Reference: Data Visibility and Confidentiality
All survey responses are confidential to protect
employee identity. The available settings and features are in place to treat responses
as confidential, while providing the necessary level of insight to analyze survey
results.
Data Visibility Settings
Setting | Setting Location | Description |
|---|---|---|
Number of responses
| Controls the required number of responses to display a segment for
comparison. Example: you set Number of
responses to 5, and Aggregation
period to 1 year. A segment displays data if 5 unique
employees answered a survey in the last 1 year. | |
Number of scores per question
| Controls the required number of responses to display a driver or a
question for comparison. Example: you set Number of scores per
question to 5, and Aggregation
period to 1 year. A driver, or a question displays data
if 5 unique employees answered that specific driver or question in the
last 1 year. | |
Unique employees across two segments
| Administration
Data
Settings
Data
| Accounts for cases of 2 mostly overlapping segments to avoid exposure
through comparison. Example: you have a country manager with an All
reports segment containing 49 employees in their reporting line.
There's also a Country segment with 50 employees, containing the same
group as well as the country manager themselves. If both segments are
visible and available for comparison, the confidentiality of the country
manager is at risk. If you set this setting to 2, one of the overlapping
segments isn't visible, because the number of unique employees between
them is less than 2. |
Comment visibility thresholds :
Segments
| Controls the required number of responses to display comments in a
segment. This setting is the cap for the Number of
responses setting, and it works on a per-survey
basis.Example: you set Number of responses to
5, and the Aggregation period to 1 year. A
segment displays comments if 5 unique employees answered a survey in the
last 1 year. | |
Comment visibility thresholds :
Responses
| Controls how many employees must answer the survey in a survey round,
to display comments for that specific round. The combination of the 2
settings can alleviate confidentiality risk during periods of lower
participation, such as summer holidays. This setting works on a per-survey
basis, and can't be higher than the comment visibility threshold of
segments. Example: you set Comment visibility
threshold for Segments to 6 and
Comment visibility threshold for
Responses to 3. Comments are visible if at
least 6 employees have answered the survey in the visibility window, of
which at least 3 answered that specific survey round. | |
Display settings :
Date
| Controls whether the date on each comment is the comment date or end
date of the survey round that contained the comment. | |
Display settings : Conversation email
content
| Controls whether to display the message, conversation history, and
original comment in comment reply emails. When this setting is off, the
employee needs to click a link to go to the conversation. We recommend
enabling this setting if your organization uses personal dashboards, to
encourage employees to view conversations securely in their personal
dashboard. | |
Restricting attributes and segments | To restrict an attribute:
Alternatively, to restrict individual segments: | Enables you to restrict attributes and segments, and use access groups
to control who can see this data. You can restrict attributes on a dashboard
level and an employee record level. Restricting an attribute on employee
record level also hides the list of surveyed employees on its
dashboard. Example: you create an editable attribute named Ethnicity,
so employees can validate which segment they should be part of during
their survey. The aggregate dashboard data should be visible to the
Diversity & Inclusion consultant, without seeing the employees who
selected each segment. Set the employee record access to No one ,
and dashboard access to Only those with rights to access restricted
segments . |
Access Control Permissions
You can set permissions individually for each access control group.
Permission | Description |
|---|---|
Access list of employees who received the survey
| Controls whether you can display the list of employees that were part
of the survey, during the visibility window. |
Access restricted attributes
| Controls whether you can display segments of restricted
attributes. |
Access comments
| You can control the types of comments, if any, each access group can
view. |
Access comments in real time
| Controls whether comments become visible in real time, or, if disabled,
end of round. |
View comment managers
| Controls whether you can display the hierarchical list of managers on a comment. The
list only displays managers whose segments have met the visibility
requirements. The list adapts based on the context and the manager viewing
the comment. Example: you can't view the segment of a manager due to
overlapping segments, so their name isn't visible on comments from their
direct reports in your view. The administrator can view the segment of
this manager, so when they view the same comments, the manager's name is
on the list. |
View comments by segment
| Controls whether you can filter comments by specific segments. If you
disable this permission, members of the group can only view comments on
their overall dashboard, but not when drilling into subsegments that met the
visibility requirements. |
Survey Experience
Survey Experience | Description |
|---|---|
Overall confidentiality | The scores and comments an employee submits are confidential and don't
reveal their identity. |
Participation | Survey participation is optional, and the dashboard doesn't reveal
which employees actually answered the survey. Employees can also skip
questions, and leaving comments is optional. |
Comments | Comments never reveal the identity of the employee. Automatic comment shuffling
prevents comments from a single survey submission displaying as a group on a
manager dashboard. |
Receiving emails | Employees can unsubscribe from emails by clicking on the link at the
bottom of the email. Unsubscribing to 1 email type doesn't opt you out of
other email types. Example: if you unsubscribe to the survey email, you can
still receive comment conversation or acknowledgment emails. |
Personal dashboard | Employees can only access their scores and comments on their personal dashboard by
logging in using the email address on their employee record. |
Emails
Email Type | Confidentiality Features |
|---|---|
Survey email | The survey email contains the name of the employee, however the answers
the employee submits won’t display their name. The name is present to
indicate that the employee shouldn’t share their survey link with another
employee. |
Survey reminders | Because each employee has a unique survey token, they receive reminders
if their participation isn't complete. The reminders are automatic, so
participation status of each employee remains confidential. |
Comment acknowledgment | You can control which access control groups can acknowledge comments.
Employees receive an email with a random delay containing the name of the
manager and the acknowledgment. |
Comment reply | You can control which access control groups can reply to comments.
Employees receive an email with a random delay containing the name of the
manager, the content of the reply and the option to respond. Responses of
the employee remain confidential throughout the process. You can remove the
comment preview from the email content in Data
Settings . |