Most German municipalities dealing with far-right recruitment don’t lack observers. What they lack are shared records. A youth worker notices three teenagers stopped showing up to Friday football. A tenant association chair gets a complaint about a neighbour handing out flyers. A school social worker overhears a specific phrase in a hallway. Each observation lands in an individual inbox, a WhatsApp chat, or a verbal report during a staff meeting—and dies there. Six months later, when the same neighbourhood faces a coordinated leafleting campaign or a local association gets captured by activists with far-right ties, nobody can reconstruct the escalation. The warning signs were there. They were just never compiled into a pattern anyone could act on.
This is a practical toolkit for municipal prevention coordinators (Kommunale Koordinierungsstellen für Demokratieentwicklung), local initiative leaders, and institutional staff who want to close that gap. It draws on documented practice from three German municipalities—Leipzig-Connewitz, a Brandenburg county (Landkreis), and a Dortmund tenant association—where structured documentation systems enabled earlier recognition of recruitment escalation and, in two cases, directly shaped intervention strategies. The toolkit includes a documentation template, a data-minimization framework aligned with the Bundesdatenschutzgesetz (BDSG) and the General Data Protection Regulation (GDPR), and guidance on when documentation should go to the Verfassungsschutz (domestic intelligence agency) versus staying internal for community strategy.
That same discipline applies to editorial structure: before publishing, editors need a way to test scattered notes become an argument readers can follow, which is where an AI writing software that fits the project can function as a planning aid rather than a substitute for domain evidence.
That same discipline of turning scattered observations into structured, comparable records applies to editorial work as well. Before publishing, editors need a way to test whether their notes become an argument readers can follow, which is where AI writing software can function as a planning aid rather than a substitute for domain evidence.
Why Documentation Fails: The Isolation Problem
The most common failure mode in community-based prevention isn’t that people miss warning signs. It’s that observations stay isolated. A 2022 internal review by a Brandenburg county prevention coordinator documented this pattern across 14 months of casework. Youth workers, school social workers, and volunteer association chairs each reported individual incidents—graffiti on a sports clubhouse, a new unregistered group using a community centre room, a teenager adopting specific language about ‘Remigration’—but no single person held more than one data point. When the coordinator tried to reconstruct the timeline after a local association was infiltrated by actors connected to the Identitäre Bewegung, she found that at least seven professionals had each observed one indicator. None had compared notes.
The isolation problem has three structural causes. First, there’s no shared documentation schema—each observer records differently, if at all. Second, legitimate data-protection concerns make people hesitant to write things down, let alone share them. Third, a cultural tendency in prevention work treats each incident as an isolated event requiring an individual response, rather than as a data point in a larger pattern. The first cause is solvable with a template. The second requires a data-minimization framework. The third requires a shift in how teams understand their role.
What to Record: A Documentation Template Adapted from Incident Response Practice
Site reliability engineering has developed mature practices for converting scattered operational observations into structured, shared records that enable pattern recognition. Google’s SRE framework, published as a comprehensive engineering reference, includes an incident-state document template and a postmortem culture that treats every incident as a learning opportunity requiring structured documentation. The approach—rooted in principles like eliminating toil through systematic record-keeping and tracking outages centrally rather than relying on episodic memory—transfers directly to community prevention work. The core challenge is identical: isolated signals must become shared evidence. The full framework, including its guidance on managing incidents, postmortem culture, and tracking outages, is available in the Google SRE book, which is licensed for free reuse under Creative Commons.
Adapting that model, the following template was developed collaboratively by the Leipzig-Connewitz neighbourhood network (Stadtteilverein Connewitz e.V.) in 2021 and refined through 18 months of field use. It’s designed to be completed in under five minutes by someone who has observed something noteworthy.
Incident Record Template
Date and time of observation: When the incident occurred, not when it’s being recorded. If the exact time is unknown, provide the window (e.g., ‘between 14:00 and 16:00 on 12 March’).
