My company’s new Reflect & Engage service makes a bold promise:
Every leadership team knows more than its meetings reveal. We help surface that insight before the decision is made.
Think about the last time your team committed to a direction, and someone said afterward, “I had a feeling that wouldn’t work.” That feeling was data. It just never made it into the conversation.
The process is designed to remove the social pressures that suppress dissent. Participation is voluntary. People record audio responses to targeted reflection questions anonymously and asynchronously, and can decline any question or withdraw entirely. No one’s reading the room, no hierarchy to defer to. Their responses are analyzed to surface tensions and divergent assumptions rather than convergence, and the results are delivered as what we call a Field Report: a map of the group’s actual thinking, including the minority perspectives that a typical meeting would bury.
The quality of our analysis depends on people sharing what they actually think. Why on earth would they trust us enough to do that? Why would participants believe their responses will be truly anonymous?
The conventional wisdom is that trust is earned. I don’t think that’s quite right. “Earning” implies that if I check enough boxes, trust is owed to me, and that gets the relationship backwards. Trust is always granted by the person taking the risk. The best we can do is to act in a manner worthy of trust.
So the design question I’ve been wrestling with isn’t “how do we earn trust?” It’s “what would make us worthy of it?” That’s a very different question, and it’s shaping how we’ve built the Reflect & Engage service.
Broken Promises of Confidentiality
The standard promise of confidentiality fails because it can be broken. I suspect that the trust problem isn’t about intent, it’s about architecture.
“Your responses will be kept confidential.” It’s in every survey and 360 review. Have you ever been burned by it? Has a manager somehow known what was said and by whom? Has your “anonymous” feedback been clearly identifiable by role or writing style? Was the supposedly aggregated data shared in a way that made attribution obvious?
“We’ll keep your personally identifiable information safe.” Every organization that’s ever had a data breach said exactly that. What if we worked to make the promise unnecessary?
Data That Isn’t Captured
What does real anonymity require? What’s the minimum information necessary to fulfill our promise to deliver insight? Those are the questions shaping our approach “via negativa,” removing the opportunity to do harm rather than promising to do what’s right.
We don’t collect names or email addresses. We don’t promise, “We won’t associate your name with your answers.” We don’t have your name. There’s nothing to leak because the identifying data doesn’t exist1.
Data We Don’t Control
Audio is different. It’s inherently identifying. Anyone who knows you will recognize your voice. This is the one place where our protection is a policy, not an architecture.
We can’t un-hear a voice. What we can do is limit exposure. The facilitator never hears recordings. The sponsor never hears them. No person outside of our company listens to them.
There’s something else we should be transparent about. We expect to process audio through a third-party behavioral analytics service to extract non-verbal signals. These inferred metrics enrich the collective synthesis. For example, they help us identify where participants feel the strongest conviction or the greatest uncertainty. Behavioral data is never attributed to individual participants in any deliverable, and it’s subject to the same deletion timeline as everything else.
Deleted Data Can’t Be Shared
Within 30 days of the conclusion of an engagement, we delete everything. That includes the voice recordings, transcripts, behavioral analytics data, and participant metadata. The only artifact that persists is the Field Report: anonymized, aggregated synthesis. The process extracts collective intelligence and then destroys the individual inputs that produced it.
Of course, participants don’t see the data get deleted. On this point, we’re asking them to take our word for it, which brings us right back to the trust problem we’re trying to design around. I’m not sure what to do about that yet.
What Architecture Can’t Solve
The high-stakes conversations that warrant an intervention like Reflect & Engage often involve a small group of people. That poses a problem. Even when the analysis is stripped of identifying information and aggregated, members of the group might be able to infer attribution of a minority perspective. Complete, unassailable anonymity may be out of reach.
Unlike the data problem, I don’t think this can be solved by architecture. It requires judgment — ours and the facilitator’s. That’s a real limitation, and it shapes where and how we’re willing to operate.
The Field Report is delivered to a professional facilitator, not directly to the sponsor. We rely on the facilitator’s experience and skill to artfully incorporate minority perspectives into their facilitation plan without exposing their source.
Before we commit to an engagement, we sit down with the sponsor and facilitator to understand the context, the sponsor’s objectives, and their likely receptivity to contrary input. If we’re not confident the environment is safe enough, we won’t proceed. We might suggest the team complete a psychological safety assessment based on Amy Edmondson’s research. If the sponsor declines or if the results indicate low psychological safety, Reflect & Engage is probably not a fit.
The onus is on us to apply Reflect & Engage in a disciplined manner. To be trustworthy, we can’t shoehorn ourselves into a situation where inferred attribution is likely to have negative consequences for a participant.
Building Something Worthy
Chatham House — an organization and place in London — was formed “from the ashes of war” to “foster mutual understanding between nations.” It is guided by “The Rule”:
When a meeting, or part thereof, is held under the Chatham House Rule, participants are free to use the information received, but neither the identity nor the affiliation of the speaker(s), nor that of any other participant, may be revealed.
The Rule doesn’t ask anyone to be trustworthy. It changes the structure of the conversation, making candor possible. That’s the same instinct behind Reflect & Engage: don’t promise to protect people, build a process where the promise is unnecessary.
We started with a simple observation: every leadership team knows more than its meetings reveal. The insight is already there. It’s in the person who stays quiet because they’re reading the room. It’s in the half-formed concern that needs twenty uninterrupted minutes to articulate. It’s in the feeling someone has afterward that this won’t work.
The question was never whether that insight exists. It was whether we could build something worthy of receiving it.
There’s a related boundary worth naming: the platforms we use to host reflection forms automatically collect technical metadata as part of their standard operation. That data is collected and retained by those platforms under their own privacy policies, outside our direct control. We never access or correlate it with participant responses, but we can’t pretend it doesn’t exist.


