How do you open document usage monitoring?

Open the view from the application menu: Menu -> Monitoring -> Documents. It is used to review document work recognized from user activity, window titles, applications and data collected by the agent on the computer.

Open this view when you want to see which files users worked with most often, which documents appeared last, which applications were associated with them and whether document type recognition looks reliable. Document monitoring also helps separate ordinary office work from days where the number of opens suddenly rises or new dominant documents appear.

The page consists of an Analytics Panel and a records table. In the panel, you move from general counters to document lists, daily charts, period comparisons, anomaly signals, presence hours and checks of detail completeness. One table record represents one monitoring day for one computer. After clicking an entry, the application shows that day's details for the selected workstation and employee, broken down by document, application, process, window title, extension, document type, recognition confidence and active hours.


Day table in document monitoring

The daily table shows the main summary of document work without opening every record's details. It helps you quickly check whether activity was focused on a single file or covered a broader set of documents.

The basic visible columns are:

  • Documents - the number of documents included in the daily summary.
  • Document activity - the number of detected occurrences of document work.
  • Most Used Document - the document with the highest activity on that day.
  • Last Document - the last document noticed in this record.

After expanding the columns, you can also see application, extension, confidence of the last recognition, last application, process, document type and window title. In practice, these fields help distinguish real work with a file from a situation where the document was recognized only from the application window context.

The search includes date, agent, computer, Windows user, active hours, document name, application, extension, document type, process, window title and text stored in details. If you know only part of a file name or notice an unusual extension, entering it in the search field is usually enough.


Analytics Panel in company document monitoring

The Analytics Panel gathers data from the selected period and lets you switch the analysis to day, week, month or a custom range. You can read values as Total or Daily Average, which is useful when comparing a short activity increase with a longer, calmer period.

The most important panel metrics are:

  • Document Count - the total number of documents saved in daily records.
  • Unique Documents - the number of different documents recognized in details.
  • Document activity - the main counter for work with documents.
  • Average Confidence - average document recognition confidence weighted by observations.
  • Recognized Document Types and Recognized Extensions - indicate what share of observations had an identified type or extension.
  • Computers and Employees - show the data reach in the analysed range.

When interpreting the panel, do not look only at the number of documents. High activity with low average confidence can mean the application had ambiguous window titles. A high share of recognized extensions, on the other hand, makes later filtering and ranking review easier.


Rankings in monitoring the most used documents

Rankings show which documents, applications, extensions and document types built activity in the selected period. This view is not only for finding the highest number of opens. It also helps check whether work concentrated on one report, many files of the same type or one specific application.

The panel includes:

  • Top Documents - documents with the highest activity.
  • Top Applications - programs associated with document work.
  • Document Extensions - activity distribution by file extension.
  • Document Types - grouping by recognized document type.
  • Top Computers and Top Employees - places and people where document activity was highest.

If a generally named document appears high in a ranking, check the application, process and window title in details. If one extension dominates, compare it with the watched extension list in the profile. That order makes it easier to decide whether the result comes from actual work or from the way the agent recognizes windows.


Trends and activity hours in document monitoring

Trends show how document work changed across consecutive days. Separate series are available for document activity, unique documents, average confidence, unique extensions, unique document types, computers and employees.

When reading trends, pay attention to:

  • whether activity growth rises together with the number of unique documents,
  • whether a drop in average confidence appears after a change of application or file type,
  • whether extensions and document types stay stable or change abruptly,
  • whether activity belongs to one workstation or a larger group of computers.

The Hourly Document Presence chart answers a narrow question: during which local hours did document activity appear on monitored days? It is not an open count or an observation count. A marked hour only means that document activity was present during that hour.


Comparisons in monitoring document work

The comparison tab reads the selected period against an earlier baseline. In the Documents view, this makes changes in file work intensity, document diversity and recognition quality easier to spot.

When analysing comparisons, check:

  • an increase in Document activity, because it shows more occurrences of file work,
  • an increase in Unique Documents, when you want to assess whether the user worked with a wider set of materials,
  • a change in Average Confidence, especially when new applications or window titles appear at the same time,
  • a lower share of recognized types and extensions, because it makes later document filtering harder,
  • a change in the number of computers and employees, which shows whether the pattern is local or organization-wide.

If the comparison shows a large jump, start with the metric that grew the most. Then move to document and application rankings, and finally open record details. Only there can you see the window title, process, confidence and active hours connected with a specific document.


Anomalies in document and recognition confidence monitoring

Anomalies point to periods and documents that differ from earlier behaviour. In this view, the system analyses not only activity growth, but also lower recognition confidence and documents that suddenly begin to represent a large share of work.

The anomaly mechanism includes:

  • Document activity increased significantly - when the current number of occurrences is clearly higher than in the comparison period.
  • a decrease in average document recognition confidence - when classification is weaker than before despite a sufficient number of observations.
  • New document has a high activity share - when a document absent from the comparison period becomes an important part of current work.
  • Document detection confidence is low - when a frequently observed document has low average recognition confidence.

Anomaly evidence can include current and baseline document activity, document activity increase, average confidence, observation count, activity share, document name, application and window title. For low confidence, start with the window title and process, because they most often explain why the document was classified less clearly.


Record details in document monitoring

After clicking a record, the application shows documents aggregated for one day and one computer. Details combine repeated occurrences of the same document, so you can see not only the latest trace of activity but also the total scale of work with that file.

In the details table, check:

  • document identification: document, extension, document type and item key.
  • application context: Application, process and window title.
  • activity scale: Document activity, activity share and observations.
  • recognition quality: average confidence and minimum confidence, if available.
  • data origin: source, source type and category.
  • time frame: first seen, last seen and active hours.

Hourly filtering is not available for document usage details because the active-hours mask stores event presence and does not split document counters into individual hours. Read details as a daily document summary, not as a minute-by-minute log of file work.


Data quality in document usage monitoring

The data quality section shows whether daily records have complete and consistent document details. This matters because an activity counter without a document list does not let you verify which file, application or window title produced the result.

In this part of the panel you can check:

  • Detail Coverage - the share of records for which a document list is available.
  • Records Without Details - days with document activity, but without a breakdown into items.
  • Current partial data - today's entries that may still be waiting for aggregation to finish.
  • Open historical records - older days left in an unclosed state.
  • Invalid Details - situations where the detailed data structure cannot be read correctly.
  • Days without data - gaps in the selected date range.

A warning for the current day usually does not have to mean a problem, because data may still be processed. If the message concerns closed days, check the agent status, monitoring profile, watched extension list and export of data to the backend.


Document monitoring settings

Data for the Documents view depends on Monitoring Profiles. The agent uses profile settings only after downloading the current configuration to the computer. For this view, the relevant options are in the file activity section and are editable in the profile control.

The most important settings are:

  • File Activity Monitoring - enables base collection of file events, which part of document data depends on.
  • Document Insight - allows the agent to create document usage data from application context, window titles and recognized files.
  • Watched File Extensions - defines which extensions should be considered; by default, the list includes office documents, PDF files, text and configuration files, source code, archives and installers.
  • Watched User Folders - indicates user profile folders watched by the agent, by default Desktop, Documents and Downloads.

If only a small number of documents appears in the view, first check whether File Activity Monitoring and Document Insight are enabled in the profile. Then compare extensions visible in the ranking with the watched extension list. Assess profile changes after the next monitoring day, because daily records are built from data collected by the agent on the computer.