Privacy & Anonymity
How privacy is protected, by design
These safeguards are not optional settings — they are structural. They hold for dashboards, Decision Packs, transactional email, bots, and AI assembly: thin channels, floor-safe aggregates, and human gates for consequential decisions.
The 5-person rule
No group result is ever shown for fewer than five people. A protected group and an empty one look exactly the same — so nobody can guess how many people are in a small team.
Kept completely separate
An anonymous answer can never be matched back to a named record — a check-in, a support request, a consultation, an investigation — anywhere in the system, including Decision Pack assembly and AI assistants.
Managers see only their own team
A manager never sees another team's results. If they try to open a team they don't manage, it simply isn't found — it doesn't say “access denied,” which would confirm the team even exists.
A pause after staffing changes
After a team's headcount changes, its results stay protected for a while — so a small shift in numbers can't be used to work out who answered what.
Channels stay thin
Transactional email and chat bots carry titles, due dates, and deep links — never HIGHEST free text, individual answers, or investigation content. Sensitive work opens in the authenticated app.
Human gates for consequence
Orchestration prepares work; people still approve non-standard controls, investigations, risk acceptance, DPIA, and pack activation. Tier 3 only auto-applies standard library controls under policy, with audit.