Skip to content

Home / Two lives

The Container and What It Actually Separates

Work profiles do most of what they promise. Understanding the edges is what prevents both false reassurance and unnecessary suspicion.

Two lives · Explainer

A work profile space is the main technical answer to the two-owners problem. It is better than its reputation among employees and more limited than its reputation among employers.

The practical lesson in “The Container and What It Actually Separates” is to connect every record to a named decision. Organisations exploring learn more here for stealth computer monitoring software can add structured workforce context, provided the use is disclosed and interpretation is reviewed with the people affected.

What it does

Work applications and their data live in a separate space maintained by the operating system. Company files, mail and documents stay inside it. The employer can configure and remove that space.

For an independent reference relevant to “The Container and What It Actually Separates”, consult the Android Enterprise security resources; compare its principles with the proposed ownership model, access rules and real support process.

The personal side is outside it. Personal applications, files, photographs and accounts are not within the employer's reach, and that is enforced by the platform rather than by the employer's restraint, which is a considerably stronger guarantee.

Removing the container removes the work data and nothing else. This is the property that makes a clean exit possible, which is why the container question is the most consequential technical decision in a BYOD arrangement.

What it does not do

It does not hide the device's existence or its basic attributes: model, operating system version, compliance state are visible, and reasonably so.

It does not prevent somebody photographing a screen, or copying text into a personal note, or forwarding a document to a personal address. Containers separate storage, not intent.

It does not survive the person deliberately dismantling it, which is uncommon and worth knowing.

And it does not apply to anything configured outside it. A work mail account added directly to the device's own mail application sits on the personal side, and this is the commonest leak in practice.

The leak that matters most

Work data arriving outside the container, usually because somebody set something up before the container existed or because an application was installed on the wrong side.

The result is work documents in a personal file store, work mail in a personal client, and an exit process that removes the container and leaves all of it behind.

Checking for this is worth doing: which accounts are configured where, and whether any work application exists outside the work space. Most platforms report it and most organisations never look.

What to tell people about it

That the separation is real and maintained by the device, not by the employer's good behaviour.

That the employer sees the work side and the device's compliance state, and not the personal side.

And that removal takes the work space and nothing else.

Those three sentences answer most of what people are actually worried about, and they have the advantage of being true.

Where a container is not available

Some device types and some older platforms do not support it. The honest options are then full enrolment, which the earlier note argues against on hardware the employee owns, or browser-only access, which the alternatives section covers and which is frequently the right answer.

Checking where things actually live

A container is only as good as the discipline of putting work inside it. Most platforms can report which accounts are configured in which space, and the report routinely shows work mail on the personal side of devices that have a perfectly good container sitting unused. Finding that is a configuration fix rather than a policy failure, and nobody looks.

Explaining it without overselling

Describing the container as complete separation invites the discovery of its edges, and the discovery costs more than the honesty would have. Saying that it separates storage, that the employer sees the work side and the device's basic state, and that somebody determined to move data out of it could, is accurate and is received better than a stronger claim that turns out to be approximate.

Where a container is not enough

For the most sensitive categories of data, separation on an unmanaged device may still not be an acceptable control, and the honest answer is that the work should not be done there at all. Knowing which categories those are requires the classification that most organisations have never done. A BYOD arrangement without a container is an arrangement with no clean way to end. That is the whole of the case for it.

Whose Device, Whose Data