Koé, rebuilt: anonymous feedback that survives the AI era

In 2015 we built Koé so employees could say true things safely. In 2026 the same product would be malpractice — because the thing that makes feedback synthesizable now is the same thing that makes anonymity fragile. This is the rebuild that takes both seriously.
01What we built then — and where it strained
Koé 1.0 let people send work issues anonymously from a phone to a dashboard. The design work was classic for its moment: mental models, flows, wireframes, an interface gentle enough that raising a problem didn’t feel like filing a complaint. The strain was structural, not visual: leadership received raw anonymous messages — unreadable at volume, impossible to prioritize, and quietly identifying, because people write like themselves. Trust eroded from both directions.
02What a decade changed
Two opposing facts define the 2026 version. AI can now do what no dashboard could — synthesize hundreds of raw notes into a handful of faithful themes. And AI can also do what no manager could — deanonymize an “anonymous” note from its writing style alone, in seconds. Any 2026 rebuild that only exploits the first fact while ignoring the second is a trust product that destroys trust.
03The three design decisions
K-anonymity is a UI primitive, not a policy line. No theme becomes visible to leadership until at least five distinct voices have joined it. The threshold isn’t buried in terms of service — it’s rendered: employees watch their note “held — 3 of 5 voices” and understand the protection because they can see it working.
AI paraphrases; nothing is ever quoted. Leadership sees themes with strength, breadth, and trend — “seven voices across three teams, rising” — expressed in generated language that carries the meaning and strips the stylometry. Provenance without identity.
The submitter confirms what the machine understood. Before a note joins anything, the employee sees exactly what leadership would see: which theme it joins, how it will be expressed, when it becomes visible. Confirm or cancel. It’s the same discipline as my enterprise AI work — models interpret, interfaces verify, humans confirm — applied to the most fragile data there is: an employee telling the truth.
04The tension
Paraphrase costs fidelity — sometimes the exact words ARE the signal, and a template of the pain is not the pain. The concept carries one declared carve-out: content suggesting safety issues or legal duties doesn’t enter the anonymous pool at all; it routes to a disclosed, separate channel, and the product says so up front. A trust product earns more by naming its limits than by pretending it has none.
Try both sides of it
Raise an issue as an employee, confirm what the machine understood, then switch chairs and see what leadership actually gets.
Your note joins the theme and will be expressed as:
Themes appear only at five or more voices. Below that, leadership sees that something is held — never what, never who.
The working notes
Why each rule exists, and what it costs.
MethodK-anonymity rendered, not promised
The threshold of five isn’t magic — it’s the smallest number where “which of them said it” stops being guessable in a normal team. What matters is that the gate is visible on both sides: employees watch their protection accumulate; leadership sees held themes as sealed, which itself is information (“something is building”) without exposure.
EvidenceStylometry is the quiet killer
Writing style identifies authors with uncomfortable accuracy, and modern models made that a commodity capability. Any product that forwards raw anonymous text is anonymous in name only. Paraphrase-only isn’t a nice-to-have in 2026 — it’s the minimum viable trust architecture for the category.
ConstraintConcept-study rules
The 2015 project was real; the client no longer exists, which is why it can be shown. Everything 2026 on this page is design reasoning, clearly labeled — the prototype simulates the model with rules, sends nothing anywhere, and says so on its face. A concept that cosplays as a shipped product would break this site’s evidence rules.
LessonThe confirm step is the product
The novel interaction isn’t the synthesis — it’s the moment before sending, when the submitter sees their meaning in the machine’s words and decides whether it survived. That single screen is where trust is manufactured: interpretation made visible, consent made real. It’s the confirm-what-you-see pattern doing its most delicate job.
Compas: planning that shows its consequences →
Meet Koé as an employee would ↗ Simulated product site — built as part of this case study.