Guide

HR software without AI surveillance

By the Capstan team at PeopleCap · Last updated 17 August 2026 · About 6 min read

Most HR software now ships some form of AI that judges your people, and most of it is a liability you are paying to carry. The safe default is software that stores facts and runs process, and refuses to guess who will quit, who is unhappy, or who is worth interviewing. This guide explains what the risky category actually contains, why it is turning into a legal and trust problem for employers, and how to buy your way around it.

What “AI in HR” usually means

The phrase covers a lot, so it is worth being specific. Four things are worth naming, because they are the ones that end up in employment products.

Attrition-risk scores. A model reads tenure, pay, leave patterns, and activity, then assigns each employee a probability of leaving. Managers get a dashboard of names ranked by flight risk. At startup headcount the sample is far too small for the maths to mean anything, and the moment people learn they are being scored, the score changes their behaviour and poisons the trust it claimed to measure.

Sentiment analysis. Software reads messages, survey text, or reviews and rates how a person feels: engaged, disengaged, at risk. You are now running surveillance on the private tone of your own team, inferring emotion from words, and acting on a machine’s reading of a mood.

AI candidate screening and ranking. A model scores or orders applicants before a human looks. It learns from your past hiring, which means it learns your past bias, and then applies it at scale with a veneer of objectivity. The candidate who was filtered out never knows why, and neither, usually, do you.

Productivity surveillance. Keystroke counts, active-window tracking, activity scores. It measures motion, not work, and it tells your best people that you do not trust them to do the job you hired them for.

The common thread is that each one turns a person into a number, and then treats the number as a fact. It is not a fact. It is a guess with a confident interface.

Why this is a growing risk, not a perk

Vendors sell these features as insight. In practice they import four problems at once.

Bias, laundered. A model trained on your history repeats your history. If your past hiring skewed, the screen learns the skew and calls it a pattern. The bias is now inside a system that looks neutral, which makes it harder to see and harder to challenge.

Regulation is arriving fast. The EU AI Act classifies AI used for recruitment, task allocation, and worker monitoring as high-risk, with documentation, transparency, and human-oversight duties attached. Other jurisdictions are moving the same way on automated decisions about people. When the model lives in your HR stack, the employer usually owns the obligation and the liability for a bad outcome. You inherit the risk the vendor built.

Trust, spent. Employees find out. They always find out. The day your team learns that their messages are being scored for sentiment or their names ranked by quit-risk is the day the honest conversation you actually need becomes impossible. You cannot ask someone how they are doing after you have already had software guess for them.

It does not even work at your scale. Below fifty people the numbers are noisy and the models are unreliable. You are taking on real legal and cultural risk to buy a prediction you should not act on anyway.

The uncomfortable summary: most AI in HR asks you to accept bias, regulation, and broken trust in exchange for a number you cannot trust. That is a bad trade.

What to ask a vendor

You can settle this in one short conversation. Ask the questions that do not have comfortable hedges.

  1. Does any part of the product produce a score, rank, or inference about a named individual? Attrition risk, sentiment, productivity, candidate ranking. A straight product does not, and can say so plainly.
  2. Can a manager see more about a person because of a model than they could work out by hand? Analytics should aggregate and narrow. If a model widens what one person can see about another, that is surveillance with a nicer name.
  3. Is it on by default, and can it be switched off entirely? A feature that is opt-out and buried is a feature the vendor expects you to run without deciding to.
  4. Where is this written down? Ask for the non-goals in public, not the reassurance on the call. A vendor that publishes what it refuses to build is telling you the truth before you sign.

If the answers arrive wrapped in “responsible AI” language without a plain no, assume the feature exists and is running.

Where Capstan stands

Capstan does not put AI in judgement of your people, and this is written down because it is a product decision rather than a slogan.

Nothing in the product produces an attrition-risk score. Nothing reads your team’s messages for sentiment. Nothing counts keystrokes or ranks people by activity. The Recruitment module runs your hiring process and turns a signed offer into an employee record in one step, and it does no AI screening or ranking of candidates: a human reads every application, in a consistent order, on the merits.

The one place people expect a model, Advanced Analytics, is built the opposite way, and the mechanism is worth stating because it is stronger than the promise. Reports run under the identity of the person reading them, so a report can only ever narrow what that person could already see and can never widen it. That is a composition property rather than a policy, which means it cannot be forgotten in a future release the way a rule in a document can. Small groups are suppressed rather than reported, so an aggregate never resolves to a judgement about a single named person. You get headcount, attrition, and time-to-hire as honest aggregate numbers, and you get them without a scoring engine attached.

The same discipline runs through the parts of the product where a model would be easiest to bolt on. Recruitment stores a résumé without parsing it, engagement surveys keep participation and responses in separate tables so a response cannot be traced back to a person, and performance cycles record what humans wrote about each other with nothing generating a rating.

The reasoning is simple. Software should hold the facts about your people and run the process around them. It should not sit in judgement of them. When you want to understand your team, the tool for that is a conversation, not a rank.

If this is the standard you are buying to, read how the HR data security and compliance picture fits together, then look at the security page and the product directly. The core is free up to twenty active employees, and the module prices are public.

Common questions

What is algorithmic management?

It is the use of software to make or heavily influence decisions about people at work: who gets hired, who looks like a flight risk, whose messages read as disengaged, who is judged productive. The system turns a human into a number and then acts on the number. The problem is not that the maths is hard, it is that the number is treated as truth about a person when it is really a guess dressed up as a fact.

Does Capstan use AI to score or rank employees?

No. Nothing in Capstan produces an attrition-risk score, a sentiment reading, a productivity rank, or an AI screen of candidates. This is a deliberate product decision, not a feature we have not built yet. The analytics can aggregate and narrow what a manager sees, never widen it, and never resolve to a judgement about one named person.

Why is AI in HR becoming a legal risk for employers?

Because regulators have started treating employment AI as high-risk. The EU AI Act, for example, places systems used for recruitment, task allocation, and monitoring of workers into a high-risk category with obligations attached. If a vendor bolts a scoring model onto your HR data, the compliance burden and the liability for a biased outcome usually land on you, the employer, not on them.

What should I ask a vendor about AI before I buy?

Ask three plain questions: does any part of the product produce a score, rank, or inference about an individual; can a manager see more about a person because of a model than they could see manually; and can you turn the whole thing off. If the answers are hedged, assume the feature exists and is on by default. A vendor that publishes its non-goals in writing is safer than one that reassures you on a call.

The guide is free. So is the software that does this for you.