Control working-time compliance with policy packs

Workspace separates time recording from legal evaluation. Employees can continue recording time when a profile is missing or an evaluation cannot reach a definitive result. The compliance engine produces reproducible findings with PASS, WARNING, VIOLATION, or INDETERMINATE outcomes.

This capability supports operational review. It is not legal advice and does not provide a blanket guarantee that a particular organization satisfies every employment-law obligation.

Policy packs in this build

The initial product release contains curated packs for adult employees in the general scope of application:

PackJurisdictionBaseline rulesMinimum retention
DE_ARBZG_GENERALGermanydaily maximum, average window, breaks, daily rest, Sunday and holiday work730 days
AT_AZG_GENERALAustriadaily and weekly maximum, 17-week average, breaks, daily and weekly rest, and holiday work365 days
CH_ARG_GENERALSwitzerlandcategory-based weekly maximum, breaks, daily rest, 35-hour weekly rest, daily span, and holiday work1,826 days

Collective-agreement deviations, young workers, night work, and sector-specific exceptions are not automatically covered. An unsupported exception profile therefore produces INDETERMINATE until an approved pack exists.

Activate a policy release

  1. Open Staff → Working-time compliance.
  2. Review the pack version, jurisdiction, official sources, and known exclusions.
  3. Create a draft with your legal approval reference and validity start.
  4. Activate the draft with staff_time_policy:activate.
  5. Add an effective employment profile for each covered employment contract, including the default work location, time zone, worker category, recording mode, any required evidence reference, and the start of compliance evaluation.

Activations are prospective. A new pack version never changes existing snapshots or silently reevaluates historical periods.

Employment contract, work location, and day context

The employment contract provides the legal employment identity. Organizational assignments to a person, team, or position do not replace that contract. The effective profile defines a default work location. Record a day override when a different location applies to a particular workday. Workspace does not infer work locations from IP addresses, browsers, or geolocation. Corrections append a revision instead of overwriting earlier evidence. Evidence therefore identifies whether a location came from the profile (PROFILE_DEFAULT) or a day override (DAY_OVERRIDE).

Evaluations for Germany, Austria, and Switzerland consume the existing holiday administration; they do not introduce a second holiday table. The holiday region of the effective work location and the approved public_holiday_templates are authoritative. The region, calendar source, and applied template references are sealed with the evaluation facts. If the object-bound location is missing or conflicts with the jurisdiction, the holiday rule specifically remains INDETERMINATE; time recording and other evaluable rules remain available. The same fail-closed behavior applies when an evaluation period spans an unsupported jurisdiction.

Readiness and evaluation runs

Before an evaluation, the workbench indicates whether the required prerequisites are available. This readiness check does not change data. It checks effective policy releases, employment contracts and profiles, default work locations, coverage of their holiday regions by active holiday templates, policy-pack-compatible facts, and the required retrospective recording coverage. It distinguishes ready, warning, and blocked, exposes stable reasons, and links to the responsible configuration area. Warnings never block time recording; blockers only prevent a reliable compliance evaluation.

An evaluation creates a dedicated evaluation run. If the profile, policy release, or jurisdiction changes within the requested period, the run is split into reproducible segments. Missing employment or location context is recorded as a context gap and is never filled with an invented policy state.

Evidence and retention

Ledger events, day contexts, evaluation snapshots, findings, correction reviews, and deletion receipts are immutable. Corrections append events and immediately trigger a new evaluation for previously evaluated periods. The new snapshot references its predecessor. Every snapshot binds facts to a policy pack, version, and manifest digest.

A finding's review status remains separate from its evaluation outcome. A finding starts as OPEN and can be recorded as ACKNOWLEDGED or REVIEWED. Reevaluation marks findings from the replaced snapshot as SUPERSEDED without changing the old snapshot or its evidence. Correction reviews use the separate PENDING, CONFIRMED, and CHALLENGED chain.

Employees can export their own evidence for a period. HR and compliance users need the separate staff_time_compliance:export permission for tenant-wide exports. The export includes a SHA-256 manifest digest that identifies unchanged export content.

The applicable minimum retention deadline is attached when an event is recorded. The later value from policy requirements and tenant configuration applies; a tenant value of 0 means indefinite retention. Later policy changes cannot shorten the stored deadline. If an applicable policy minimum is unavailable, the event remains protected. The retention executor deletes only entries whose deadline elapsed and that have no active legal hold, then writes an immutable deletion receipt.

The packs reference official baseline rules including the German Working Time Act, the Austrian Working Time Act, and guidance published by the Swiss SECO.

A German draft bill on electronic time recording does not automatically constitute enacted law. Changed requirements are delivered as a new legally reviewed pack version and require explicit tenant activation.