Top 8 Best Computer Keystroke Monitoring Software of 2026

GITNUXSOFTWARE ADVICE

Cybersecurity Information Security

Top 8 Best Computer Keystroke Monitoring Software of 2026

Compare Computer Keystroke Monitoring Software with a ranked top 10 list. Teramind, Veriato, and Time Doctor reviewed. Explore best picks.

16 tools compared23 min readUpdated todayAI-verified · Expert reviewed
How we ranked these tools
01Feature Verification

Core product claims cross-referenced against official documentation, changelogs, and independent technical reviews.

02Multimedia Review Aggregation

Analyzed video reviews and hundreds of written evaluations to capture real-world user experiences with each tool.

03Synthetic User Modeling

AI persona simulations modeled how different user types would experience each tool across common use cases and workflows.

04Human Editorial Review

Final rankings reviewed and approved by our editorial team with authority to override AI-generated scores based on domain expertise.

Read our full methodology →

Score: Features 40% · Ease 30% · Value 30%

Gitnux may earn a commission through links on this page — this does not influence rankings. Editorial policy

Computer keystroke monitoring tools help organizations map sensitive input activity to compliance needs, insider-risk reviews, and incident investigations. This ranked list compares leading platforms by how reliably they capture or infer user interactions, enforce policy controls, and support investigators with searchable event telemetry.

Editor’s top 3 picks

Three quick recommendations before you dive into the full comparison below — each one leads on a different dimension.

Editor pick

Teramind

Keystroke logging with searchable session replay and behavior-based alerts

Built for enterprises needing keystroke evidence, behavioral alerts, and audit reporting.

Editor pick

Veriato

Keystroke logging with investigatory timelines for fast evidence review

Built for enterprises needing detailed keystroke evidence for compliance and investigations.

Editor pick

Time Doctor

Keystroke monitoring with activity timelines inside Time Doctor reports

Built for teams needing keyboard-level insight with time tracking and management dashboards.

Comparison Table

This comparison table reviews computer keystroke monitoring software tools, including Teramind, Veriato, Time Doctor, Zaius, and lansweeper. It helps readers compare monitoring coverage, data collection depth, workflow and reporting features, admin controls, and deployment fit so teams can match capabilities to their compliance and operational needs.

18.8/10

Teramind provides user behavior analytics and endpoint activity monitoring that can capture keystrokes for insider risk, compliance, and investigations.

Features
9.1/10
Ease
8.4/10
Value
8.7/10
28.1/10

Veriato offers employee monitoring with keystroke capture, screen visibility, and policy controls for security and productivity assurance.

Features
8.8/10
Ease
7.2/10
Value
7.9/10

Supports productivity monitoring with optional activity and keyboard monitoring features for managed workforces and audits.

Features
8.6/10
Ease
7.9/10
Value
8.0/10
47.7/10

Supports customer security and fraud workflows via behavior-based identity and interaction monitoring rather than direct keystroke capture.

Features
8.2/10
Ease
7.2/10
Value
7.4/10
57.6/10

Performs asset discovery and software inventory that can be paired with other controls for endpoint risk management rather than keystroke logging.

Features
8.1/10
Ease
7.2/10
Value
7.4/10
68.1/10

Provides UEBA and security analytics that can highlight suspicious user input patterns using event telemetry rather than direct keylogging.

Features
8.6/10
Ease
7.6/10
Value
7.9/10
78.0/10

Detects cyber threats with network and user behavior models that can surface risky interactions connected to user activity.

Features
8.6/10
Ease
7.4/10
Value
7.9/10

Collects endpoint and behavioral telemetry for security investigations that can correlate suspicious input-driven actions without keystroke capture.

Features
8.2/10
Ease
7.3/10
Value
7.4/10
1

Teramind

enterprise UBA

Teramind provides user behavior analytics and endpoint activity monitoring that can capture keystrokes for insider risk, compliance, and investigations.

Overall Rating8.8/10
Features
9.1/10
Ease of Use
8.4/10
Value
8.7/10
Standout Feature

Keystroke logging with searchable session replay and behavior-based alerts

Teramind stands out for combining computer activity monitoring with keystroke-level capture and rich user-behavior analytics. It supports live monitoring, session playback, and detailed activity trails that help investigate insider risk and policy violations. The platform also includes alerts and automated responses based on configurable behavioral rules. Administrators can manage data retention, access control, and reporting across endpoints.