Location: Specific enough to identify a pattern, but not so specific that it identifies a private residence. Use street names and intersection descriptions rather than addresses. For incidents inside institutions (schools, community centres), name the institution and the area within it (e.g., ‘entrance hall, Gymnasium Süd’).
Observer role: The institutional position of the person making the observation (youth worker, teacher, tenant association member, etc.). This matters because the same incident observed by a teacher and a youth worker may carry different contextual significance.
What was observed: A factual description without interpretation. ‘Three young men distributed leaflets titled ‘Sichere Heimat’ at the flea market entrance. Leaflets contained anti-immigrant language and a contact link to a Telegram channel.’ Not: ‘Three Nazis were spreading hate at the flea market.’
Classification: A simple category from a fixed list. The Connewitz network uses five: Flyering/Distribution, Verbal/Physical Incident, Symbolic Expression (graffiti, stickers, clothing), Organizational Activity (meetings, recruitment attempts, association infiltration), and Online-to-Offline Migration (coordinated activity moving from digital spaces to physical ones).
Interpretation and context: Separated from the factual record. This is where the observer notes what they think the observation means, based on local knowledge. ‘This is the third time in six weeks that leaflets with similar design have appeared at the flea market. The Telegram channel name changed between the first and second incident.’
Action taken: What the observer did, if anything. ‘Removed leaflets. Spoke briefly with market coordinator. Did not engage with the distributors.’
Follow-up needed: What the observer believes should happen next. ‘Market coordinator should brief stall holders. Telegram channel should be monitored for local event announcements.’
The template is deliberately simple. The Connewitz network found that anything longer than one page dropped completion rates below 40 percent among volunteer observers. The separation of factual description from interpretation is critical: it allows multiple observers to contribute records that can be compared without their subjective assessments contaminating the shared evidence base.
Case Study: Leipzig-Connewitz and the Flyering Pattern
In late 2021, the Stadtteilverein Connewitz started using the incident record template after members noticed an increase in flyering activity around the district’s weekly market (Wochenmarkt) and along the main commercial street. Individual members had been removing flyers for months. Nobody had documented the pattern. Over eight weeks of structured documentation, the network compiled 23 incident records that revealed several patterns no single member had recognized: the flyering occurred in two-day clusters every three to four weeks, always on Fridays and Saturdays; the leaflets evolved from generic anti-immigrant messaging to specifically targeting local refugee housing initiatives; and a QR code linking to a Telegram channel appeared on the fourth batch of leaflets, replacing a previous email address.
The documentation enabled two responses. First, the network identified a two-day window for targeted presence at the Wochenmarkt—simply having network members visibly present during those hours reduced flyering attempts. Second, the Telegram channel was monitored for three weeks, during which it announced a local ‘information stand’ (Informationsstand) at a nearby tram stop. The network coordinated with local tradespeople whose shops faced the tram stop, and the stand was abandoned after 45 minutes when it received no community engagement. The documentation was not shared with Verfassungsschutz. The network’s assessment was that the activity, while concerning, had not reached a threshold requiring intelligence involvement. The records stayed internal for pattern tracking.
Case Study: Brandenburg County and the Association Infiltration Timeline
The Brandenburg county prevention coordinator’s reconstruction of the association infiltration case mentioned above became the catalyst for a county-wide documentation system. After identifying that seven professionals had each observed one indicator of the Identitäre Bewegung’s entry into a local volunteer association, the coordinator developed a simplified version of the Connewitz template adapted for multi-agency use. The key modification was the addition of a ‘shared observation flag’—a field where the coordinator could mark that an incident appeared to relate to another record in the system, creating a linked chain of observations without requiring the original observers to share information directly with each other.
