
What anonymous has to mean to actually be anonymous
Anonymous reporting is easy to offer and hard to mean. The gap between the two is where people get identified.
The name, everywhere, not just on the report
Persohap uses what we call a hidden-identity model. Your account stays linked to the report — that is how you can follow the case and reply to a handler's questions. But for an anonymous report your name is never serialised into any response.
Not to case handlers. Not into the audit view. Not back to you: your own case reads "submitted anonymously", which is deliberate. If your view showed your name, anyone glancing over your shoulder would learn something the handler is not allowed to know.
The job role is a deanonymisation channel
This is the one people miss. Hiding the name but showing the role looks harmless until you consider a department with one manager. "The manager filed it" identifies exactly one person.
So on an anonymous reporter's own log rows, the role is nulled alongside the name.
Error messages leak too
If asking for a case you may not see returns "forbidden", you have learned the case exists. Ask for a few plausible identifiers and you can map what is being investigated without ever reading a word of it.
Denied access returns "not found" — the same answer as a case that does not exist. Platform operators have no branch in that check at all.
Consent has to survive the org chart
Beyond administrators, the reporter chooses who else may read the case: their direct manager, their department head, each shown by name so the choice is informed.
That grant is snapshotted at submission. We store the specific person consented to, not the role. A reorganisation, a promotion or a new line manager never grants access to an old case — including, pointedly, when the new manager is the person the report is about.
Only the reporter can withdraw
Not an administrator, not a handler, and not the subject of the report. And the access log is kept separately with no links to the case, so its rows survive the deletion of the case they describe.
What we do not claim
This is a description of mechanics, not a certification. We make no claim of EU Whistleblower Directive compliance, there is no retention policy or scheduled deletion, and designated compliance officers as handlers are a planned option rather than a shipped one.

We publish the review formula before anyone is scored
Goal progress 30%, kudos 15%, your department's own yardsticks 55% — and the reward scheme is fixed during setup, before a single person is graded. Here is why the order matters more than the numbers.
Read article
One yardstick at a time, across the whole team
Judging a whole person in one pass invites the halo effect, where a strong impression on one measure bleeds into every other rating. So the scoring board is built the other way round.
Read article
In, out, or unresolved — the third answer that matters
Eligibility used to have two outcomes, and a blank cell quietly meant "out". Somebody could be dropped from their own performance review with no warning anywhere. Now a round refuses to launch instead.
Read articleSee it working, not just described.
Every decision in these posts is visible in the product. We will walk you through whichever one you care about.