Pros

  • Keystroke-level monitoring paired with session playback for fast investigations
  • Behavioral alerting detects risky patterns across users and applications
  • Granular policy controls support targeted monitoring and enforcement
  • Strong analytics and reporting for audit-ready evidence trails

Cons

  • Keystroke capture requires careful rollout to limit user friction
  • Setup and tuning of policies can take specialist attention
  • Investigative dashboards can feel dense for first-time admins

Best For

Enterprises needing keystroke evidence, behavioral alerts, and audit reporting

Official docs verifiedFeature audit 2026Independent reviewAI-verified
Visit Teramindteramind.co
2

Veriato

employee monitoring

Veriato offers employee monitoring with keystroke capture, screen visibility, and policy controls for security and productivity assurance.

Overall Rating8.1/10
Features
8.8/10
Ease of Use
7.2/10
Value
7.9/10
Standout Feature

Keystroke logging with investigatory timelines for fast evidence review

Veriato focuses on keystroke-level visibility for insider risk and productivity assurance across managed endpoints. It combines monitored input capture with timeline-based investigations that connect activity to user and machine context. It also supports policy-driven monitoring that can target specific users or systems for compliance workflows.

Pros

  • Keystroke-level monitoring supports detailed incident reconstruction
  • Policy targeting helps reduce noise compared to blanket monitoring
  • Investigation timelines link activity to specific users and endpoints
  • Configurable data capture supports compliance-focused retention needs

Cons

  • Setup and tuning typically require careful governance to avoid overcollection
  • User-facing reporting can feel complex without dedicated workflow training
  • High monitoring depth may increase investigation and storage overhead

Best For

Enterprises needing detailed keystroke evidence for compliance and investigations

Official docs verifiedFeature audit 2026Independent reviewAI-verified
Visit Veriatoveriato.com
3

Time Doctor

workforce monitoring

Supports productivity monitoring with optional activity and keyboard monitoring features for managed workforces and audits.

Overall Rating8.2/10
Features
8.6/10
Ease of Use
7.9/10
Value
8.0/10
Standout Feature

Keystroke monitoring with activity timelines inside Time Doctor reports

Time Doctor stands out by combining detailed activity tracking with built-in time and productivity reporting for distributed teams. The product captures application usage and can record idle time, activity levels, and task-oriented timelines that are useful for workflow auditing. Keystroke monitoring is available alongside computer usage visibility, which supports granular review of what happens on endpoints. Reporting and dashboards then translate those signals into management views for attendance, effort allocation, and behavioral patterns.

Pros

  • Granular activity timelines with application and idle-time context for endpoint review
  • Keystroke monitoring capability supports detailed productivity auditing
  • Dashboards summarize behavior patterns across teams and projects

Cons

  • Configuration for monitoring scope can become complex across varied roles
  • High data detail increases the need for governance and review discipline
  • Keystroke data can raise privacy friction depending on workplace policy

Best For

Teams needing keyboard-level insight with time tracking and management dashboards

Official docs verifiedFeature audit 2026Independent reviewAI-verified
Visit Time Doctortimedoctor.com
4

Zaius

identity monitoring

Supports customer security and fraud workflows via behavior-based identity and interaction monitoring rather than direct keystroke capture.

Overall Rating7.7/10
Features
8.2/10
Ease of Use
7.2/10
Value
7.4/10
Standout Feature

Behavior analytics dashboards that correlate activity signals with user behavior

Zaius stands out by focusing on behavioral customer intelligence that can include endpoint activity signals for compliance and productivity monitoring. The platform supports detailed activity capture suitable for understanding user behavior across sessions. Keystroke monitoring is positioned as part of a broader analytics and governance workflow rather than as a standalone keylogger experience. Admin controls emphasize oversight and reporting for organizations that need actionable behavioral data.

Pros

  • Behavior analytics approach adds context beyond raw keystrokes
  • Centralized reporting supports audit-ready reviews of user activity
  • Policy controls help align monitoring with organizational governance
  • Activity data can feed investigations and performance assessments

Cons

  • Setup and configuration require careful policy and data handling
  • UI navigation can feel complex for teams new to monitoring
  • Monitoring depth may increase operational overhead for review
  • Keystroke outputs need interpretation alongside other telemetry

Best For

Teams needing behavioral monitoring with governance-grade reporting

Official docs verifiedFeature audit 2026Independent reviewAI-verified
Visit Zaiuszaius.com
5

lansweeper

endpoint inventory

Performs asset discovery and software inventory that can be paired with other controls for endpoint risk management rather than keystroke logging.

