Count the responses, hold back any cell small enough to name the person who wrote it, and put the finding in front of a named officer who decides whether it may be published.
A wave closes, and the cell each answer was counted in is written down beside it.
02
A cell falls under the reporting minimum, and it is suppressed before a manager reads it.
Reason
03
The employer knows the roster, which is what GDPR Recital 26 means by means reasonably likely.
04
A survey runs on a platform, and BetrVG § 87(1) Nr. 6 turns on objective suitability alone.
05
In BAG 1 ABR 47/16 the survey escaped § 94 because it stayed anonymous and voluntary.
Decide
06
A retention call reads the score, and 29 CFR 1607.2(B) lists retention as a selection use.
07
Under 29 CFR 1607.4(D) the missing records can themselves evidence adverse impact.
Out
08
Consent is offered as the basis, and EDPB Guidelines 05/2020 paragraph 21 says it is not one.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
Counting, suppression and the cell record belong to the agent. Publication, and any decision taken on a finding, belongs to a named people-analytics officer.
Example workflow
One survey wave, response to publication
AgentHuman
1Responses receivedPulse tool, annual census, free-text comments, exit surveys or a collaboration graph
2Cells counted and fixedThe wave, the cell each response fell in, the minimum in force and the cuts already published
3Finding drafted, cells namedThe draft finding, the cells beneath it, the responses it may not show and confidence
4Controls appliedCell-size checks, overlapping-cut checks, language-coverage checks and drafting confidence
No human action required
Stages 1 to 4 run unaided, and nothing is published at any of them — the agent is counting, and the officer lane opens at the suppression gate.
5DecisionSplits at the suppression gate
Cell clear of the minimum
Goes to the named officer to publish.
Anything near the floor
Adds a works council read first.
Officer review
The finding is held with its cells, its response rate and the cuts it could be combined with.
Publish · Suppress · Send to works council review
Published — by the named officer▼
6Reporting and analytics systems updatedOnly where write access and the works agreement allow it
7Outcome evaluatedSuppression stability, response-rate movement, officer suppressions and what review found
Suppressions
Each officer suppression is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Publishing a finding to line managers.
Setting the minimum cell size.
Naming a team inside a readout.
Releasing an individual risk score.
Automation boundaryAgent acts unaided
✓Suppress any cell falling under the minimum in force.
✓Flag any two cuts whose overlap rebuilds a suppressed cross-section.
✓Draft the works-council description of what the platform collects.
✓Hold the finding for the officer who publishes it.
Nothing publishes and no cell opens except by the named officer, inside the agreed limits.
Judging whether a promise of anonymity still holds.
Signing the works agreement the tool runs under.
Deciding what a fall in candour means.
Changes to the cell minimum, the cuts or the wording.
Example output
One finding, annotated
This serves a people-analytics team that may have to show a works council what the platform actually touches — and Annex III point 4(b) duties, deferred to 2 December 2027, will land on the same tool; below is one finding exactly as the agent leaves it.
Finding record · single team cellIllustrative example
Finding
Counted in
Wave
Evidence held
Confidence
To be published by
Engagement index, one team cell
Below the reporting minimum, unpublished
Counted in a cell of four
Response set, one free-text batch
Held suppressed
The publishing officer, by name
As receivedDrawn from the survey platform and the wave record, and it says nothing about anyone the cell could name.
What the record holdsWave and cellResponse rateFree-text batch
Why nothing publishes hereSaying a cell is safe to publish is a call the named officer makes.
ActionPublishSuppressSend to works council review
What the score decidesBelow the configured floor a finding picks up a works council read before the officer.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every responseFrom the wave it was answered in
03The cell
Where a score becomes a decision
Under 29 CFR 1607.16(Q) your flight-risk score is a selection procedure, and 1607.2(B) lists retention; 1607.15 wanted the impact records from the first score.
01Approved path
We said it was anonymous
A minimum cell size of five protects one cross-section; you are selling trends and drill-downs, which are many overlapping cross-sections.
02Human review
What was looked for, and not found
A full-text search of the Code of Federal Regulations returns nothing for sentiment analysis, employee attrition or pulse survey, while adverse impact and collective bargaining both return hits on the same index, and no independent validation of individual attrition prediction was found.
04Build an evidence trail
The response, the group it was counted in and the officer who published it stay together.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Integration availability depends on the client's existing systems and API access.
Agent controls
Six sieves between the model and the readout
Six filters along one train, the last the tightest. What survives is set out in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to counting responses when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and suppression rules, and note the version each finding was drafted under.Track
L4TraceabilityRecord the wave, the cell counted and each read of the finding; the impression-of-surveillance doctrine under 29 U.S.C. 158(a)(1) outlived the rescission of GC 23-02.Record
L3Publication releaseHold the finding for the named officer; in Conseil d'État n° 492830 the monitoring survived, and the retention, the notice and the access control did not.Gate
L2Surface guardrailsRefuse a surface the works agreement never named. The device in 1 ABR 16/23 could not record anything, and co-determination attached anyway.Restrict
L1Confidence thresholdsRoute a finding near the floor to a works council read, and refuse voice and video under Article 5(1)(f).Require review
Model coreFinding drafted — the wave, the cells counted, the rate that answered and what was suppressed
L1 – L2Test whether a finding may publish
L3Leaves the publication to a named officer
L4 – L5Keep the finding and the cell size behind it
L6Suppresses the cell and reports nothing when signals degrade
How Nestack evaluates it
Evaluate the whole measurement — not only the score that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the score a leadership readout carries
Depth of coverage ▼
E1Final-output evaluationDid the finding record the cell it rests on and the rate that answered it?
