Org-wide PII masking
Names, emails, phone numbers and employee IDs are replaced with deterministic pseudonyms on every read path — dashboards, exports, audit views, AI prompts. Nothing routes around it.
Workers Council Mode is on in every workspace, from the first login.
German works council approval is not a paperwork exercise — it is a hard gate on any system that processes employee data. Lojycal ships with Workers Council Mode enabled by default, so the platform can be deployed under a Betriebsvereinbarung without a single unmasked name reaching a screen.
Enabled by default · Owner-only toggle · Every reveal audited
§ 87 BetrVG gives the works council a co-determination right on any technical system capable of monitoring employees. IT and HR platforms sit squarely inside that scope — a rollout without the Betriebsrat is a rollout you cannot defend.
Workers Council Mode collapses that conversation. Names, emails and personal identifiers are masked org-wide before the first admin logs in. The council reviews what the platform can see, not what you promise it will one day hide.
Workers Council Mode is a single org-level setting that rewrites how every screen, export and Lab renders employee data. There is no per-page toggle to forget.
Names, emails, phone numbers and employee IDs are replaced with deterministic pseudonyms on every read path — dashboards, exports, audit views, AI prompts. Nothing routes around it.
The same employee resolves to the same pseudonym everywhere, so cost per seat, HRIS reconciliation, license reclaim and every Lab keep working. Analysis stays intact; identity does not.
Only workspace owners can flip Workers Council Mode. Every change writes a WORM audit_log entry with actor, before/after and timestamp — reviewable by the Betriebsrat at any time.
Show this view during the works council review. Nothing on screen identifies an individual — the cost per seat and lifecycle signal are preserved so the platform still does its job.
No email addresses. No display names. No org chart handles. Only the pseudonym the Betriebsrat helped agree.
There are moments — an offboarding, a security incident, a legally-mandated disclosure — where a real name is required. Workers Council Mode does not block that; it channels it.
An owner grants a named, time-boxed re-identification scope to a specific admin. Every name-reveal in that window writes a security.pii_reidentified entry to the WORM audit log with actor, target, reason and duration. The Betriebsrat gets a single export to review.
security.pii_reidentified · actor · target · reason · ts
Workers Council Mode is on by default in every new workspace. If it was ever turned off, an owner can turn it back on in under a minute.
Open the Admin Control Plane and go to Settings. The Workers Council Mode card sits at the top of the Privacy section.
Flip the toggle. The change writes an audit_log entry the moment it commits — no separate confirmation dialog to click past.
The setting propagates over realtime to every session in the workspace. Nobody needs to reload; nothing renders an unmasked name after that instant.
Workers Council Mode controls who can read a name today. Data Retention controls how long any employee record can live in the platform at all. Together they cover the two questions every Betriebsvereinbarung ends up asking.
Workers Council Mode is not a checkbox we added to close a deal. It is the default posture of the platform, backed by the same WORM audit log and RLS-per-org boundaries every other Lojycal feature relies on.
We will spin up a workspace with Workers Council Mode on, walk the works council through the masked view, and hand over the audit trail to your DPO in the same session.