Written by Brandon Bibbins. Reviewed and updated September 1, 2026.
An anonymity threshold is the smallest number of responses a vendor will report on before showing a result. Published minimums in this category range from one to ten depending on the product and the program type, and several of them are defaults an administrator can move rather than floors the product enforces. Read the number, then read the three conditions that always travel with it: which program types it covers, who can change it, and what the tool does when a group falls below it.
A number on its own promises nothing. A number, the program types it covers, and the name of the person who can change it is a promise you can hold someone to.
What a threshold is, and the three questions that follow it
A threshold is a suppression rule. Below it, the system withholds the result; at or above it, the system shows an aggregate. Every vendor in this category has one, and almost every published number is less absolute than it first appears, because thresholds are usually per-item, per-view, and per-program rather than global.
Three questions turn a number into something usable. First, which program types does it cover: an engagement survey, a pulse, a lifecycle survey at onboarding or exit, an always-on channel, a comments view? Several products apply different numbers to each. Second, who can change it: is it a floor the product enforces, or a default an administrator sets, and can it move down as well as up? Third, what happens below the line: is the row suppressed, is the next smallest group also hidden to prevent differencing, and is participation itself protected?
The vocabulary is worth pinning down before the vendor call, because the same word does different work at different companies. Anonymous usually means the recipient cannot identify the contributor through the system. Confidential usually means someone can, under limits. Private usually means the material stays with the person. A product can be honest and still use whichever word its own documentation defines, so ask for the definition rather than assuming yours.
- Which program types does the number cover, and which are excluded?
- Is it an enforced floor or an administrator-set default?
- Can it move down, and who authorizes that?
- What is suppressed when a group falls short, and is the next smallest group hidden too?
- Is participation itself protected, or can a manager infer who responded?
Microsoft Viva Glint publishes the fullest table
Microsoft documents two survey types, confidential and identifiable. For a survey to be confidential the minimum number of responses is three, responses are aggregated into group averages before reporting, and results are reported only when an item meets the confidentiality threshold, a number the organization chooses and which may differ for survey items versus comments. For identifiable surveys, Microsoft states that respondents can be directly or indirectly identified in reporting and gives an exit survey as the common example.
The threshold guide publishes the specific numbers. Rated Confidentiality, also called Minimum Sample Size, defaults to 5 with adjusted options of 3 or 4. Suppression, also called Minimum Group Size, defaults to 2 with options of 1 or 2. Parent Team Suppression defaults to 400. Response Rate defaults to 5 and is matched to the Rated Confidentiality setting at 3 or 4. Comments Search, also called Minimum Respondent Size for Comments, defaults to 10, and Comments Confidentiality, also called Minimum Group Size for Comments, also defaults to 10, both adjustable up or down.
The line that deserves a second reading is about identifiable programs: the minimum threshold for an ad hoc or recurring program is three, and the minimum threshold for an Employee Lifecycle or always-on survey is one. Those are different settings from Suppression, which can also be set to 1, and conflating the two produces a wrong answer in both directions. Microsoft also states that admins can only adjust survey-level reporting thresholds before a program launches its first survey and cannot change them once a program has collected response data, which is a genuine protection and a real planning constraint.
| Setting | Default | Adjustable to |
|---|---|---|
| Rated Confidentiality, also called Minimum Sample Size | 5 | 3 or 4 |
| Suppression, also called Minimum Group Size | 2 | 1 or 2 |
| Parent Team Suppression | 400 | Not stated in the guide |
| Response Rate | 5 | Matched to Rated Confidentiality at 3 or 4 |
| Comments Search, also called Minimum Respondent Size for Comments | 10 | Adjustable up or down |
| Comments Confidentiality, also called Minimum Group Size for Comments | 10 | Adjustable up or down |
| Minimum threshold, ad hoc or recurring program | 3 | Stated as a minimum |
| Minimum threshold, Employee Lifecycle or always-on survey | 1 | Stated as a minimum |
Lattice publishes a floor that only moves upward
Lattice’s anonymity article states that by default it provides aggregate results only for anonymous engagement and pulse surveys, that a minimum of three employees must answer a question for the results to be revealed, and that admins have the option to raise the anonymity threshold for each survey but it can never be less than three respondents. That is a floor rather than a default, which is a stronger commitment than most of this category publishes, and it is worth crediting as such.