E2Step-level evaluationDid the agent read the right wave, the right roster and the live cell minimum?
E3Tool evaluationDid it read and write the correct wave and the correct cell?
E4Confidence calibrationDo low-confidence findings actually attract more officer suppressions?
E5Slice evaluationHow does performance change across specific populations?
E6Business outcomeHow many findings were suppressed before the officer published?
Floor — what people will tell their employer
Failure modes
Where each failure originates in the agent
Seven failure modes, each set at the stage where it first shows itself.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
VJ-03
Respondent mix never gathered
Who answered, and how many, is not carried.
Stage gathersThe wave, the roster, the cells and the rate
02 · Reasoning2 modes
VJ-04
Sarcasm scored as contentment
A bitter comment is counted as a warm one.
VJ-06
Language read as a mood
A region lights up because it does not write in English.
Stage proposesThe cells counted, the cuts they allow and confidence
03 · Tool / write2 modes
VJ-02
Live with no works agreement
The platform runs before anybody signed for it.
VJ-05
Risk score decides a retention call
A score becomes the basis of an employment decision.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
VJ-01
Published, and the writer is named
A manager recovers one person from the readout.
Stage returnsThe score a readout carries and a board reads
05 · Change / Version1 mode
VJ-07
Connector widens, notice does not
A release note adds a surface nobody notified.
Stage tracksModel, prompt, cell minimums and cut rules
Sev-1 · a person named from a published cellSev-2 · a cell publishes below the minimumSev-3 · signal degrades, finding held back
A population-level suppression figure can read clean while teams near the reporting floor carry most of the suppressing. Nestack reports the suppression rate by population, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Small teams near the floor
8.3%
3.7×
Review
Non-English comment sets
5.9%
2.6×
Review
Attrition-risk cohorts
3.7%
1.7×
Watch
Large business units
1.7%
0.8×
Normal
Bar: suppression-rate lift vs. large-business-unit baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a nameable cell costs
A cycle shuts when the team small enough to name is a standing case. That suite is what the next survey wave is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Suppression rate rises on teams near the reporting floor.
02Diagnose
The readout that let a manager work out who wrote the comment is worked backwards until one cause is left standing.
03Improve
Findings go out numbered, and the cell sizes beneath them ride with it.
04Verify
Each touched suppression case is run again, and one red holds it back.
05Learn
The case is kept, and the reporting rules change in that same commit.
Learn → DetectThe return edge. The next finding is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, suppression logic, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Suppression rules and the automation-boundary work.
02Survey, roster and collaboration sources.
03Response-set and collaboration-graph source mapping.
04Survey response capture.
05Cell binding and suppression logic.
06Confidence scoring and council routing.
07Officer publication workflow.
08Reporting-system integration.
09Suppression and basis cases.
10Guardrails and publication controls.
11Response-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne wave, one populationProductionProduction reporting workflowAdvancedMultiple waves / jurisdictions
Introduced at Pilot
Suppression to your cell minimums✓✓✓
Named officer publication✓✓✓
Population-and-cell baseline✓✓✓
Introduced at Production
Reporting by population class—✓✓
Officer publication review in your systems—✓✓
Approved write-back—✓✓
Survey-and-directory integration—✓✓
Introduced at Advanced
Multi-country works agreements——✓
Layered publication sign-off——✓
Large response volumes——✓
Multi-country consultation controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, population coverage, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your live survey waves and the officer each one names→Response capture and cell countingWeek 1
02Representative past waves and how each was reported→Roster binding, suppression logic and the population baselineWeek 2
03Your reporting calendar and the councils it consults→Cell-minimum mapping, roster binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Survey, roster and collaboration-source assessment, then integration setupWeek 2
05Findings you would not want re-identified→Suppression cases and the evaluation roundWeek 4
06What no finding may reveal→Confidence scoring, council routing, guardrails and release controlsWeek 3
07A named officer who publishes the finding→Release to the named officer, then pilot waves and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
These bands are counted, not spaced for appearance; the fifth week carries two because they coincide.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Wave discovery, cell-minimum mapping and the automation boundaryW2Survey and roster integration and the population baselineW3Suppression logic, overlapping-cut checks and release controlsW4Evaluation suite, suppression cases and failure-mode testingW5Reporting-system integration, pilot findings and targeted correctionsW6One survey wave run under the people-analytics lead, then Agent Care handover
Reading the bandA band covers only the weeks its own work is named for, and the fifth week doubles on purpose.
At the end of W6When the response record validates, Agent Care adopts the agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · HR AI agent
Build an engagement insights agent around the promise you made when you asked.
Show us one survey wave and the readout that went to managers. If a team of eight was reported quarter after quarter and sliced two ways, the anonymity you promised was gone before anyone lied about it. Ask what cell each number was counted in.