Whoever watches is watched
Remote support is the most far-reaching access in IT operations. It requires works council co-determination not because anyone intends to monitor, but because the tool could. Which is why our remote support module ships locked.
Remote support starts with a sentence that sounds harmless: “Mind if I take a look?” What follows is the most far-reaching access IT operations has. Whoever takes over a screen sees the open mailbox, the private window next to it and the message popping up right now.
That is why remote screen control requires works council co-determination in Germany. The reason is subtler than it first appears.
The statute says “intended”, the courts apply “capable”
Under section 87(1) no. 6 of the German Works Constitution Act, the works council co-determines the use of technical devices “intended to monitor the conduct or performance of employees”. Read literally, that sounds like purpose: intended, therefore wanted.
That is not how it is applied. Since the 1975 Produktograph ruling, the Federal Labour Court has relied on objective capability. A device is “intended” to monitor if it is able to collect conduct or performance data, regardless of whether anyone plans to use that ability. In 2022 the court applied the same test to Microsoft 365.
For remote support that means co-determination does not depend on what you do with the tool. It depends on what the tool can do.
Which is why the module ships switched off
The remote support module does not start in operation, it starts locked. It can only be enabled once the legal basis is confirmed: the wording, the reference to the works agreement, the corresponding processing activity and the retention period. The defaults are three years for session data and ninety days for recordings.
A tool that only runs after the works agreement spares you the more awkward version of that conversation: the one where it has been running for a while.
A session is a procedure, not a connection
Access is requested, not established. The request carries a purpose and the ticket it came from. Approval follows the four-eyes principle, with a comment. The session gets a time window and ends on its own. Channels are listed individually: what is requested is what is needed, what is granted is what is permitted, and the data keeps the two apart.
There is a separate path for emergencies, and it is deliberately inconvenient: it demands a written justification and marks the session permanently as emergency access. Not forbidden, but visible.
A log you can tell has been touched
Every session keeps its own event log, sequentially numbered and linked by a hash chain. Removing or altering an entry afterwards breaks the chain at that point. The log sits apart from the general audit trail, because the event density is of a different order: every channel switch, every file transfer.
And the sentence that explains the whole module
Recordings are the delicate part. Not their creation, but what happens to them afterwards. So every viewing is itself logged, with a reason and with the person who approved it. The data model states the rationale in one line:
Anyone who can watch recordings unobserved holds a surveillance tool – precisely what the works agreement is meant to rule out.
This one table does not audit itself, because it is the evidence.
What we deliberately do not supply
The transmission. Screen, keyboard and files keep running through the tool already in the building, and several at once is the norm: Intune for the Windows laptops, SSH for the Linux servers, MeshCentral for the rest. What is missing is rarely remote support. What is missing is the layer above it, where someone decides who may reach what, when and why.
More on the remote support module page. Product-related context, not legal advice.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.