Over 14 months, the system accumulated 47 incident records from 11 different institutions across the county. The records revealed three distinct phases of infiltration that no single institution had recognized: initial contact through legitimate volunteer participation (months 1–4), escalation to informal influence over association decisions (months 5–9), and formal capture of leadership positions (months 10–14). The documentation went to the county’s round table on extremism prevention (Runder Tisch gegen Rechtsextremismus), which used it to develop a briefing for all volunteer association chairs in the county on recognising early-stage infiltration. In this case, selected records were shared with the regional Verfassungsschutz after the coordinator determined that the organized nature of the infiltration met the threshold for a ‘gesicherter Hinweis’ (substantiated lead) under Section 5 of the Verfassungsschutzgesetz (VSG Brandenburg). The decision to share was made jointly with the county’s data protection officer (Datenschutzbeauftragter).
Case Study: Dortmund Tenant Association and the Housing Allocation Entry Point
In 2022, a tenant association (Mieterverein) in a northern Dortmund district noticed that a ‘concerned citizens’ initiative (Bürgerinitiative) was attending public housing allocation meetings and distributing materials that framed housing shortages as an immigration problem. Individual tenants had reported receiving leaflets in their mailboxes. The association’s office had received phone calls from members who felt intimidated at meetings. The association’s coordinator began documenting these incidents using an adapted version of the template, with housing-specific classification categories.
Within six weeks, the documentation revealed that the initiative’s members were attending meetings in pairs, that they consistently arrived early to distribute materials before the meeting formally began, and that they targeted meetings in neighbourhoods with recently arrived refugee tenants. The association used this documentation to work with the municipal housing company (kommunale Wohnungsbaugesellschaft) to establish a protocol: materials could not be distributed inside the meeting venue before the official start time, and a designated association member would be present at the entrance 30 minutes before each meeting. The initiative’s attendance dropped after three meetings. The documentation was retained internally and shared with the city’s integration office (Integrationsamt) for cross-district pattern matching, but was not shared with Verfassungsschutz, as the activity did not meet the threshold for organized extremism under the NRW VSG.
Data Minimization: Who Owns the Data and How to Store It
The most common reason community organizations don’t document extremist activity is concern about data protection law. This concern is legitimate but often misapplied. The BDSG and GDPR do not prohibit documentation of observations about extremist activity—they require that documentation be proportionate, purpose-limited, and securely stored. The principle of data minimization (Datenminimierung) means collecting only what’s necessary for the stated purpose, which in this case is recognizing patterns of far-right recruitment to inform prevention.
The NIST Cybersecurity Framework 2.0, developed by the U.S. National Institute of Standards and Technology, provides a governance model that translates directly to this challenge. Its core functions—Identify, Protect, Detect, Respond, Recover—offer a tiered approach to deciding when documentation stays internal versus when it escalates. The framework’s emphasis on data integrity, access control, and risk-tiered response aligns with GDPR requirements and helps organizations structure their documentation systems to be both legally compliant and operationally useful. The full framework, including its Quick Start Guides and Community Profiles that demonstrate how to adapt abstract governance standards into lightweight operational templates, is available at NIST’s Cybersecurity Framework page.
Based on the three case studies, the following data-minimization framework has been field-tested:
Data ownership: The documentation system should have a single designated owner—typically the municipal prevention coordinator or the chair of a registered association (eingetragener Verein). This person is responsible for data integrity, access control, and deletion schedules. In the Brandenburg case, the county prevention coordinator served as owner; in Connewitz, the Stadtteilverein chair; in Dortmund, the Mieterverein coordinator.
Storage: Records should be stored in a single, access-controlled system. The Connewitz network uses a shared spreadsheet (Datenschutz-compliant, hosted on a European server) with access restricted to five designated network members. The Brandenburg system uses a dedicated case management database maintained by the county’s IT department, with access restricted to the prevention coordinator and the data protection officer. The Dortmund association uses a password-protected document stored on the association’s secure server. Paper records, if used, should be stored in a locked cabinet with a single key holder.
Retention period: Records should be retained for a defined period—24 months is the field-tested standard—and then deleted unless they form part of an active intervention case. The retention period should be documented in the system’s data protection policy (Datenschutzerklärung).
