guide

How to run an employee satisfaction survey and keep it anonymous

September 19, 2026 ・ Halict Editorial

An employee satisfaction survey is usually announced as anonymous and then built in a way that is not. The form asks for department, office, tenure band, and role level, because the results will be more useful sliced up. Put those four answers together in a company of two hundred and a good number of respondents are uniquely identified without a single name being collected.

Staff sense this, often without being able to articulate exactly how. The visible result is not an accusation. It is a set of cautious sixes and a comment box that is left empty, and a report that says the company is fine.

The design problem is a trade off, not a technicality. Every slice that makes the results more useful to act on makes the responses more identifiable. What follows is how to make that trade deliberately, and what to check about the form tool before promising anything.

Decide what the result is for before choosing questions

A satisfaction survey can serve at least three different purposes, and the question set differs for each.

Tracking a number over time. The aim is a stable figure that can be compared with the same figure next year. This calls for a short, unchanging question set and consistent timing. Its output is a trend line, and its value comes entirely from repetition, which means the wording must be frozen after the first round.

Finding out what to fix. The aim is a ranked list of problems with enough context to act on. This calls for driver questions and open text, and it tolerates changing questions between rounds because the output is a list of actions rather than a comparable score.

Reporting to a board, an owner, or a certification scheme. The aim is a defensible figure produced by a documented method. This calls for a known instrument and stated response rates, because the number will be questioned.

These pull in different directions. A survey redesigned every year cannot produce a trend. A frozen survey cannot investigate this year's particular problem. The practical answer for most companies is a short core set that never changes, plus a small rotating block of three or four questions about whatever is live this year. That keeps the trend intact and still leaves room to ask about the office move or the new shift pattern.

Write the purpose down in one sentence before the first question is drafted. It settles most of the later arguments, including the one about whether managers get to see results for their own teams.

The core question set

Satisfaction is not one thing, and a single question about it produces a number nobody can act on. The workable structure is one summary question plus a small set of drivers.

For the summary, the two common options are a straight satisfaction rating and a recommendation question of the kind used for employee net promoter scores. Either works. Mixing them in the same round produces two numbers that disagree slightly and an argument about which is the real one.

For the drivers, six to ten statements rated on a labelled five point scale cover most of what actually moves satisfaction:

  • The work itself is a good match for what this person is good at
  • The workload is sustainable at its current level
  • It is clear what good work looks like in this role
  • The direct manager gives useful feedback
  • Decisions that affect this team are explained
  • Progression and pay are dealt with honestly
  • The tools and information needed to do the job are available
  • Effort is noticed
  • Raising a problem is safe
  • The stated values match how things actually run

Label every point on the scale rather than just the ends, keep all statements pointing the same way so a high score always means good, and include a no opinion option. Reverse worded statements sprinkled through a list to catch inattentive respondents mostly catch people reading quickly and add noise.

Then two open questions, no more. One asking what the single most useful change would be, and one asking what should not change. The second is not filler. It is the only place a survey collects information about what is working, and it protects the things a new manager might otherwise dismantle.

Total: twelve or thirteen questions, about five minutes. A thirty minute survey does not produce three times the insight. It produces a completion rate that falls off after the first page and a sample skewed towards people with time to spare.

Demographic questions are where anonymity is lost

This is the section to read twice. Names and email addresses are the obvious identifiers and are easy to leave out. Combinations of attributes are the real risk, and they arrive disguised as sensible reporting requirements.

Each attribute multiplies the number of possible groups. Department with eight options, office with four, tenure in three bands, and role level in three gives two hundred and eighty eight combinations. In a company of two hundred people, most of those combinations contain nobody, and the ones that contain somebody usually contain exactly one person. No name was collected, and the author of every comment is still findable.

Three habits keep this under control.

Ask for one attribute, or at most two. Usually department alone is enough to act on. Adding tenure and level to the same form rarely changes any decision and always narrows the group.

Use wide bands. Three tenure bands rather than six. Group small departments into a single other category rather than listing them, because a department of four is not reportable whatever the form promises.

Set a reporting threshold and publish it before the survey opens. Results are shown for any group with at least a stated number of responses, commonly five, and groups below it are folded into the next level up. This is the rule that makes small team members willing to answer, and it has to be announced to have that effect.

The uncomfortable part is that a manager of five people may then get no group specific results. That is the correct outcome. Handing a manager three free text comments from a team of five is not anonymous reporting under any definition, and everyone on that team knows it.

What anonymous has to mean in the form tool

Announcing anonymity is a claim about software behaviour. It is worth checking each of these before the claim is made, because several form tools collect identity by default for good reasons that do not apply here.