Two asymmetries travel with it. Within anonymous Engagement surveys, though not Pulse, admins can optionally enable an export of all individual responses and comments with names and emails hidden, and Lattice notes that responses may still include fields such as manager or department. An admin may instead create an identifiable survey, in which responses are visible to the admin and linked to the employee’s name and identity. And the article states plainly that onboarding and exit surveys are identifiable.
None of that is hidden. All of it is published on the page a buyer would read. The practical implication is that the three-respondent floor is the documented minimum for anonymous engagement and pulse surveys specifically, and reading it as a floor across every Lattice survey type would be a misreading of the vendor’s own words.
Culture Amp publishes a habit, not a floor
Culture Amp’s survey-format guide states that results are typically reported in aggregate with a minimum reporting group size determining the number of submitted responses required before any results will be shown, and that the minimum reporting group size is usually 5, but that may vary depending on the exact circumstances. The qualification is the vendor’s own, and it means no fixed floor can be attributed to Culture Amp from its documentation. That is a documented absence rather than a hidden number.
The same guide draws a distinction a buyer should not collapse. Attributed surveys are described as the most common format used in Culture Amp, with each response linked to an employee in the account through the user profile, and Culture Amp states it prefers to communicate that its surveys are confidential. Unattributed surveys use a common link with no connection to a specific individual, and the guide notes that a genuinely anonymous survey would be unattributed with no demographic information, and that these are not the norm.
Its confidentiality guide documents a configurable reporting group minimum, described as the smallest number you can filter down to in reporting, and a separately configurable comments group minimum that counts people who took the survey rather than comments written. It documents three indirect-identification settings, None, Basic, and Strong, states that Basic is its recommended default and hides the next smallest group when a filter includes a group of one, and states that Strong hides the next smallest group whenever a filtered group falls under the reporting group minimum. It also documents a removal rule intended to prevent triangulation in leader-based reports with drill-down enabled. Every one of those is a setting a customer chooses, including None, which provides no protection from indirect identification, so the effective protection in a Culture Amp deployment is a configuration question rather than a product answer.
Leapsome publishes a default and explains the mechanism
Leapsome’s participant FAQ is unusually direct about how responses are tied together, and the directness is worth crediting. It states that when you are invited to a survey you are assigned an individual one-time token that will tie your answer to a certain ID, with which Leapsome can tie the answer to an email address, and that because answers are tied to a one-time token you cannot go back and edit them after submitting.
On thresholds, the same FAQ states that admins decide whether a survey is anonymous, that an anonymous survey requires an anonymity threshold with a default of 3 set by admins, that the threshold must be reached for each segmentation viewed, and that Leapsome will dynamically increase the threshold once more than one demographic filter is applied. The dynamic increase is a real protection against the differencing problem and few competitors publish an equivalent.
Two limits belong beside it. The default of 3 is a default an admin sets rather than a floor the product enforces, and the FAQ states no minimum below which it cannot be set. And the visibility guide states that owners of the survey and super-admins will always be able to see all results and modify visibility for other people, which is stated as unconditional. By default only survey owners can see the answers, and whether a person responded is never revealed to their manager.
The Daylogue ladder, and the sentence that goes with it
Daylogue publishes a ladder rather than a single number. The pricing page describes the Business leader dashboard as aggregate only, with themes at 5 people and averages at 10. The approved enterprise wording states it in full: employer-context dashboards are designed not to display individual entries, transcripts, scores, or participation histories, and eligible aggregate views appear only after the applicable threshold is met, where the general floor is five, averages and narrower intersections generally require ten, and some protected settings require fifteen or a higher configured floor.
