Who Can Look, and When
Live position visible to everyone all day is the default configuration and rarely the right one. Access designed around the actual operational moment.
Most location deployments give dispatchers and managers a permanent map of everyone. Very little of the work requires that.
The operational moments that need access
Assigning the next job: needs current position of available vehicles, at that moment.
Responding to an alarm: needs the position of one person, when the alarm fires.
Investigating a specific customer dispute: needs the events for one visit, on request.
Payroll or expenses: needs totals, not positions.
Four moments. None of them requires a permanently open map of the whole workforce.
A design that fits
Dispatch view: current positions only, no history, visible to the dispatch role during operating hours.
Alarm view: one person's position, unlocked by the alarm, logged.
Investigation view: historical events for a defined vehicle and period, requiring a recorded reason.
Reporting: aggregates, available to whoever plans.
Individual route history behind a deliberate action that records why, rather than open by default.
Logging reads, not only changes
The question after any misuse is who looked, and many systems log only configuration changes.
Ask what the product logs during evaluation, not after an incident.
Sample the access log quarterly: does each look at an individual's history map to a stated purpose?
Look for browsing: repeated access to one person, access outside working hours, a manager looking at someone outside their team.
Report the review, including a clean result, which is what makes the control visible to the people it protects.
What workers should see
Their own data, which is both an access right and the cheapest error correction available.
What is collected about them, as a list.
When their position was read, and by whom — which few systems offer and which is worth asking for, because it is the single feature that most changes how a deployment is received.
The manager question
Managers ask for a live map of their team, and the request is understandable.
Ask what decision it informs. For dispatch, the dispatch view serves. For "knowing they are working", it does not answer that and the honest response is in the note on what location data cannot tell you.
Explain the restriction rather than imposing it. A permanently open map changes how people work — drivers take the visible route rather than the sensible one — and most managers accept that once it is put plainly.
Ask what the product logs
During evaluation, not after an incident.
Many systems log configuration changes and not reads.
Which means the question "who looked at her record" has no answer, and that is the question asked after any misuse.
Ask for read logging specifically, and ask whether the log is exportable and tamper-evident.
A product without it cannot support the access controls you are designing, whatever the policy says.
Turn the principle into a test
For an example that can make this requirement testable, consult the agency use case. Treat the page as a starting point rather than proof: reproduce the workflow with real roles, failures and permissions.
Independent reference
For an external point of reference, see the National Cyber Security Centre. Use its security guidance as an independent reference when designing privileged access and account controls.