that option was selected when creating the alert. The report highlights repeat offenders, aka employees who triggered an Irregular Behavior alert more than once in the previous seven days. From the email, you can quickly navigate to the Logs page, automatically filtered to the relevant employee.

Reviewing a flagged case

Flagged cases live in Alerts → Logs. Each entry shows the date and time, employee, computer, category, type, alert name, and author, with a link to screenshots if the employee has them enabled. If an employee had multiple shifts on the same day, they're grouped into a single entry.

Expand an entry and you'll see:

  • The start and end time of the irregular activity

  • Which trigger activated the alert

  • The activity log for that window

  • A daily timeline with the irregular period marked in red, plus a screenshot preview if enabled

  • A link to all screenshots for that window, in a read-only view

If you see an empty state where you expected screenshots, it's one of three things: none were captured during that window, you don't have permission to view screenshots, or screenshots are switched off for that employee.

Good to know

Detection relies on a maintained list of known activity-simulation apps, so a brand-new or unlisted tool may not be flagged yet. Coverage expands over time.

If you have any questions about Irregular Behaviour Alerts, reach out to our support team. We're happy to help!

Did this answer your question?