What a form tool may record Does it identify a respondent What to do for an anonymous survey
Name or email question in the form Yes, directly Remove the question rather than leaving it optional
Required sign in before answering Yes Use a tool where respondents answer without an account
A unique link per person Yes, by design Send one shared link to everyone
Automatic contact records keyed on email Yes, if email is asked Leave email out entirely so no contact record is created
Submission timestamp Sometimes, in a small team on a known shift Report in weekly buckets, not by time of day
Free text wording Often, and averages do not protect it Decide in advance whether text is passed on as written or summarised
Uploaded files Yes, through document properties Do not ask for uploads on this form

Two of these deserve extra attention. Unique per person links are convenient, because they let a reminder go only to people who have not answered. They also make every response traceable to an individual, which cancels the anonymity entirely. Pick one. If chasing non respondents matters more than anonymity, say so plainly and run the survey as confidential instead.

Automatic contact building is the other. A tool designed around enquiries and applications will often create a person record from the email address, which is exactly right for a support queue and wrong here. The feature list of whatever tool is in use will say whether contacts are built from responses, and the fix is simply not to ask for the address.

Last, check who inside the workspace can open the raw responses. Announcing that only two people read the answers means nothing if everyone with a login can see them. Some plans separate a full member from a view only role and some do not, and that distinction usually appears on the pricing page rather than in the feature list.

Response rate, and what a number can carry

A satisfaction score without a response rate next to it is not a result. Sixty per cent satisfied among thirty per cent of staff says almost nothing, because the people who do not answer a staff survey are not a random sample.

Useful reference points, without pretending they are laws: under fifty per cent is a finding in itself and should be reported as one. Sixty to seventy five per cent is normal for a well run voluntary survey. Above ninety per cent in a large company usually means people believe participation is being tracked, which is worth knowing too.

Small numbers need honesty rather than decimal places. In a group of eight, one person changing their answer moves the average by a noticeable amount, and reporting that movement as a trend is misleading. Report counts alongside percentages for any group below about thirty, and resist the urge to rank departments against each other when the differences are within the noise.

Comparisons over time work only when the questions, the scale, and the timing all stay the same. A survey moved from March to November has weather, workload, and the aftermath of a reorganisation baked into the change. Hold the date roughly constant, and record what else was happening that month in the report, because next year's reader will not remember.

Turning it into something visible

Everything above is preparation. What determines whether the next round gets answered is what happens in the fortnight after it closes.

Publish results within two weeks, including the parts that look bad. Withholding the low scores is always noticed, because the people who wrote them remember what they wrote. Then pick three things. Say which two will be acted on and by whom, and say which one will not be and why not. A refusal with a reason costs far less credibility than silence does.

Then keep the open questions moving through a workflow rather than a document. Comments naming a broken process, a manager problem, and a facilities issue go to three different people, and the common failure is that all of them stay in one exported spreadsheet that nobody owns. Assigning each item an owner and a status, so the list can be worked down and reviewed later, is the mechanism that makes the survey different from a suggestion box. The same handling shows up in other inbound processes and the requirement is identical: an owner, a state, and a review date.

Six months later, publish a short update on those two commitments. That update, more than any question wording, is what produces a higher response rate next year.

What to change first

Take the draft form and delete every demographic question except one, then set and publish a reporting threshold. That single edit does more for honest answers than any rewording of the satisfaction questions.

Then check whether the tool creates a person record from responses and whether every login can read the raw text, and fix the answer before the survey is announced rather than after. A tool where each response carries an owner and a status makes the follow up work visible, and Halict can be tried on a short pilot round first.

Q1. Can an employee satisfaction survey really be anonymous?

Yes, if the form asks for no identifying field, respondents do not have to sign in, links are not unique per person, and the demographic questions are wide enough that no combination points to one person. Announcing anonymity while sending a personal link cancels it, and staff usually work that out.

Q2. How many questions should the survey have?

Twelve or thirteen, taking about five minutes: one summary question, six to ten driver statements, and two open questions. Longer surveys lose people partway through, and the ones who finish tend to be those with time to spare rather than a representative sample.

Q3. What is a good response rate?

Sixty to seventy five per cent is normal for a voluntary survey with no pressure attached. Below fifty per cent, the result should be reported with that caveat attached, since non respondents in staff surveys are not a random sample of the workforce.

Q4. Should managers see the results for their own teams?

Only where the group is large enough to meet the published reporting threshold, commonly five responses. Below that, fold the results into the next level up. Passing three comments from a team of five to that team's manager is not anonymous reporting, whatever the form said.

Q5. How often should it run?

Once a year for the full survey, with the date held roughly constant so comparisons mean something. A shorter pulse of four or five questions can run quarterly if there is a genuine intention to act between rounds. Surveying more often than the organisation can respond produces falling participation.

All guides

How to run an employee satisfaction survey and keep it anonymous | Halict