Anonymity

Can your manager find out that it was you?

On an anonymous audit, no. Nobody in your organization can see who gave which answer — not your manager, not an administrator, not us. Here is exactly how that works, and where it stops.

Anonymous audit — nobody in your organization can see who gave which answers. Shown at the top of every anonymous audit you fill in, next to this incognito icon — it marks every anonymous audit.

Two mechanisms

Anonymity means two different things here

Auditee has two anonymity mechanisms and they are not equally strong. We would rather explain the difference than blur it.

Anonymous audits · display-level

Hidden everywhere, not erased

  • Filled in by a signed-in member of the organization.
  • Your identity is still stored. It is hidden on every screen, export and report the product has.
  • Chosen in the draft and frozen at publication, so no submitted answer can ever change its status.
Polls · storage-level

Never linked to a person at all

  • Filled in by anyone holding a one-time access code. No account, no sign-in.
  • No user ID is ever stored with a poll answer. The code is the identity, and the code is linked to nobody.
  • Always on. It cannot be switched off.

How polls work

The manager's side

What your manager actually sees

One results card, in aggregate, and nothing to click into. This is the whole of it.

Anonymous audit — individual answers and identities are hidden for this audit; results are shown in aggregate only. The banner on the manager's results card.
Submissions 18 · Average score 76% · Passed 14 · Failed 4 Everything an anonymous audit reports. There is no row to open.
Not enough auditees have submitted yet to show anonymised results (min 5). The locked state, shown until the threshold is reached.

The threshold

Results stay locked until enough people have answered

An anonymous audit unlocks once distinct submitters reach the greater of five and a fifth of the people assigned. The count is of people, not submissions — one keen person filling a weekly audit forty times never unlocks anything.

20 people assigned

unlocks at 5 submitters

100 people assigned

unlocks at 20 submitters

Below 5, anonymity weakens — in a small group answers may be attributable. Shown to the auditor while they build the audit. The threshold is a mitigation, not a proof.

Refusals

What the product refuses to do

These are not settings. On an anonymous audit the features simply do not function, for everybody.

  • No drill-in, for anyone, ever

    The per-submission transcript route refuses before it even checks who is asking. An organization administrator gets the same refusal as everyone else. So do we.

  • No alert emails

    An alert email would name you, so the ALERT rule action is disabled in the builder, refused by the server and suppressed at the mail producer — including for rules written before anonymity was switched on.

  • No reminders

    A reminder has to be addressed to somebody. Manual reminders on anonymous audits are refused too.

  • No identity-carrying exports

    Assignment, score, answer, rule-firing and task exports emit no rows at all for anonymous audits. The compliance summary keeps the counts and blanks the scores below the floor.

  • No per-person analytics

    Per-auditee scoring and the contributors widget skip anonymous audits, because a per-person count re-identifies just as well as a per-person score.

  • No progress roster where it would give the game away

    Per-person progress cells are hidden everywhere, and where an audit assigns one person per round the assignee column is hidden too, because progress deanonymises by elimination.

Honest limits

Where it stops

Every tool on the market claims total anonymity. We would rather show our work, including the parts that are not perfect.

Six things we will not pretend

  • Hidden is not erased. Your identity stays in the database, so the record remains auditable and so you can review your own submission. Anyone with direct database access could re-identify. Our commitment is that the product never reveals it — to anyone, including us.
  • Small groups are hard. The threshold is a mitigation, not a proof. Below five people the builder says so out loud.
  • Timestamps exist. When a submission was started and finished is recorded. In a very small group, timing can narrow things down.
  • Photos can carry metadata. We do not strip EXIF data from uploads today.
  • Reported problems carry your words. When a rule asks you to describe a problem, that description becomes a task for the team to fix. The reporter shows as “Auditee” and no user ID is stored, but on a small team the content itself can point at you. It is a deliberate trade: nobody can fix a hazard they cannot read about.
  • The roster is not secret. On ordinary anonymous audits a manager can see who was assigned. Never who submitted what.

For auditors

Switching it on costs you something. That is the point.

No alerts, no reminders, no per-person reporting, no drill-in, no identity exports. You trade the ability to chase one individual for answers people were willing to give honestly. Decide before you publish — afterwards it is frozen, which is the only reason the promise is worth anything.

Polls: the stronger guarantee How we handle your data