That gap has become expensive. Employment costs have climbed, boards are scrutinising every approval, and "we are stretched" is no longer enough to unlock a requisition.
The organisations handling this well are not hiring less out of stubbornness. They are answering a harder question first: where is our existing capacity actually going, and how much of it is recoverable?
Key Takeaways
- Employer National Insurance rose to 15% from 6 April 2025, with the secondary threshold cut from £9,100 to £5,000, so every approved hire costs meaningfully more than it did two years ago.
- A lot of what looks like a resourcing shortfall is process variation, rework or tool sprawl, none of which a new starter fixes.
- The ICO's guidance on monitoring workers, published in October 2023, explains how existing UK GDPR and DPA 2018 duties on lawful basis, transparency and impact assessments apply at work.
- Gartner research cited in the ICO's 2023 impact assessment put the share of large employers using tools to monitor workers at around 60%, with a rise towards 70% expected.
- Framing matters. Operational visibility gets buy-in, oversight-first messaging does not.
- Measure a small number of things well before rolling anything out broadly.
The Maths Behind Every Requisition Changed
From 6 April 2025, the main rate of employer National Insurance rose from 13.8% to 15%, and the secondary threshold at which employers start paying dropped from £9,100 a year to £5,000.
Deloitte's analysis of the measure put the combined effect in plain numbers. For an employee on average UK earnings of £36,036, employer contributions moved from £3,715 in 2024-25 to £4,655 in 2025-26, an increase of roughly 25%.
The Employment Allowance rose to £10,500 and the previous £100,000 eligibility cap was removed, which softens the blow for smaller employers. For anyone approving hires at scale, though, the cost per head has simply reset upwards.
That is why "add a person" now faces resistance it did not face a few years ago. Finance wants to know what else was tried first.
Most Capacity Gaps Are Process Problems in Disguise
Here is the uncomfortable pattern. A team reports being underwater, a requisition gets raised, the hire lands, and six months later the same team reports being underwater again.
The cause is rarely a genuine shortage of hours. It is more often that the same task takes four times longer in one pod than another, that handovers stall in a queue nobody owns, or that a chunk of the week disappears into rework nobody has quantified.
This is part of a wider shift already reshaping the function. As traditional hiring models come under strain, more organisations are treating internal capability and workflow design as the first lever rather than the last resort.
None of that is visible from a timesheet or a status meeting. It only becomes visible when you can see how work actually moves through the organisation, at the level of the process rather than the person.
What Operators Actually Need to See
The useful questions are structural rather than individual. Which processes have the widest variation in completion time, and why does the fastest cohort finish faster?
Where does work sit idle between steps, and who owns that handover? How much time is going into applications the business is paying for but barely uses?
And critically, what does capacity look like when you strip out duplicated effort? Answering that honestly usually surfaces more headroom than a single hire would have delivered, and it does so without adding to the salary bill.
Software utilisation is the quickest win for most organisations. Licence counts drift upward, teams accumulate overlapping tools, and nobody reconciles what is being paid for against what is genuinely being used.
Billing accuracy is the second. Agencies and professional services firms in particular lose margin when hours land against the wrong client or project, and that leakage is invisible until someone measures where the time actually went.
The output of all this should be a decision, not another dashboard. Either the work genuinely exceeds the team's available capacity and the hire is justified, or the constraint sits in the process and the money is better spent elsewhere.
Choosing Tools Without Losing the Room
Buyers researching employee productivity software are increasingly framing the brief as an operational question rather than a behavioural one, and the stronger products in the category have moved to reflect that. It is a useful correction, because the previous wave was driven by something less durable.
Microsoft's 2022 Work Trend Index found that 85% of leaders said the shift to hybrid working had made it hard to be confident their people were being productive. Buying tools to settle that anxiety rarely ends well, because the anxiety is not a measurable business problem.
Capacity planning, billing accuracy and software utilisation are. A rollout pitched as oversight invites resistance and a quiet arms race, while one pitched as finding and fixing bottlenecks tends to get engagement from the people closest to the work.
Practical selection criteria follow from that. Look for process-level reporting rather than only individual activity, integrations with the systems your teams already use, granular access controls so managers see only their own teams, and a clear deployment story for cloud or on-premise depending on your data posture.
Ask the vendor what a first-90-days measurement plan looks like. If the answer is a feature list rather than two or three operational metrics, keep looking.
The UK Compliance Baseline Is Not Optional
The ICO published its guidance on monitoring workers on 3 October 2023, replacing the 2011 employment practices code chapter and reflecting the reality of homeworking and modern tooling. The guidance itself is not statutory. The obligations it interprets, under UK GDPR and the Data Protection Act 2018, very much are.
The core obligations are straightforward. Identify a lawful basis before anything is switched on, be transparent with workers about what is being collected and why, minimise the data to what the stated purpose requires, and set a retention period rather than keeping everything indefinitely.
A data protection impact assessment is mandatory where processing is likely to result in high risk to workers' interests, which covers a good deal of activity data. The ICO also expects employers to seek and document the views of workers or their representatives unless there is a good reason not to.
Consent is the trap. Because of the power imbalance between employer and worker, the ICO treats consent as unlikely to be an appropriate lawful basis in most employment contexts, so legitimate interests plus a documented assessment is the more common route.
Gartner research cited in that impact assessment put usage among large employers at around 60% back in 2022, with a rise towards 70% expected. On those numbers the differentiator is no longer whether you hold the data. It is whether you can defend how you collected it.
Where Work Intelligence Fits
A newer category has grown up around the operator-first framing set out earlier, built for capacity decisions rather than individual review. Insightful describes its Work Intelligence platform as always-on observability combined with AI-powered process capture, aimed at turning activity data into decisions about capacity and efficiency.
The practical details are what matter at procurement. The company reports more than 5,100 teams on the platform, lists SOC 2, ISO 27001, HIPAA, GDPR and CSA compliance, and offers deployment in the cloud or on your own servers.
It also connects to the systems most operations teams already run, with more than 50 integrations including Jira, Asana, ClickUp, BambooHR and GitLab. Individual employees can be given access to their own data through Employee Login, which makes the transparency conversation considerably easier to have.
None of that removes the need for a DPIA or a clear internal policy. It does mean the compliance and transparency groundwork is supported by the product rather than working against it.
The Short Version
The next requisition on your desk may well be justified. The point is that you should be able to prove it with something better than a manager's impression of how busy the team feels.
Recovered capacity is cheaper than recruited capacity, and in the current cost environment that difference compounds quickly. Find the headroom first, then hire against what is genuinely left.
FAQ
Do UK employers need employee consent before collecting workforce activity data? Usually not, and consent is rarely the right basis. The ICO treats consent as unlikely to be appropriate in employment because of the power imbalance, so most employers rely on legitimate interests supported by a documented assessment.
When is a DPIA required? Wherever the processing is likely to result in a high risk to workers' interests, which covers most systematic collection of activity data. The ICO also expects the assessment to be revisited when the scope or technology changes.
How is this different from older monitoring tools? The older category was built around individual oversight. The newer framing is built around process visibility, capacity planning and efficiency outcomes, with reporting aimed at operators rather than line-by-line review of individuals.
How do you introduce this without damaging trust? Tell people before it happens, explain the specific business problem it is solving, give workers access to their own data, and publish a plain-language policy. Consulting worker representatives early is both an ICO expectation and the fastest route to buy-in.
What should we measure in the first quarter? Pick two or three operational metrics tied to a decision you are about to make, such as process cycle time, idle time between handovers or software utilisation. A narrow, well-defined pilot beats a broad rollout with no hypothesis attached.





