A Fair Mouse Jiggler Policy for Remote Teams (Free Template)
If you monitor activity levels and have not written down what counts as acceptable, you already have a mouse jiggler policy — it is just unwritten, inconsistent, and decided case by case by whoever notices first. This page gives you a policy you can copy, and explains the reasoning behind each clause so you can defend it when someone pushes back.
We make time tracking software with activity monitoring, so read the recommendations with that in mind. Our commercial interest would be served by telling you to detect harder and punish faster. We think that is bad advice, and the policy below reflects what actually holds up when a real dispute happens.
Start by deciding what you are actually measuring
Most jiggler arguments are really arguments about a badly chosen metric. Before writing any policy, answer this honestly: does an idle minute cost you money?
For hourly billed work — agencies billing clients, BPO contracts, anything where hours are the invoiced unit — yes. If you bill a client for an hour, that hour should contain work. Idle time is a billing accuracy problem and you are entitled to care about it.
For salaried outcome-based work, usually no. If a developer ships their work, the fact that the mouse stopped moving for forty minutes while they read documentation is not a loss. Measuring their input activity is measuring the wrong thing, and any policy built on it will produce false conflicts.
Teams that skip this question end up with a policy that punishes thinking. That is the single most common failure mode here, and it drives away exactly the people you least want to lose.
Why people use jigglers — the uncomfortable list
A fair policy has to acknowledge that not every jiggler user is defrauding you. From what employers actually find when they investigate:
- Fear of a status light. Someone read a spec on paper for twenty minutes and does not want to explain "away" to a manager who treats it as slacking. The jiggler is defensive, not fraudulent.
- Genuinely idle work. Long compiles, renders, uploads, waiting on a customer. The work is happening, but the machine registers nothing.
- Bathroom and coffee anxiety. If the culture treats any gap as suspicious, people manufacture continuity.
- Actual time theft. Being paid for hours not worked. Real, and the reason the category exists.
- Overemployment. Holding down a second full-time job. The rarest case by a wide margin — only about 444,000 Americans work two full-time jobs, roughly 1 in 364.
A policy that treats all five identically will be experienced as unjust, because it is. The first three are culture problems that a policy can fix. Only the last two are misconduct.
The policy template
Copy this, change the bracketed parts, and delete anything that does not fit how you actually work. It is deliberately short — a policy nobody finishes reading does not govern anything.
[COMPANY] Activity Monitoring and Input-Simulation Policy
1. What we measure and why. During time you have voluntarily tracked to [COMPANY], our time tracking software records [screenshots at randomised intervals / keyboard and mouse activity levels / the applications and sites open during tracked time]. We do this to [bill clients accurately / verify hours for payroll], not to assess how hard you are working minute to minute. Tracking runs only while you have the timer on. It does not run outside tracked hours, and it never runs on personal devices unless you have chosen to install it there.
2. Idle time is normal and is not misconduct. Reading, thinking, meetings away from the keyboard, phone calls, waiting on a build, and short breaks all produce low or zero activity. None of these are a problem. You do not need to justify ordinary gaps, and you will never be asked to.
3. What is not allowed. Do not use any tool, script, hardware device, or physical arrangement whose purpose is to make the tracker record activity when you are not working. This includes mouse jigglers (hardware or software), auto-clickers, key-repeat macros, and similar. The rule is about simulating work, not about periods of genuine low activity.
4. If your work is genuinely idle. If your role regularly involves long unattended waits, tell [manager/role] and we will [exclude that project from activity requirements / agree a different measure / switch you to manual time entry]. We would much rather adjust the measurement than have you work around it.
5. How we handle a flag. Our software flags patterns consistent with simulated input for human review. A flag is not an accusation and is never actioned automatically. If something is flagged on your account, [manager/role] will talk to you first, tell you what was flagged and when, and give you the chance to explain. Explanations are accepted in good faith unless there is clear evidence otherwise.
6. Consequences. First occurrence: a documented conversation, and correction of any affected timesheet. Repeat or deliberate falsification of billed hours: [normal disciplinary process], up to and including dismissal. Recovery of overpaid amounts will follow [jurisdiction/contract] rules.
7. What you can see. You can view your own tracked time, screenshots and activity data at any time. You may delete your own screenshots; a marker remains showing a deletion occurred, but the image is gone. You can ask [DPO/role] what is stored about you and request its deletion in line with [privacy policy link].
8. Questions. If any part of this feels unreasonable, say so — contact [role]. A monitoring policy that people cannot question is a policy that gets worked around.
Why each clause is written that way
Clause 2 does the heavy lifting. Explicitly protecting idle time removes the main innocent reason people jiggle. If low activity is safe, defensive jiggling disappears and remaining cases are far more likely to be real. Most policies omit this and then wonder why the behaviour persists.
Clause 3 targets intent, not activity levels. "Do not simulate work" is enforceable and fair. "Maintain 60% activity" is neither — it is trivially gamed by the exact tools you are banning, and it punishes roles that are legitimately quiet. Never set a numeric activity floor. It is the most common mistake in this category.
Clause 4 gives an exit. Every workaround exists because a legitimate need had no legitimate route. Provide the route.
Clause 5 is the one that protects you legally. Automated detection producing an automated consequence is exactly the kind of processing that regulators scrutinise, and under GDPR Article 22 individuals have rights around solely automated decisions with significant effects. Human review is not a nicety, it is the defensible design. It also protects you from the base-rate problem: when the underlying behaviour is rare, most flags are false positives, and a policy that acts on flags without review will mostly punish innocent people.
Clause 7 is what makes the rest credible. Monitoring that employees cannot inspect feels like surveillance. Monitoring they can see feels like measurement. The difference costs you nothing and changes how the whole system is received.
What to do before you publish it
- Check works councils and local law. In Germany, monitoring generally requires works council agreement. Several EU states, and some US states, have notice or consent requirements that go beyond GDPR. This template is a starting point, not legal advice, and it is not a substitute for someone qualified reviewing it in your jurisdiction.
- Give notice before it takes effect. Introducing monitoring retroactively is the fastest way to lose the room.
- Say what happens to the data. Retention period, who can view it, when it is deleted. If you cannot answer those, fix that before publishing a policy.
- Apply it to managers too. Policies that exempt the people who wrote them are read exactly as they deserve.
Detection, and its limits
Since we build this: detecting simulated input is genuinely tractable. Synthetic events tend to have signatures human input does not — unnatural regularity, movement without corresponding application state changes, activity patterns no person produces. Our faked-activity detection surfaces these into a review queue for a person to decide on. It never issues an automatic accusation, and that is a deliberate design decision rather than a limitation we are apologising for.
What detection cannot do is read intent. It cannot distinguish "left a video playing to look busy" from "ran an automated test suite that moved the cursor". That gap is exactly why clause 5 exists.
If your real worry is not jigglers but someone holding a second job, that is a different problem with a different signal set, and a much smaller population than the coverage suggests — we went through the actual figures in the overemployment numbers, and there is a practical guide at overemployment detection for remote teams.
The short version
Protect idle time explicitly. Ban simulation, not silence. Never set a numeric activity floor. Route every flag through a human before it has consequences. Let people see their own data. Then most of this problem stops being a monitoring problem, because you have removed the reasons honest people were working around you in the first place.
This template is offered freely — adapt it, republish it, no attribution required. It is not legal advice.