How anonymity works

People tell you the truth when they believe they are safe. That belief has to be earned with specifics, so here are ours — the actual numbers the platform enforces, and the honest limits of what they guarantee.

The thresholds

A small sample is the enemy of anonymity: in a team of three, a single comment is as good as signed. Timbre suppresses results until enough people have answered that no individual stands out.

4responses

Before comments appear

Verbatim free-text answers are withheld until 4 people have completed the campaign. Below that you still see how many responses came in — you just cannot read them.

A Client Administrator can adjust this from 2 to 10. It cannot be set to 1, which would tie a comment to the only person who wrote one.

5responses

Before answer patterns appear

The per-respondent view — one row per anonymous participant showing how they scored every question — needs 5 responses. A pattern of answers is more identifying than any single score, so this floor is higher.

Fixed; not configurable.

5per department

Before a department is broken out

Department comparisons need 5 distinct respondents in a department. Smaller departments are merged into “Other” rather than shown.

And if “Other” itself does not reach 5, it is dropped entirely instead of becoming a group of one.

What is never shown

No screen, report, PDF export, or AI summary in Timbre attributes a response to the person who submitted it. There is no admin view, no support tool, and no export that reveals it. When a report shows a per-respondent pattern, the rows are anonymous participants — never names.

Administrators can see who has and has not completed a survey. That is deliberate: someone has to chase the people who have not answered yet. Completion is tracked; content is not attributed.

What this does and does not guarantee

Being precise matters more here than sounding absolute. Timbre’s anonymity is enforced by the application: the platform holds the link between an invitation and the person it was sent to, so that reminders can go out and each person can answer once, and it never surfaces that link alongside anyone’s answers.

What that means honestly: your responses are not anonymous to the database, they are anonymous to everyone using the product. Someone with direct production database access — us, not your administrators — could technically correlate a submission with an invitation. We do not do this, no feature depends on it, and access is restricted and logged. But we would rather write that sentence than claim a mathematical guarantee the system does not implement.

If a stronger guarantee matters for your rollout, tell us — severing that link at submission time is a change we are willing to make for customers who need it.

Why anonymity is the default, not a setting

In most feedback tools anonymity is a per-survey checkbox, which means it is also a per-survey decision someone can quietly get wrong. In Timbre, anonymous responses are how the product works — there is no toggle that turns attribution on, because the reporting layer has nowhere to display it.

The one thing an administrator controls is the comment threshold, and only within the 210 range above. Lowering it to 2 is offered because a five-person team otherwise never sees a single comment; the trade-off is shown in the product when you change it.

Telling your team

The threshold only builds trust if people know about it. Link this page in your launch announcement — it says the number out loud, which is more convincing than an assurance that responses are “confidential”.