Rebuilt 2015 → 2026 · Koé · Concept study

Koé, rebuilt: anonymous feedback that survives the AI era

Five ink paper planes on dashed paths converge on a gate line; past it, one large ultramarine plane continues - many voices become one protected theme.
Then2015: mobile-first anonymous workplace feedback — iOS, responsive web, a dashboard. Real project; the client later shut down.
Now2026 concept rebuild: same problem, redesigned for a world where AI can both synthesize honesty and destroy anonymity
ArtifactA working simulated prototype, on this page — not screenshots
HonestyConcept study, clearly labeled. The 2015 facts are history; the 2026 decisions are design reasoning, not a shipped product.
The 30-second version
ProblemAnonymous workplace feedback dies two deaths: employees stop believing it’s anonymous, and leadership drowns in unreadable raw quotes. AI makes both worse AND both solvable.
DecisionThree rules: no theme surfaces below five voices (k-anonymity as a UI primitive) · AI paraphrases, never quotes (writing style identifies people) · the submitter confirms their meaning survived before anything sends.
OutcomeA working prototype below — try both sides of it. Concept study; the 2015 original was real and the client is gone, which is why this can be shown at all.

In 2015 we built Koé so employees could say true things safely. In 2026 the same product would be malpractice — because the thing that makes feedback synthesizable now is the same thing that makes anonymity fragile. This is the rebuild that takes both seriously.

01What we built then — and where it strained

Koé 1.0 let people send work issues anonymously from a phone to a dashboard. The design work was classic for its moment: mental models, flows, wireframes, an interface gentle enough that raising a problem didn’t feel like filing a complaint. The strain was structural, not visual: leadership received raw anonymous messages — unreadable at volume, impossible to prioritize, and quietly identifying, because people write like themselves. Trust eroded from both directions.

02What a decade changed

Two opposing facts define the 2026 version. AI can now do what no dashboard could — synthesize hundreds of raw notes into a handful of faithful themes. And AI can also do what no manager could — deanonymize an “anonymous” note from its writing style alone, in seconds. Any 2026 rebuild that only exploits the first fact while ignoring the second is a trust product that destroys trust.

03The three design decisions

K-anonymity is a UI primitive, not a policy line. No theme becomes visible to leadership until at least five distinct voices have joined it. The threshold isn’t buried in terms of service — it’s rendered: employees watch their note “held — 3 of 5 voices” and understand the protection because they can see it working.

AI paraphrases; nothing is ever quoted. Leadership sees themes with strength, breadth, and trend — “seven voices across three teams, rising” — expressed in generated language that carries the meaning and strips the stylometry. Provenance without identity.

The submitter confirms what the machine understood. Before a note joins anything, the employee sees exactly what leadership would see: which theme it joins, how it will be expressed, when it becomes visible. Confirm or cancel. It’s the same discipline as my enterprise AI work — models interpret, interfaces verify, humans confirm — applied to the most fragile data there is: an employee telling the truth.

Anonymity you have to trust is a promise. Anonymity you can watch working is a design.

04The tension

Paraphrase costs fidelity — sometimes the exact words ARE the signal, and a template of the pain is not the pain. The concept carries one declared carve-out: content suggesting safety issues or legal duties doesn’t enter the anonymous pool at all; it routes to a disclosed, separate channel, and the product says so up front. A trust product earns more by naming its limits than by pretending it has none.

Simulated prototype — rule-based stand-in for the model · nothing leaves this page

Try both sides of it

Raise an issue as an employee, confirm what the machine understood, then switch chairs and see what leadership actually gets.

Themes appear only at five or more voices. Below that, leadership sees that something is held — never what, never who.

Deep dive

The working notes

Why each rule exists, and what it costs.

EvidenceMethodConstraintLesson
MethodK-anonymity rendered, not promised

The threshold of five isn’t magic — it’s the smallest number where “which of them said it” stops being guessable in a normal team. What matters is that the gate is visible on both sides: employees watch their protection accumulate; leadership sees held themes as sealed, which itself is information (“something is building”) without exposure.

EvidenceStylometry is the quiet killer

Writing style identifies authors with uncomfortable accuracy, and modern models made that a commodity capability. Any product that forwards raw anonymous text is anonymous in name only. Paraphrase-only isn’t a nice-to-have in 2026 — it’s the minimum viable trust architecture for the category.

ConstraintConcept-study rules

The 2015 project was real; the client no longer exists, which is why it can be shown. Everything 2026 on this page is design reasoning, clearly labeled — the prototype simulates the model with rules, sends nothing anywhere, and says so on its face. A concept that cosplays as a shipped product would break this site’s evidence rules.

LessonThe confirm step is the product

The novel interaction isn’t the synthesis — it’s the moment before sending, when the submitter sees their meaning in the machine’s words and decides whether it survived. That single screen is where trust is manufactured: interpretation made visible, consent made real. It’s the confirm-what-you-see pattern doing its most delicate job.