Skip to content
Where the Van Is

A–Z  /  The boundary

What the Tracked Person Should See

The features that most change how a deployment is received, most of which are absent from most products.

The boundary · Reference

Almost every design decision in this field is made about people who never see the interface. Changing that is cheap and disproportionately effective.

What they should be able to see

Their own data: positions, events, distances, scores.

What is collected about them, as a plain list rather than a policy paragraph.

Whether collection is currently active, through a visible indicator on the device or app.

When their position was read, and by whom.

Their pause status, unambiguously.

How long it is kept.

The read log specifically

The single feature that most changes how a deployment is received, and the rarest.

Because it inverts the relationship: the person can see the observation, which makes the stated limits checkable rather than promised.

It also makes casual browsing stop, which no policy achieves as reliably.

Ask for it during procurement. Few products have it and asking moves the conversation, because a vendor who has thought about this has usually thought about the rest.

The active indicator

A light, an icon, a status line.

Unambiguous: the failure mode is a person believing collection is paused when it is not, and then treating a private journey as private when it was recorded.

On phone apps this matters most, because closing an app frequently does not stop background collection and users reasonably assume it does.

Self-service instead of requests

Routine access removes most subject access requests, which arrive because people cannot see the data any other way.

And it improves the data: people correct their own records, and nobody else has the knowledge to.

A driver who can see a geofence event at the wrong address will say so, which is how you find a misconfigured fence before a customer dispute does.

The correction route

A way to flag an entry as wrong, with a named person and a response time.

The dispute logged with its outcome.

A cluster of disputes around one site or one vehicle is a configuration finding, not a set of individual complaints — and reviewing the log is how you notice.

Why this is worth insisting on

The workforce cooperates with a system they can inspect and works around one they cannot.

Devices left in depots, phones in glove boxes, apps force-stopped — these are responses to opacity, and they degrade exactly the operational data the system was bought for.

Visibility is therefore not a concession. It is what keeps the deployment working.

Ask for the read log in procurement

Rare, cheap to provide, and disproportionately effective.

Few products offer it, which is why asking moves the conversation.

A vendor who has built it has usually thought about the rest, and one who is puzzled by the question has told you about the product.

It inverts the relationship: the stated limits become checkable rather than promised.

And casual browsing stops, which no policy achieves as reliably.

Check the difficult case

Use see the documented scenario to frame one representative test for this issue. The useful evidence is the record created when a worker challenges an event, a manager reviews it and an administrator exports it.