Guide/privacy

Privacy & Anonymity

How privacy is protected, by design

These safeguards are not optional settings — they are structural. They hold for dashboards, Decision Packs, transactional email, bots, and AI assembly: thin channels, floor-safe aggregates, and human gates for consequential decisions.

The 5-person rule

No group result is ever shown for fewer than five people. A protected group and an empty one look exactly the same — so nobody can guess how many people are in a small team.

Kept completely separate

An anonymous answer can never be matched back to a named record — a check-in, a support request, a consultation, an investigation — anywhere in the system, including Decision Pack assembly and AI assistants.

Managers see only their own team

A manager never sees another team's results. If they try to open a team they don't manage, it simply isn't found — it doesn't say “access denied,” which would confirm the team even exists.

A pause after staffing changes

After a team's headcount changes, its results stay protected for a while — so a small shift in numbers can't be used to work out who answered what.

Channels stay thin

Transactional email and chat bots carry titles, due dates, and deep links — never HIGHEST free text, individual answers, or investigation content. Sensitive work opens in the authenticated app.

Human gates for consequence

Orchestration prepares work; people still approve non-standard controls, investigations, risk acceptance, DPIA, and pack activation. Tier 3 only auto-applies standard library controls under policy, with audit.