Overall Rating7.6/10
Features
8.1/10
Ease of Use
7.2/10
Value
7.4/10
Standout Feature

Endpoint activity monitoring correlated with Lansweeper’s device and software inventory

Lansweeper stands out as an IT asset discovery and management platform that also supports endpoint activity monitoring for compliance and investigations. Key capabilities include collecting computer and user context across managed endpoints and mapping activity to devices and software inventories. It is geared toward identifying where data, applications, and user actions occur inside the endpoint environment rather than only capturing raw keystrokes. The monitoring workflows are typically administered through the same infrastructure used for asset inventory and endpoint visibility.

Pros

  • Unifies endpoint activity visibility with IT asset inventory for faster investigations
  • Correlates monitoring findings with device and software context
  • Centralized administration fits environments already using asset discovery

Cons

  • Keystroke monitoring setup can be more complex than standalone log-only tools
  • Fewer deep investigative workflows than dedicated keystroke platforms
  • Operational overhead increases with agent deployment and tuning

Best For

Organizations needing endpoint monitoring tied to device inventory and compliance workflows

Official docs verifiedFeature audit 2026Independent reviewAI-verified
Visit lansweeperlansweeper.com
6

Securonix

UEBA analytics

Provides UEBA and security analytics that can highlight suspicious user input patterns using event telemetry rather than direct keylogging.

Overall Rating8.1/10
Features
8.6/10
Ease of Use
7.6/10
Value
7.9/10
Standout Feature

Keystroke monitoring integrated into insider risk and security investigation analytics

Securonix stands out by tying keyboard activity collection into broader security analytics and investigation workflows. The platform supports keystroke monitoring with session context so responders can correlate typed content to endpoints, users, and timelines. It also emphasizes enterprise detection use cases like insider risk and threat investigation rather than standalone keylogging for simple compliance. Centralized policy management and SIEM-aligned output make it usable in security operations centers.

Pros

  • Strong investigation workflows that connect keystrokes to identity and endpoint context
  • Enterprise-grade analytics designed for insider risk and security operations
  • Centralized policy and event management supports large deployments
  • Integrations aimed at SIEM and case workflows

Cons

  • Setup and tuning require security engineering effort
  • High data collection can increase storage and event-handling complexity
  • Less suitable for lightweight monitoring without broader security use cases

Best For

Security teams investigating insider risk and user activity across enterprise endpoints

Official docs verifiedFeature audit 2026Independent reviewAI-verified
Visit Securonixsecuronix.com
7

Darktrace

behavior detection

Detects cyber threats with network and user behavior models that can surface risky interactions connected to user activity.

Overall Rating8.0/10
Features
8.6/10
Ease of Use
7.4/10
Value
7.9/10
Standout Feature

Autonomous response with DETECT and RESPOND for suspicious user and endpoint activity

Darktrace stands out for its AI-driven approach to cyber defense, with detections built from autonomous learning of system and user behavior. For computer keystroke monitoring, it provides visibility into endpoint and identity activity to support investigation and response workflows. Its focus is less on standalone keylogging and more on behavioral security monitoring tied to broader threat detection signals. This makes it stronger for threat hunting use cases than for simple compliance-grade keystroke capture alone.

Pros

  • AI-driven detections correlate endpoint and identity signals for investigations
  • Strong behavioral context helps reduce noise compared to raw event monitoring
  • Integrates into broader Darktrace detection and response workflows
  • Coverage extends beyond keystrokes into user and device activity telemetry

Cons

  • Keystroke-specific capture depth is not the primary product emphasis
  • Tuning detections and onboarding can require specialized security expertise
  • Investigation outputs can feel complex without strong analyst workflows

Best For

Security teams needing behavior-based endpoint monitoring beyond keystrokes

Official docs verifiedFeature audit 2026Independent reviewAI-verified
Visit Darktracedarktrace.com
8

SentinelOne

EDR telemetry

Collects endpoint and behavioral telemetry for security investigations that can correlate suspicious input-driven actions without keystroke capture.

