The Working Agreement: An Eight-Clause Template for Rolling Out Agents to a Team
Rolling agents out to a team is not only a technical migration. It is a negotiation about what the audit trail may be used for against the people who appear in it. As of June 2026, no working agreement written for AI coding agents exists anywhere to settle that question. The closest artifacts are German model works agreements (Muster-Betriebsvereinbarungen) for AI in general, and Agudo's coding-rollout guide (April 2026) confirms the circulating 2025/26 templates "were mostly written for ChatGPT Business or Microsoft Copilot as chat assistants." Agents add MCP servers, sandboxed execution, and third-country prompt routing as unregulated extras. Nobody has published the agreement that covers them.
It is the companion to the rollout sequencing in cohorts beat mandates: the cohort decides who gets agents and when, the working agreement decides what the system may record about them. What follows is original drafting by this handbook, built on the eight-clause architecture that recurs across the strongest German sources: the HUMAINE model agreement (May 2026, 56 pages, 23 sections), the IG Metall NRW module texts (April 2025, 20 modules, co-developed with works councils at Diebold Nixdorf, WAGO, Weidmüller, and Wincor Nixdorf), Bitkom's employer-side guidance (February 2026), and the real IBM Germany framework agreement with ver.di, documented in a Hans-Böckler-Stiftung portrait. Quotes from the German sources are translated. The legal context, why a per-actor session log is the paradigm case for codetermination, is covered in works councils and monitoring law.
The German skeleton is the only clause architecture tested against real session logs
The German templates are the only clause architecture that has been negotiated against real employers and real session logs. The eight categories below recur across union-side, employer-side, and real-agreement sources, which is what makes them a skeleton rather than a wishlist. Even Bitkom, writing for employers, concedes councils "typically demand access to log data" and are in principle entitled to it. Outside Germany nothing forces you to sign this. Sign it anyway.
Eight clauses, each mapping one-to-one onto an audit-plane property
Original drafting
The clause categories and the German pattern in each are sourced. The agent-specific drafting in each clause is this handbook's, and has not been negotiated or counsel-reviewed anywhere.
1. Purpose whitelist (closed list). Personal data from agent sessions may be collected and evaluated only for: system security, data protection, verifying compliance with this agreement and statute, analyzing technical errors, statutory retention, and external audit. All other purposes are excluded by default. This is HUMAINE §13's exhaustive negative default, and it is nearly word for word the legitimate purpose set of a compliance audit trail. Performance evaluation is not on the list.
2. Individual-evaluation bar, with a voidness remedy. Session data may not be used for behavior or performance monitoring, comparison, or measurement; personnel measures based on data obtained in violation are void and must be reversed (HUMAINE §10's three stacked prohibitions). Agent-specific drafting: name the barred metrics explicitly. Prompt counts, suggestion-acceptance rates, agent-task throughput, and per-developer AI-usage scores all count as evaluation. This clause collides head-on with usage mandates graded in performance reviews; see mandates and measurement.
3. Aggregation floor. All dashboards and reports aggregate such that no inference about an individual's performance is possible (HUMAINE §10). Per-actor queries exist, the audit trail requires them, but they are gated to named compliance roles under clause 1's purposes.
4. Access roles, and logged access. A role-and-permission concept attaches as a signed annex; administrator access is maintenance-only; and every read of the trail is itself documented and verifiable (HUMAINE §13). In agent terms: reads of the session log are append-only events in it. The auditors get audited.
5. Purpose-bound retention. Each purpose gets its own retention clock, audit evidence in years, usage telemetry in weeks, with deletion obligatory once the purpose lapses, and an ongoing duty to prevent re-identification from "anonymized" process data (HUMAINE §10).
6. Capability disclosure. Employees can determine in advance where agents and logging operate, and what the system could enable in future, not only what is switched on today (HUMAINE §16). This is the contractual form of the what is logged about you page.
7. Representative audit rights. The council, or an ombuds role where no council exists, may verify compliance at any time, with standing read access to trail configuration and access logs (not content), a duty on platform admins to answer, and external experts at employer cost (HUMAINE §15, §80(3) BetrVG).
8. Per-tool annex, banned tier, joint body, cadence. Each agent tool gets an annex covering account model, attribution keys, enabled admin metrics, retention, data region, and MCP integrations; Agudo argues this annex "resolves half the negotiation." Add IBM's banned tier: no system that decides personnel measures from trail data may be introduced at all. Add a standing joint review body (Telekom's Digi-Board meets every four weeks), a 12-month review, and renegotiation triggered by any change to logging, analytics, or data regions. In this template, a telemetry configuration change is a contract change.
Three gaps: untested drafting, a partly unenforceable remedy, and no public negotiated text
This drafting has not survived contact with a negotiation, and three gaps say where it is weakest. First, this text has been negotiated nowhere; the German clause architecture is battle-tested, the agent-specific drafting is not. Second, the strongest remedy is legally uncertain in part: per the Federal Labour Court (BAG 29.6.2023 – 2 AZR 296/22), a contractual evidence-exclusion clause cannot be validly agreed in a works agreement, though the voidness-of-personnel-measures remedy stands on different footing. Counsel-check before relying on either. Third, the real tech-employer agreements, IBM's and Deutsche Telekom's, are not public; this skeleton leans on model texts and secondary accounts, not negotiated language. The field is silent on what an employer actually conceded in writing about an agent platform. When the first agent-specific agreement leaks or publishes, replace this page's drafting with it.