Paid module
Employee surveys with honest anonymity
The Engagement module runs pulse and annual surveys whose anonymity is enforced by the schema rather than promised in a policy. In anonymous mode, participation and responses sit in separate tables with no key between them, so a response has no author to find, and results appear only above the tenant’s minimum group size.
- Counted on
- per employee, monthly.
- Published limits
- 5, taken from the module specification and printed in full below.
- Documented seams
- 1, to one other module . Each one is optional, and absent rather than broken when the other is off.
- In the catalogue
- How people are doing
- To switch it on
- A paid plan, then one click inside the app. What it costs , and what enabling any module means.
What Engagement does not do
Every module here publishes its non-goals, from its own specification. Boundaries you learn before buying are features; boundaries you learn after are refunds.
5 published for Engagement
-
No sentiment AI and no text analytics over free text.
Nothing here scores an individual, and analytics over anonymous answers is exactly where deanonymisation lives.
-
Below-threshold slices return a stated refusal, not numbers, and the refusal is enforced in the report functions rather than hidden in the interface.
It guards administrators too, and managers do not get team results by default.
-
It cannot stop someone signing their own free-text answer.
The product says so where people type rather than pretending otherwise, and free text is optional per question.
-
Attributed surveys exist, but never as a default and never as a silent switch: the mode is fixed at creation and labelled on every surface, including the respondent’s.
-
No recognition walls, no always-on lifecycle listening, no action-planning workflow and no benchmark library.
How it runs in practice
A quarterly pulse goes out in two questions. Reminders reach the people who have not answered, because participation is tracked separately from answers rather than by looking at who said what, and team-level results appear only once a slice reaches the tenant’s minimum group size, five by default and never configurable below three.
Where Engagement meets your other modules
Each of these is a boundary both specifications state, so it reads the same from either side. Every one is optional: with the other module off, the capability is absent rather than broken.
- Advanced Analytics
A joined report inherits the survey minimum group size, so a join can never widen it.
Engagement questions
Who is Engagement for?
Companies that want to ask their people honest questions and be believed when they say the answers are anonymous. It suits a team large enough that anonymity is meaningful and small enough that a survey platform with a professional-services attachment is absurd. The buyer is usually a founder or people lead. It is a poor fit if what you want is continuous listening, benchmark comparisons against other companies, or an action-planning workflow, because none of those is built here.
How is the anonymity actually enforced?
By the shape of the data rather than by a policy. In anonymous mode, participation and responses are stored in separate tables with no key joining them, so an anonymous response has no author to find even for someone with full database access, including us. Results appear only above your minimum group size, which is five by default and can never be configured below three, and a below-threshold slice returns a stated refusal rather than numbers. That refusal is enforced inside the reporting functions rather than in the interface, so it guards administrators too, and managers do not get team results by default. The one thing software cannot prevent is someone identifying themselves in a free-text answer, and the product says so where people type rather than pretending otherwise.
What do I need in place before I can turn Engagement on, and how much setup is it?
A paid plan first, because paid modules cannot be enabled on the free plan. After that it is one of the lighter modules to start: your org structure needs to be accurate, because audiences and result slices are composed from it, and then you decide your minimum group size and write the questions. The mode, anonymous or attributed, is fixed when a survey is created and cannot be switched afterwards, so the decision that matters most is made once per survey rather than configured globally. A two-question pulse can go out the same afternoon you enable it.
What does Engagement explicitly not do?
There is no sentiment AI and no text analytics over free text: nothing here scores an individual, and analysis over anonymous answers is exactly where deanonymisation lives. It does not show you below-threshold slices under any circumstance, including for administrators. It cannot stop someone signing their own free-text answer, and it says so where they type. Attributed surveys exist but never as a default and never as a silent switch: the mode is fixed at creation and labelled on every surface, including the respondent’s own. And there are no recognition walls, no always-on lifecycle listening, no action-planning workflow and no benchmark library.
How does Engagement fit with the core and the other modules?
It composes audiences and result slices from the core org structure, sends through the core notification ladder and registers its reporting with the core report registry. It needs no other paid module, and it deliberately shares no scale or vocabulary with Performance & OKR, so a survey scale is per-survey rather than a company-wide setting some other module also reads. The interaction worth knowing is with Advanced Analytics: a composed report that reads engagement data inherits this module’s minimum group size, so joining survey results to another dataset cannot be used to get below the floor. A gate here survives every join elsewhere.
What happens if I turn Engagement off?
Surveys, responses and the results views stop being reachable, and billing stops at the end of the current period rather than on the day. The data is retained on a schedule and restored if you re-enable within that window, and a full workspace export includes module data whether or not the module is currently enabled. Anonymous responses stay anonymous throughout, because there is no key to rejoin them to a person: disabling a module does not unlock something the schema never held. Nothing in the free core changes.
Engagement needs a paid plan. The core it sits on does not.