My Employer Is a Node
The phone in your pocket is yours. The account on it says jim@oracle.com, an administrator you have never met controls what that account may do, and it still feels like your phone — because it is. Work is an app on it. That arrangement is not a compromise anyone settled for; it is written into Apple’s and Google’s own documentation, and it is the shape the next argument will be fought over.
On a personally owned iPhone enrolled through Apple’s User Enrollment, the organisation’s data is removed automatically when you remove the enrolment profile, without touching anything of yours. There is no approval step. The corresponding path on Android is Settings, Passwords and accounts, Work, Remove Work Profile. The mainframe had no such button, because the mainframe was not inside anything you owned.
01The device already settled this
The previous essay ended on a question it could not answer: whether the deciding property of the personal computer was that it could act on its own, or that it had escaped — bought around the procurement queue, owned by the person using it, unplugged by the person using it. I left it open because almost nobody owns their work laptop and almost nobody seems to mind, which looked like decent evidence that the deed does not matter much.
That was the wrong place to look. The corporate endpoint that actually carries most of the day is not the laptop. It is the phone, and the phone is yours.
It is worth remembering how completely the other model lost. Through the late 2000s the corporate mobile device was a BlackBerry, and BlackBerry Enterprise Server was the purest expression of IT provisioning ever shipped to a pocket: the company’s own documentation of the period advertises more than 450 IT policy rules, pushed to assigned users automatically. At its peak, in the third quarter of 2009, BlackBerry held 20.8% of worldwide smartphone sales on Gartner’s numbers, and the subscriber count topped out around 80 million in September 2012, per the company’s own filings. It ended internal hardware development on 28 September 2016. On 4 January 2022 the legacy operating system’s services were switched off entirely, and the remaining handsets stopped being able to place calls.
What beat it arrived with no management capability at all. The iPhone shipped on 29 June 2007 with no Exchange support, no remote wipe, no configuration profiles, nothing an IT department could have said yes to. Apple announced ActiveSync, remote wipe and the App Store on 6 March 2008 and shipped them that summer — roughly nine months after the device had already started appearing in offices. The management came second because it had to. The devices were already in the building, in people’s pockets, bought with their own money.
Three years before the iPhone, a twenty-page position paper by David Moschella, Doug Neal, Piet Opperman and John Taylor gives the pattern its name: the consumerisation of information technology. Their diagnosis is that corporate infrastructures and policies “have become a barrier to innovation and a source of increasing employee frustration.” They were describing a direction of travel, and the direction has not changed since.
02What the container actually permits
The interesting part is not that people use their own phones. It is the legal and cryptographic settlement that grew up to make it workable, because that settlement is where the sovereignty claim stops being a feeling and becomes a specification.
Apple’s User Enrollment, introduced with iOS 13, works by cryptographically separating managed data from personal data on the same device. Google’s work profile does the equivalent on Android. Microsoft’s Intune offers a third variant that does not touch the device at all — app protection policies that work, in Microsoft’s own words, independent of any mobile device management solution, centred on the user identity rather than the hardware.
What an employer can do, by who bought the device
| Capability | Company-owned enrolment | Your device, User Enrollment |
|---|---|---|
| Erase the whole device | Yes | No — managed data only |
| See the serial number or device identifiers | Yes | No |
| See your phone number | Yes | No |
| See every app installed | Yes | No — managed apps only |
| Locate the device | Yes, under Automated Device Enrollment | No |
| Reach personal mail, contacts, messages, call logs, Safari history | No | No |
| Require a passcode | Yes, including complex policy | Yes — but not a complex-passcode policy |
| Configure a device-wide VPN | Yes | No |
| Be removed by the person holding it | No | Yes, from Settings, at any time |
Read the last row again, because it is the one that matters. The person holding the device can end the relationship from a settings menu, unilaterally, without asking, and the organisation’s data disappears while theirs does not. That is a disengagement control — reachable without letting go, exactly the property the third essay in this series went looking for in an aviation regulation and could not find in a Microsoft announcement.
03The containment runs the other way now
Here is the whole thing in one sentence, and it is worth being precise because the two arrangements look similar and are opposites.
Under the mainframe, you were a session inside their system. Today, their system is a partition inside your device.
The system is the ground. Your access to it is a session it grants, on hardware it owns, in a building it controls. Ending the session is its decision. There is nothing of yours in the arrangement to withdraw.
Your device is the ground. The employer holds a scoped, encrypted, revocable sublease inside it, and your working life — the mail, the chat, the CRM — arrives as applications occupying that sublease.
- jim@oracle.com
- your hardware
- their partition
- your settings menu
That is why Slack and Salesforce ship apps, and why the way they ship them is the tell. Slack publishes a separate build for Microsoft Intune whose documentation explicitly covers app management without enrolment, with a configuration key that applies, in its own wording, to unmanaged iOS and Android devices. Salesforce — which bought Slack in a deal announced on 1 December 2020 and closed on 21 July 2021 — goes further with its own app, selling a paid security add-on that protects at the application level specifically so that it does not need to manage the user’s entire device. Two products, one corporate parent, both engineered around the same assumption: the hardware is not ours and will not be.
The employer is not the environment any more. It is one tenant among several, in a space you administer.
04The objection, which is good
The strongest argument against all of this is that I have mistaken a fiscal change for an architectural one. A work profile means the employer owns a cryptographically enforced partition of your hardware, enforced by policy you cannot inspect or alter, on a device you paid for yourself. In some respects that is more control than any 1990s PC was subject to. The employee bought the cage.
I think two things answer it, and neither is a knockout.
The first is direction. The employer’s authority inside its partition is close to total and outside it is close to zero, and that boundary is enforced by a third party — Apple, Google — whose commercial interest runs towards the person who bought the phone. Nobody in 1979 had a party with standing between them and the operator.
