Two risks pointing in opposite directions
Direct answers become sensitive when they can be linked to a person. ChefQuote does not use them to estimate whether a specific person will leave. Both failure modes below end the same way: the data becomes unsafe and untrustworthy.
Risk 1 — retaliation against the employee
Someone reports exhaustion or unfairness. A manager reads it, works out who wrote it, and it shows up in their sections, their shifts, or their file. The next survey is a lie. Everyone learns to answer safe and the signal dies.
Risk 2 — the survey used against a manager
A frustrated employee uses the survey to damage a manager's standing. Relational conflict enters as data and gets treated as measurement. Managers who fear this will block or discredit the tool, and it never gets adopted at all.
The governing rule
People data splits into two classes, treated completely differently. This single line is what lets the model keep its precision without exposing anyone:
- Class A — derived from the schedule Visible per person Shift length, consecutive days, turnaround, overtime, workload concentration. Management sees these per person because management created them. Showing a manager their own schedule reveals nothing new.
- Class B — given by the person Never visible per person Recognition, belonging, voice, fatigue, intent to stay. These exist only because someone chose to answer. The production intake accepts qualifying team-level aggregates, not individual rows.
Owner & management commit
- No adverse action from any response. Scheduling, sections, pay, standing and advancement are unaffected by what someone answered.
- No write-up may originate from survey data. Discipline requires an observed, documented performance fact. Survey data is not evidence.
- Hours are not cut using this data without consent. An overload flag starts a conversation about what that person wants — not a unilateral cut to their income.
- In-person input outranks the system read. If the read says one thing and the person says another, the person is right.
- A conversation happens before any change affecting a person. The data opens the discussion. It never concludes it.
The employee is guaranteed
- Individual answers are never shown to management. Not to your manager, not to the owner, not in an export, not in a report.
- High-risk answers aggregate only. Intent to leave, financial strain and safety concerns never release at individual level, at any team size.
- Free text is themed, never quoted. Writing style identifies people. Management sees categories and counts, never your words.
- The questionnaire prototype shows the answers entered in the current session. Those sample answers are held in page memory only and clear on reload.
- You see exactly what management sees. The manager view is open to you. There is no hidden second report.
The employee commits The half most tools omit
Leaving this side out is why managers distrust survey tools. Protection has to run both directions or neither party answers honestly.
- Answers describe working conditions, not personal grievance. A conflict with a specific person goes to the escalation route where it can actually be addressed — not buried in a rating where it silently distorts the model.
- Serious concerns are raised, not stored. Safety, harassment and wage issues have a direct route to someone who can act, including a route that bypasses the person complained about.
- The survey is not a disciplinary channel. It cannot produce a write-up for anyone, employee or manager. Using it to damage someone's standing does not work by design.
Four instruments, each feeding one thing
Not one generic engagement survey. Each exists because something downstream needs it, and each is short enough to actually get answered honestly. Open one to try it.
What the manager thinks, against what the crew reports
The same constructs are asked of both sides. The distance between them is the signal — and it is diagnostic, not disciplinary. A large gap means a manager is flying blind, which is a fixable information problem. It surfaces before turnover, which is the entire point.
Answer the Weekly Pulse and the Manager & Owner Reflection in the surveys tab to populate this.
The same responses, two audiences
The protection made visible. Toggle between them — identical underlying data, filtered by the Class A / Class B rule. The employee view is deliberately richer, because the person is entitled to their own information.
What this data will never be used for
Published to both sides, inside the product, before anyone answers a question. A commitment only management can read is not a commitment.
- Employee discipline will never be based on survey responses. No write-up, no final warning, no termination traces back to an answer.
- Time off will never be scheduled from the data alone. A fatigue flag starts a conversation about what that person actually needs. It does not silently move their shifts.
- Manager discipline will never be based on responses alone. A poor team score triggers a conversation between the manager and their people first. Support before consequence.
- Negative feedback will never be attributed to a specific person. Not by name, not by role, not by a team small enough to guess.
- The system will never recommend a write-up, a demotion or a firing. It has no such output. There is no screen where that appears, for anyone.
How the protection is enforced
Promises are not protection. These are required release controls for any production survey service. The questionnaire below is a single-session prototype, not a production aggregation service.
Minimum group size
- No team-visible output from fewer than five responses. Below that it rolls up a level or is suppressed. Small teams are where most survey tools quietly fail.
- No manager-specific readout below five direct reports. Otherwise the manager readout is the individual readout.
- Trends only, never single-response deltas. In a six-person crew, a score that moves the day after one person answers identifies them.
Attribution
- Free text categorised, never surfaced verbatim. Phrasing, spelling and vocabulary are identifying.
- High-risk items never leave aggregate. Intent to stay, financial strain, safety and fairness concerns.
- Escalation bypasses the subject. A concern about a manager never routes through that manager.
Retention
- Raw-response retention requires a configured production service. This static prototype stores sample answers only in page memory and clears them on reload. The structured operating intake accepts aggregate result CSVs, not raw responses.
- Export carries the same rules. No export path produces individual Class B data. The protection cannot be walked around with a download button.
How this reaches every part of the site
Surveys are not a bolt-on section. Each instrument feeds a specific page, and each page declares what it may and may not see. This is the integration contract.
What this is built on
Constructs drawn from published work and re-worded as original items. No licensed or copyrighted instrument is reproduced.
Prototype questionnaires · sample responses · structured intake accepts aggregate result CSV only, never individual answers