Overall Rating7.7/10
Features
8.2/10
Ease of Use
7.3/10
Value
7.4/10
Standout Feature

Endpoint behavioral telemetry plus keystroke monitoring in the same investigative workflow

SentinelOne stands out for blending endpoint threat detection with detailed user and session activity on monitored devices. Its keystroke monitoring capability is delivered through endpoint telemetry that security teams can investigate alongside attack and behavioral signals. The platform supports centralized policy control and search across endpoints for faster scoping of suspicious activity.

Pros

  • Keystroke monitoring ties directly into endpoint investigation context
  • Centralized policy management applies across monitored endpoints
  • Activity and telemetry support fast search during incident response

Cons

  • Configuration and tuning can be heavy for smaller teams
  • Deep monitoring visibility increases data volume and investigation workload
  • Workflow clarity can suffer without strong operational playbooks

Best For

Security teams needing keystroke-level visibility tied to endpoint threats

Official docs verifiedFeature audit 2026Independent reviewAI-verified
Visit SentinelOnesentinelone.com

How to Choose the Right Computer Keystroke Monitoring Software

This buyer’s guide explains how to evaluate computer keystroke monitoring software by mapping keystroke-level capture, session replay, investigative workflows, and governance controls to real products like Teramind, Veriato, Time Doctor, and Securonix. The guide also covers alternatives where keystroke capture is not the primary focus, including Darktrace, Zaius, and SentinelOne. The covered tools include lansweeper as an endpoint-visibility option that can tie activity monitoring to device and software inventory.

What Is Computer Keystroke Monitoring Software?

Computer keystroke monitoring software records what users type on managed endpoints to support insider risk, compliance evidence, and incident reconstruction. It often pairs keystroke capture with session playback, timeline investigations, and policy controls so investigators can connect typed content to users, endpoints, and actions over time. Teramind and Veriato represent the clearest keystroke-focused end of the category with keystroke logging plus searchable investigation views. Time Doctor represents a productivity-oriented approach that can include keyboard monitoring alongside application and idle-time context.

Key Features to Look For

These features determine whether investigators can reconstruct events quickly and whether admins can control monitoring scope without overwhelming users and storage pipelines.

  • Keystroke-level logging with searchable session replay

    Teramind excels with keystroke logging paired with searchable session replay so investigations can jump directly to relevant input during a session. Veriato also supports keystroke-level visibility with investigatory timelines designed for fast evidence review.

  • Behavior-based alerting and policy-driven capture

    Teramind provides behavioral alerting based on configurable rules so risky patterns across users and applications can trigger attention without manual log scanning. Veriato supports policy targeting that reduces noise by focusing capture on specific users or systems.

  • Investigative timelines that connect identity, endpoint, and typed activity

    Veriato emphasizes investigation timelines that link activity to specific users and endpoints, which speeds incident reconstruction. Securonix integrates keystroke monitoring into insider risk and security investigation analytics so typed input is correlated with identity and endpoint context.

  • Audit-ready reporting and evidence trails

    Teramind provides analytics and reporting designed for audit-ready evidence trails with access control and data retention administration. Zaius provides centralized reporting for governance-grade reviews of user activity, including how activity signals relate to user behavior.

  • Endpoint activity context beyond raw keystrokes

    Time Doctor adds keystroke monitoring alongside application usage and idle-time context so typed activity is easier to interpret in workflow terms. lansweeper correlates monitoring findings with device and software context, which helps investigators understand where actions occurred in the endpoint environment.

  • Security operations workflow integration and automated threat response

    Darktrace supports autonomous response with DETECT and RESPOND for suspicious user and endpoint activity, and it extends visibility beyond keystrokes into broader telemetry. SentinelOne combines endpoint behavioral telemetry with keystroke monitoring in the same investigative workflow so responders can scope suspicious input-driven actions alongside threat signals.

How to Choose the Right Computer Keystroke Monitoring Software

Selection should align monitoring depth with the investigation workflow, governance requirements, and the operational effort admins can sustain.

  • Define the investigation goal: compliance evidence or security detection

    Enterprises needing keystroke evidence and audit trails should prioritize Teramind or Veriato because both provide keystroke-level visibility with evidence-oriented investigation views. Security operations teams that need typed input correlated with broader detection and response should evaluate Securonix, Darktrace, or SentinelOne because these tools integrate keystroke-related visibility into security investigation workflows.