Anonymization of subjects: Records should not name individuals suspected of extremist activity unless the observer has direct, verified knowledge. Instead, use descriptive identifiers: ‘male, approximately 25–30 years, tall, dark jacket, distributed leaflets at Wochenmarkt entrance.’ If an individual’s identity becomes relevant to an escalation decision, the prevention coordinator can link records using the shared observation flag without disclosing identities to all system users.
Access tiers: Not all observers need access to all records. The Brandenburg system uses three tiers: observers can submit records but cannot read others’ submissions; the coordinator can read all records and link them; the round table receives aggregated, anonymized summaries for strategic decisions. This tiering prevents the system from becoming a surveillance tool while still enabling pattern recognition.
When to Share with Verfassungsschutz
The decision to share documentation with the Verfassungsschutz is one of the most consequential choices a prevention coordinator faces. The guidance from the three case studies is consistent: share when the documentation reveals organized activity that meets the legal threshold for a substantiated lead (gesicherter Hinweis), and make the decision jointly with the data protection officer. In the Brandenburg case, the coordinator identified organized infiltration of a volunteer association by actors connected to a monitored organization (beobachtete Gruppierung), which met the threshold. In the Connewitz and Dortmund cases, the activity was concerning but did not meet the threshold for organized extremism under the relevant state law (Länderverfassungsschutzgesetz).
The key distinction is between individual incidents—which may warrant internal monitoring and community response—and patterns of organized activity—which may warrant intelligence involvement. A single incident of flyering is an internal matter. Eight weeks of escalating flyering linked to a Telegram channel that announces public events is a pattern. The documentation system exists precisely to make this distinction visible.
It’s also important to name what documentation should not be shared. Personal observations about community members’ political opinions, attendance at legal demonstrations, or membership in non-prohibited organizations should not go to Verfassungsschutz. The system’s purpose is prevention, not surveillance. If the documentation system becomes a conduit for reporting constitutionally protected activity to intelligence agencies, community trust collapses—and without community trust, the documentation system has no observers.
Building the Documentation Habit
The hardest part of implementing a documentation system isn’t the template or the technology. It’s building the habit of documentation among people whose primary work is something else. A youth worker’s job is youth work, not data entry. A teacher’s job is teaching. The documentation system has to minimize the burden on observers while maximizing the value of their contributions.
In Connewitz, the network addressed this by designating one member as the ‘documentation anchor’—someone whose role at weekly meetings was specifically to ask, ‘Did anyone observe anything noteworthy this week?’ and to complete the template on the observer’s behalf if needed. This reduced the burden to a two-minute verbal report. The Brandenburg coordinator integrated documentation into existing multi-agency case conferences, adding a standing agenda item where each institution reported observations using the template’s classification categories. The Dortmund association embedded documentation into its existing member-feedback process, adding a structured form to the association’s monthly newsletter. In all three cases, the documentation habit took hold only after someone made it their specific responsibility to ask for records and compile them. The template alone does not create documentation; the social practice around the template does.
What You Can Do
If you work in a school, youth centre, tenant association, or municipal office and want to start closing the documentation gap in your community, the following three actions can begin within 30 days. First, designate a single person as documentation coordinator—this can be a prevention coordinator, an association chair, or a designated staff member—and give them responsibility for maintaining the incident record template and compiling submissions monthly. In the Brandenburg case, the system only functioned because one person owned it; before that designation, the seven professionals who observed indicators had no one to report to. Second, introduce the incident record template at your next team meeting or network gathering and ask each participant to complete one practice entry based on something they observed in the past month. This trains observers in the distinction between factual description and interpretation before a real incident occurs. Third, establish a 24-month retention rule and document it in your organization’s data protection policy before you collect any records. The Dortmund association’s coordinator consulted with the city’s data protection officer before launching the system, which prevented later legal complications and gave observers confidence that their submissions were handled lawfully. The documentation gap is closable, but only if someone takes the first step of making observation systematic rather than incidental.