Anonymous employee feedback works only if the boundary is exact.
Ask employees whether their survey answers are really anonymous and you get a polite silence — which is itself an answer. Doubt does not show up as a drop in participation. People keep answering. They simply stop saying anything that would cost them something, and the report that lands on a leader's desk looks perfectly healthy right up until the moment it needs to be useful. Confidence in a feedback channel rests on a boundary people can describe in their own words, not one they have been assured of by a policy they never read.
Trust is built by a boundary people can describe, not by a policy they've never read
Privacy language rarely does the work it is asked to do. Employees decide whether a channel is safe by reasoning about it plainly: who could figure out it was me, and what would happen if they did? A design that survives that question in ordinary language is worth more than a page of assurances.
In 360Score.me, anonymity is an architectural decision rather than a policy setting — built into how responses are stored and retrieved, not a configuration an administrator could reverse. The mechanism is two separate paths. When someone signs in, an identity check confirms only that they were invited and haven't already submitted. Their answers then travel down a second path entirely, carrying only the survey, the question, and the value — no email address, no network identifier, no timestamp granular enough to triangulate against a calendar. The two paths meet again only in aggregate, and only after the reporting threshold has been satisfied.
Knowing how many responded is not the same as knowing who did
Response and participation rates are visible to managers — and they should be. A score built on nine responses out of forty means something very different from the same score built on thirty-six, and a leader who can't tell the two apart isn't reading a result so much as guessing at one.
360Score.me makes participation and response rates visible across the organization, to employees and managers alike, rather than reserving them for senior leadership. Engagement is a shared condition, and a team that can see its own turnout — and how it compares to the rest of the organization — tends to act on that information without being asked.
What no manager ever sees is attribution — a name beside a score, a name beside a comment, a name beside a survey that was never opened. The count is a property of the group. The identity is not available at all.
✓ Managers see
- Aggregated scores once the threshold is met
- Unattributed comments, grouped by theme
- Response and participation rates — counts, never a roster
- Trend lines across survey cycles
✗ Managers never see
- Which named individuals responded
- Which named individuals did not respond
- Individual answer rows
- Who wrote any given comment
Small groups are where confidentiality is won or lost — which is why reporting waits for a floor.
Why small groups wait for a floor before anything is reported
Consider a team of four. Publish their results and it takes very little arithmetic — spread across two cycles — to work backward from a shifting average to the person whose view changed. The people on that team can run the same arithmetic, which is exactly why they answer carefully when they suspect the group is small.
Five unique respondents is the smallest group in which an individual answer stops being recoverable, even when demographic filters are applied. Below that number, nothing is shown — not a score, not a comment, not a rate. That floor is built into the platform rather than left to a configuration setting, because a threshold that can be turned off in a moment of curiosity is not a threshold.
Skip-level reviews sit at a floor of three, for a structural reason: the responding pool is bounded by the organization's shape, and additional masking applies to the results that do surface.
A note on moderation: administrators can remove content that violates platform or company policy, without ever learning who wrote it. See the Terms of Use.
Anonymous by design — attributed by necessity
It would be simpler to make everything anonymous. It would also be wrong. The right answer depends on what each instrument is being asked to do.
360 Peer Reviews and Company Pulse surveys are unattributed on purpose. Both measure conditions and observed behavior, and in both cases a name adds nothing to what a leader can conclude while meaningfully degrading the quality of the answer given.
Performance Evaluations in 360Score.me disclose identity, equally on purpose. When a supervisor evaluates an employee, the result becomes a formal record attached to a consequential decision. That record is only defensible — to the employee receiving it, and to anyone reviewing the decision later — when the rater is known. The platform states that distinction at the survey type itself, so no one has to guess which kind of channel they've been invited into. It is the same logic that keeps cadence measurement and evaluation on separate instruments.
The first three cycles settle the question
In practice, none of this is decided by a policy document. It is decided by what employees observe over the first few cycles of a program. They notice whether small teams stay blank when they should. They notice whether what a leader says afterward reveals something that leader shouldn't have had access to.
Get those cycles right and the question quietly stops being asked. Get one of them wrong and it gets asked for years — usually in silence.