  • Validate that the product supports fast evidence review, not just raw capture

    Teramind and Veriato are designed for rapid evidence review using session replay or investigatory timelines that connect input to identity and endpoints. Time Doctor supports keyboard monitoring inside activity timelines in its reports, which helps managers audit behavior alongside application and idle-time context.

  • Confirm policy controls match governance and limit overcollection risk

    Teramind offers granular policy controls for targeted monitoring and enforcement, which helps reduce unnecessary user friction when keystroke capture is enabled. Veriato emphasizes policy targeting and configurable data capture so governance teams can avoid overcollection that increases investigation and storage overhead.

  • Check how the monitoring depth affects operations, tuning, and storage handling

    Securonix and Darktrace require security engineering effort because they connect keystroke collection into enterprise analytics and detection workflows that generate high data volumes. SentinelOne and Teramind also support deep monitoring, which increases investigation and workflow load, so operational playbooks are needed to keep analysts productive.

  • Match the tool to adjacent systems and existing endpoint workflows

    lansweeper fits organizations already centered on IT asset discovery because it correlates endpoint activity monitoring with device and software inventory, which supports compliance workflows tied to IT context. If the organization wants behavior intelligence rather than a standalone keylogger experience, Zaius provides behavior analytics dashboards that correlate activity signals with user behavior.

Who Needs Computer Keystroke Monitoring Software?

Computer keystroke monitoring software fits teams that must reconstruct user actions at the input level, connect typed activity to identity and endpoints, and produce evidence for governance or investigations.

  • Enterprises needing keystroke evidence, behavioral alerts, and audit-ready reporting

    Teramind is the strongest fit because it pairs keystroke logging with searchable session replay plus behavior-based alerts and audit-ready reporting with retention and access control administration. Veriato also fits this segment with policy-driven keystroke capture and investigatory timelines that support compliance workflows.

  • Compliance and insider risk programs that require detailed incident reconstruction

    Veriato is built around keystroke-level evidence with timelines that connect activity to specific users and endpoints. Securonix fits organizations running security operations because it integrates keystroke monitoring into insider risk and security analytics with centralized policy and event management.

  • Productivity and workforce auditing teams that want keyboard monitoring plus time and workflow context

    Time Doctor supports keystroke monitoring alongside application usage, idle-time tracking, and activity timelines inside its reports. This combination helps teams audit productivity signals without relying solely on typed content.

  • Security teams focused on behavior-based threat detection and investigation workflows beyond raw keylogging

    Darktrace is designed for AI-driven detections and autonomous response with DETECT and RESPOND for suspicious user and endpoint activity, where keystrokes support broader behavioral telemetry. SentinelOne supports keystroke-level visibility delivered through endpoint behavioral telemetry so responders can correlate input-driven actions with threat and session context in one investigative workflow.

Common Mistakes to Avoid

Common implementation failures come from mismatched tool focus, overly broad capture, and underestimating the governance and tuning effort required for deep monitoring.

  • Enabling keystroke capture without a rollout plan that minimizes user friction

    Teramind supports keystroke logging but requires careful rollout and policy tuning to avoid unnecessary user disruption when keystroke-level capture is enabled. Veriato also requires governance because detailed keystroke capture increases oversight needs to prevent overcollection.

  • Assuming timeline investigations will be straightforward without analyst workflow design

    Teramind investigative dashboards can feel dense for first-time admins, which can slow investigations if analysts lack playbooks. SentinelOne can suffer from workflow clarity issues without operational playbooks when deep monitoring visibility increases investigation workload.

  • Using a security analytics platform for pure compliance evidence without aligning expectations

    Darktrace and Securonix connect keystrokes to broader enterprise detection and investigation workflows, so keystrokes are not the primary standalone keylogger experience in both platforms. Zaius similarly emphasizes behavior analytics dashboards and governance-grade reporting where typed outputs require interpretation alongside other telemetry.

  • Trying to replace endpoint inventory context with keystroke data alone

    lansweeper is stronger when endpoint activity monitoring is correlated with device and software inventory, not when it is treated as a standalone evidence-only keylogger. Time Doctor provides keyboard monitoring plus application and idle-time context, which prevents misinterpreting typed content without workflow signals.

