Works Council · Betriebsrat

Run Lojycal with every name masked by default.

Workers Council Mode is on in every workspace, from the first login.

German works council approval is not a paperwork exercise — it is a hard gate on any system that processes employee data. Lojycal ships with Workers Council Mode enabled by default, so the platform can be deployed under a Betriebsvereinbarung without a single unmasked name reaching a screen.

Enabled by default · Owner-only toggle · Every reveal audited

Why it exists

Co-determination on the tools that watch employees.

§ 87 BetrVG gives the works council a co-determination right on any technical system capable of monitoring employees. IT and HR platforms sit squarely inside that scope — a rollout without the Betriebsrat is a rollout you cannot defend.

Workers Council Mode collapses that conversation. Names, emails and personal identifiers are masked org-wide before the first admin logs in. The council reviews what the platform can see, not what you promise it will one day hide.

What Workers Council Mode does

PII masked once, everywhere, by default.

Workers Council Mode is a single org-level setting that rewrites how every screen, export and Lab renders employee data. There is no per-page toggle to forget.

Org-wide PII masking

Names, emails, phone numbers and employee IDs are replaced with deterministic pseudonyms on every read path — dashboards, exports, audit views, AI prompts. Nothing routes around it.

Deterministic pseudonyms

The same employee resolves to the same pseudonym everywhere, so cost per seat, HRIS reconciliation, license reclaim and every Lab keep working. Analysis stays intact; identity does not.

Owner-only toggle, always audited

Only workspace owners can flip Workers Council Mode. Every change writes a WORM audit_log entry with actor, before/after and timestamp — reviewable by the Betriebsrat at any time.

What the Betriebsrat sees

A platform without a single reachable name.

Show this view during the works council review. Nothing on screen identifies an individual — the cost per seat and lifecycle signal are preserved so the platform still does its job.

Masked viewCost / seat
  • Employee · 7C4A€ 148 / mo
  • Employee · 91B2€ 92 / mo
  • Employee · A03F€ 214 / mo
  • Employee · D5E1€ 38 / mo

No email addresses. No display names. No org chart handles. Only the pseudonym the Betriebsrat helped agree.

De-anonymize with audit

The only path to a real name is a logged one.

There are moments — an offboarding, a security incident, a legally-mandated disclosure — where a real name is required. Workers Council Mode does not block that; it channels it.

An owner grants a named, time-boxed re-identification scope to a specific admin. Every name-reveal in that window writes a security.pii_reidentified entry to the WORM audit log with actor, target, reason and duration. The Betriebsrat gets a single export to review.

security.pii_reidentified · actor · target · reason · ts
How to enable it

Three clicks, then it stays on.

Workers Council Mode is on by default in every new workspace. If it was ever turned off, an owner can turn it back on in under a minute.

  1. Step 01

    Admin · Settings

    Open the Admin Control Plane and go to Settings. The Workers Council Mode card sits at the top of the Privacy section.

  2. Step 02

    Workers Council Mode · Toggle on

    Flip the toggle. The change writes an audit_log entry the moment it commits — no separate confirmation dialog to click past.

  3. Step 03

    Every open tab masks in real time

    The setting propagates over realtime to every session in the workspace. Nobody needs to reload; nothing renders an unmasked name after that instant.

Fits with Data Retention

Masking is one half. Retention is the other.

Workers Council Mode controls who can read a name today. Data Retention controls how long any employee record can live in the platform at all. Together they cover the two questions every Betriebsvereinbarung ends up asking.

Deployable under a Betriebsvereinbarung — out of the box.

Workers Council Mode is not a checkbox we added to close a deal. It is the default posture of the platform, backed by the same WORM audit log and RLS-per-org boundaries every other Lojycal feature relies on.

Ready to walk the Betriebsrat through it?

We will spin up a workspace with Workers Council Mode on, walk the works council through the masked view, and hand over the audit trail to your DPO in the same session.