The second is revocability, which is the real one. The cage has a door on the inside. The Ivanti research for 2025, surveying a few thousand IT and security professionals and six thousand office workers, found that around three-quarters of IT staff say personal-device use is routine, only about half of organisations explicitly permit it, and where it is prohibited, 78% of employees do it anyway. That last figure is the thing. The endpoint did not merely escape procurement. It escaped policy, and it continues to escape policy in organisations that have written a rule against it.
Where the objection holds firmly is the laptop. There is no rigorous public figure for how many people use a personally owned computer for work — the numbers circulating for this have no published method and I will not repeat them — and corporate PCs are still bought in bulk by IT, tracked by shipment, and enrolled automatically at purchase. On the desk, provisioning won. On the phone, it did not. And a named, dated prediction is worth recording here as a caution against my own enthusiasm: Gartner said on 1 May 2013 that by 2017 half of employers would require employees to supply their own device. It did not happen. Eurostat’s enterprise survey has employer provision of portable devices rising, not falling — 28% of employed persons in 2019, 33.2% in 2024.
05The same question, one level up
Now apply it to the thing actually being sold this year.
An assistant that is useful gets that way by accumulating a model of you: how you work, what you care about, what you would have said, what needs to happen next. Microsoft has a name for that layer and has been explicit that it is the moat. Every hour of use thickens it.
The question is not whether that model is valuable. It obviously is. The question is the one the phone already answered, asked about something less replaceable than a handset: where does the model of you live, and who can delete it?
If it accumulates inside the employer’s tenant, under an identity the corporate directory issued, then the entity learning you is theirs. You are a session again — a very sophisticated one, running for as long as the employment does. When you leave, the model stays and you do not. Every hour you spend making it better is an hour spent improving an asset on someone else’s balance sheet, and there is no settings menu.
If it accumulates on your side, and the employer connects to it the way it connects to your phone — a scoped, encrypted, revocable partition, with clear rules about what it may see — then the topology matches the one that already won, and your working life is again an application running inside something you administer.
Microsoft’s Autopilot, as announced, is the first arrangement. Its agents run under identities issued by the corporate directory, gated by device policy, on central compute, revocable by an administrator. That is coherent, it is well governed, and it is a terminal — a very capable one, which is the point of the previous essay. The desktop application it reaches through is not the agent. It is a window onto an agent running somewhere else, which is the oldest arrangement in this business wearing new clothes.
I do not think that settlement holds, for the same reason BlackBerry’s did not. Not because it is badly built — BES was not badly built, it had four hundred and fifty policy rules — but because the thing it manages will turn out to be something people regard as theirs, and the history of this industry is that when a technology becomes personal, the ownership question gets re-decided by the person holding it, on a timescale no procurement department controls.
The test is simple enough to watch for. When the AI that knows how you work offers you a way to take it with you — and when your employer has to connect to it rather than issue it — the argument will be over. Until then, look for the button. If there is no Remove Management, you are not the ground.
06Where this stops being true
- Already true
- BlackBerry peaked at 20.8% of worldwide smartphone sales in Q3 2009 on Gartner’s sell-through numbers and at roughly 80 million subscribers in September 2012 per its own SEC filings; it ended internal hardware development on 28 September 2016 and switched off legacy OS services on 4 January 2022. The iPhone launched 29 June 2007 without enterprise management; ActiveSync, remote wipe and the App Store were announced 6 March 2008. The CSC consumerisation paper is dated 18 June 2004. The Apple and Google capability rows come from Apple Platform Deployment, Apple Platform Security and Google’s work-profile documentation; the Intune app-protection description is Microsoft’s own. Slack’s Intune build documents management without enrolment; Salesforce sells an app-level security add-on on the same premise. Salesforce announced the Slack acquisition 1 December 2020 and closed it 21 July 2021. The Gartner prediction is dated 1 May 2013. Eurostat’s figures are 28% (2019) and 33.2% (2024).
- What has to happen for the argument to hold
- Someone has to ship a personal AI layer that an employer connects into rather than issues, with a real revocation control on the user’s side, and people have to bring it to work the way they brought the iPhone — before IT approves it. If two years pass and the only durable assistants are tenant-resident, then the phone was a special case, and the reason was the hardware bill rather than the principle.
- Where the shorthand breaks
- The Android container is meaningfully weaker than Apple’s and I have said so rather than averaging them. The Ivanti figures are a vendor survey, disclosed method and large sample, but a vendor survey. Eurostat measures employer provision, not personal-device use, and must not be silently flipped into its complement. There is no defensible public number for personally owned computers used for work, so I have given none. The two-phone explanation people reach for — that corporate-liable programmes lost because nobody will carry two handsets — has no study behind it that I could find, so it appears here as an argument and not as a citation. And Microsoft shipped a $349 thin client in 2025, which is a reasonable reminder that the re-centralising instinct is alive and well funded.
- Where I am probably wrong
- The sharpest version of the counter is regulatory. Between 2022 and 2024 the SEC and CFTC fined banks and brokers well over two billion dollars over business communications conducted on personal devices, and if anything were going to reverse this it would be that. It did not: the documented responses were surveillance software, policy, and clawed-back pay, not repossession of the handset — HSBC blocked WhatsApp on work phones and left personal devices explicitly outside the scope, which tells you what was actually enforceable. But a sufficiently determined regulator could make employee-owned endpoints untenable in a whole sector, and if that happens in banking it will happen to personal AI first and hardest, because the model of you is a record and records get subpoenaed. The other honest risk is that I want this to be true. It fits everything I have written about sovereignty, and an argument that flatters its author deserves a heavier discount than I am probably applying.
1 thought on “My Employer Is a Node”