How We Selected and Ranked These Tools

we evaluated each tool on three sub-dimensions: features with weight 0.4, ease of use with weight 0.3, and value with weight 0.3. The overall rating equals 0.40 × features plus 0.30 × ease of use plus 0.30 × value. Teramind separated from lower-ranked tools by combining keystroke-level monitoring with session replay and behavior-based alerts, which scored high on the features dimension because investigators get both evidence capture and searchable review workflows. Tools with keystroke visibility tied more tightly to broader analytics, like Securonix and Darktrace, performed well on investigation workflow integration but leaned on specialized tuning effort that can affect ease of use.

Frequently Asked Questions About Computer Keystroke Monitoring Software

Which tools provide keystroke-level evidence plus searchable session playback?

Teramind combines keystroke logging with session playback and searchable activity trails for investigations. Veriato also captures keystroke-level evidence and organizes it into timeline-based views that connect user and machine context.

Which solution is best for insider-risk investigations that connect typed content to enterprise context?

Securonix is built for security investigations and correlates keyboard activity with endpoints, users, and timelines in broader analytics workflows. SentinelOne similarly blends keystroke monitoring with endpoint telemetry so responders can scope suspicious activity across monitored devices.

How do Teramind and Veriato differ in how investigations are navigated?

Teramind emphasizes behavior-based alerts and automated responses driven by configurable rules, which helps triage events quickly. Veriato emphasizes investigatory timelines that assemble keystroke capture with user and system context for faster evidence review.

Which tools include keystroke monitoring alongside productivity or time reporting?

Time Doctor pairs keystroke monitoring with application usage signals, idle time tracking, and activity timelines inside management reports. Veriato focuses more on compliance and insider-risk evidence than on time and attendance reporting workflows.

Which platforms are designed to correlate endpoint activity with asset and inventory data instead of acting like standalone keyloggers?

lansweeper ties endpoint activity monitoring to device and software inventories so administrators can map actions to the systems where they occurred. Zaius positions keystroke monitoring as part of a broader governance and behavioral analytics workflow rather than a standalone keylogging experience.

Which option fits organizations that want behavior-based detection with automated response capabilities?

Darktrace uses autonomous learning to drive behavior-based detections and includes DETECT and RESPOND style workflows tied to endpoint and identity activity. Teramind supports configurable behavioral rules that trigger alerts and automated responses during monitoring.

Which solutions support policy-driven monitoring targeting specific users or systems?

Veriato supports policy-driven monitoring that can focus capture on specific users or systems for compliance workflows. SentinelOne provides centralized policy control and lets security teams search across endpoints to scope monitored activity.

What are common technical requirements for deploying keystroke monitoring across endpoints?

Teramind and Veriato are typically deployed as endpoint monitoring agents that collect keystroke-level data alongside session and user context. SentinelOne and Securonix deliver keystroke monitoring through enterprise endpoint telemetry so the same managed environment powers investigation and analysis.

How do these tools handle evidence access and retention during investigations and audits?

Teramind includes administrator controls for data retention, access control, and reporting across endpoints. Veriato also supports investigator-oriented evidence review with monitored input capture organized into timelines that can support audit workflows.

Conclusion

After evaluating 8 cybersecurity information security, Teramind stands out as our overall top pick — it scored highest across our combined criteria of features, ease of use, and value, which is why it sits at #1 in the rankings above.

Our Top Pick
Teramind

Use the comparison table and detailed reviews above to validate the fit against your own requirements before committing to a tool.

Keep exploring

FOR SOFTWARE VENDORS

Not on this list? Let’s fix that.

Our best-of pages are how many teams discover and compare tools in this space. If you think your product belongs in this lineup, we’d like to hear from you—we’ll walk you through fit and what an editorial entry looks like.

Apply for a Listing

WHAT THIS INCLUDES

  • Where buyers compare

    Readers come to these pages to shortlist software—your product shows up in that moment, not in a random sidebar.

  • Editorial write-up

    We describe your product in our own words and check the facts before anything goes live.

  • On-page brand presence

    You appear in the roundup the same way as other tools we cover: name, positioning, and a clear next step for readers who want to learn more.

  • Kept up to date

    We refresh lists on a regular rhythm so the category page stays useful as products and pricing change.