The sentence that must travel with it: thresholds reduce reidentification risk; they do not make it impossible. That is published deliberately and is not a legal hedge bolted on afterward. A nine-person team where one person is the only night-shift lead does not become anonymous because five people contributed, and a program that has not thought about that case has thought only about the easy one.
Two honest notes about the ladder itself. The pricing page publishes the 5 and 10 rungs; the fifteen-or-higher rung for protected settings comes from the approved enterprise positioning rather than from the pricing page, and the two sources should not be blurred together. And averages and narrower intersections generally require ten is a qualified statement. Quoting ten as an unconditional floor for every average would overstate what is published.
| Product | Published number | The condition that travels with it |
|---|---|---|
| Microsoft Viva Glint | Confidential surveys require at least 3 responses; rated scores default to 5, adjustable to 3 or 4; comments default to 10 | Identifiable Employee Lifecycle and always-on surveys have a documented minimum threshold of 1, and ad hoc or recurring programs a minimum of 3 |
| Lattice | A minimum of 3 employees must answer for anonymous engagement and pulse results to be revealed | Admins can raise but never lower it; onboarding and exit surveys are identifiable, and an individual-response export can be enabled inside anonymous Engagement surveys |
| Culture Amp | Minimum reporting group size is usually 5 | The vendor qualifies it with "that may vary depending on the exact circumstances", and publishes no fixed floor; indirect-identification protection is a customer setting that includes None |
| Leapsome | Anonymous surveys carry an anonymity threshold with a default of 3 | It is an admin-set default rather than an enforced floor; the threshold increases dynamically once more than one demographic filter is applied |
| Daylogue | Themes at 5 people, averages at 10, some protected settings at 15 or a higher configured floor | Thresholds reduce reidentification risk; they do not make it impossible. The 15 rung comes from the enterprise positioning rather than the pricing page |
What a threshold cannot do
Suppression rules are a real control and a partial one. Public guidance on de-identification, including NIST IR 8053 and the UK Information Commissioner’s anonymisation material, is consistent on the point: removing direct identifiers and enforcing a group size reduces risk without eliminating it, because context, rarity, and repeated queries can reconstruct what a single view withholds.
Three failure modes recur in workplace reporting specifically. Differencing: running the same report with and without one filter and reading the gap. Rarity: a role, shift, location, or tenure band with a single occupant inside an otherwise large group. Free text: a comment that survives the threshold and identifies its author through detail rather than through a name.
The response is not a bigger number alone. It is a combination: suppress below the floor, hide the next smallest group when a filter isolates one, review rare roles before publishing, keep protected and safety reporting on separate routes, and re-check the configuration when a reorganization or a wave of departures changes who sits in which group. A threshold set once at launch and never revisited is a snapshot of an organization that no longer exists.
- Enforce the floor after every filter, not only on the unfiltered view.
- Hide the next smallest group when a slice isolates one person.
- Review rare roles, shifts, locations, and tenure bands before publishing.
- Treat free-text detail as identifying even when the threshold is met.
- Re-check configuration after reorganizations, layoffs, and turnover waves.
- Keep grievance, safety, and accommodation routes separate from aggregate reporting.
What to ask any vendor, in the order that gets answers
None of the vendors above is being deceptive. They publish different amounts of detail, and the gaps are gaps in publication rather than evidence of bad faith. The buyer’s job is to close those gaps in writing before signature, and the order of the questions matters because each one narrows the next.
- 1
Ask for the number and the page it lives on
A threshold you can link to is one you can quote to employees. A threshold described in a call is one that changes without telling you.
- 2
Ask which program types it covers
Engagement, pulse, lifecycle, onboarding, exit, always-on, and comments views often carry different numbers. Get the list, not the headline.
- 3
Ask who can change it, and in which direction
A floor the product enforces is a different promise from a default an administrator sets. Ask whether it can move down, and who signs off.
- 4
Ask what happens below the line
Is the row suppressed? Is the next smallest group hidden? Is the participation rate itself withheld? Ask for the behavior, not the intention.
- 5
Ask about exports
Which roles can export, what fields travel with the answers, and who authorizes enabling an export that includes individual responses.
- 6
Ask what the product is licensed to ingest
Read the product terms. The data types a SKU permits are a scope question your works council and legal team will ask about later if you do not ask now.
- 7
Ask for the prohibition in the contract
No use for hiring, promotion, evaluation, compensation, scheduling, discipline, or termination, covering derived material as well as visible text.
Saying it to the people it describes
The final test of a threshold is not whether it satisfies procurement. It is whether you can say it out loud to the people whose answers it governs, in one paragraph, without softening anything. If the paragraph needs a caveat you would rather not read aloud, the configuration is wrong, not the paragraph.
A version that passes: here is the minimum group size, here is who can change it and how you would find out, here is what is hidden when a group is too small, here is what your manager can and cannot see, here is what this is never used for, and here is the person to ask if you think a result identified someone. Every clause in that list is a fact a vendor can supply or cannot.
Daylogue is a system for self-understanding, not a coaching service or HR tool, and it is not therapy or a replacement for professional care. What a person writes stays theirs. The organization receives aggregate signal about work, at the thresholds above, with the honest caveat that thresholds reduce reidentification risk rather than removing it. That is the whole promise, and it is short enough to read at an all-hands.
Common questions
What is a good anonymity threshold for an employee survey?
There is no single correct number, and the published minimums in this category range from one to ten depending on the product and program type. What matters more than the number is whether it is an enforced floor or a movable default, which program types it covers, whether it is applied after every filter, and what the product suppresses when a group falls short.
What is the minimum group size in Microsoft Viva Glint?
Microsoft publishes several. A survey must have at least three responses to be confidential. Rated score display defaults to 5 and can be adjusted to 3 or 4. Comments thresholds default to 10. For identifiable surveys, the documented minimum threshold is three for an ad hoc or recurring program and one for an Employee Lifecycle or always-on survey.
Can a Lattice admin lower the anonymity threshold?
No. Lattice states that admins can raise the anonymity threshold for each survey but that it can never be less than three respondents, for anonymous engagement and pulse surveys. The same article states that onboarding and exit surveys are identifiable, so the three-respondent floor should not be read as covering every Lattice survey type.
Does Culture Amp publish a minimum reporting group size?
It publishes a practice rather than a floor. Culture Amp states that the minimum reporting group size is usually 5, but that it may vary depending on the exact circumstances, and its confidentiality settings, including the indirect-identification levels None, Basic, and Strong, are configured by the customer. Basic is described as the recommended default.
Are anonymous surveys really anonymous?
It depends on what the vendor means by the word, which is why the definition matters more than the label. Leapsome states that a one-time token ties an answer to an ID that Leapsome can tie to an email address. Culture Amp states it prefers the word confidential and that attributed responses are linked to an employee profile. Both are honest descriptions, and both mean something different from a survey nobody can trace.
What thresholds does Daylogue use?
Themes appear at 5 people, averages at 10, and some protected settings require fifteen or a higher configured floor. The employer view is aggregate only, and eligible aggregate views appear only after the applicable threshold is met. Thresholds reduce reidentification risk; they do not make it impossible, which is published alongside the numbers rather than after them.
Sources
- Microsoft: manage confidentiality thresholds in Viva Glint
- Microsoft: Viva Glint survey privacy
- Lattice: anonymity in engagement surveys and pulse
- Culture Amp: attributed and unattributed survey formats
- Culture Amp: confidentiality protections in reporting
- Leapsome: FAQs for survey participants
- NIST IR 8053: de-identification of personal information
- UK ICO: anonymisation, pseudonymisation and privacy enhancing technologies guidance
Keep exploring
Burnout detection without monitoring
The line between inferring a state and reading what someone chose to share.
Psychological safety and anonymous feedback
Why removing a name is one control rather than the whole trust model.
Employee wellbeing platforms compared
Nine products sorted by the job each one is built for.
Last reviewed September 1, 2026. Daylogue is not therapy and is not a replacement for professional care.
