A confidential exit interview needs a precise promise: who may see the source, what others receive, how small groups are handled, when information may be escalated, and when records are deleted. Explain those limits before participation. Do not use “anonymous” when context can identify the speaker.
Define three terms before writing the invitation
Teams often use confidential, anonymous, and deidentified as if they mean the same thing. They do not.
- Confidential means identifiable information is available only to specified people and used under stated rules.
- Anonymous means the organization cannot identify the participant from the data it holds. That is difficult in an exit process because the employer already knows who left.
- Deidentified means direct identifiers have been removed or separated. Reidentification may still be possible from role, dates, location, events, or wording.
Choose the term that matches the actual process. If HR can open a named transcript, call the interview confidential and explain that access. If leaders receive only grouped themes but an administrator retains source records, say so. A reporting threshold can reduce disclosure risk without making the source anonymous.
Acas says exit interviews can help an employer understand why someone is leaving, inform recruitment and retention, identify possible exclusion, arrange handover, and consider changes. See Acas guidance on responding to a resignation. Those purposes are broad enough to require a deliberate boundary. Decide which ones this program serves before collecting responses.
Use a notice people can understand
Give the notice before the employee decides whether to participate. Keep the invitation short, with a link to the full information. A practical notice answers:
| Question | Decision to state |
|---|---|
| Why are we asking? | The specific improvement or review purpose |
| Is participation voluntary? | Whether questions can be skipped and what happens if the person declines |
| What is collected? | Answers, transcript or recording, metadata, role and cohort fields |
| Who sees the source? | Named roles, vendor support access, and exceptional access |
| What do managers receive? | Raw material, reviewed extracts, or aggregate themes |
| How are small groups handled? | Thresholds, suppressed filters, delayed or combined reporting |
| What are the limits? | Circumstances that may require escalation or disclosure |
| How long is it kept? | Retention period for each record type and backups |
| What can the employee do? | Applicable rights and a contact for questions |
The UK's Information Commissioner's Office says employers should explain the purpose, lawful basis, retention periods, recipients, rights, and other uses of worker information. It also says records should be handled fairly, lawfully, transparently, and limited to justified purposes. See the ICO employment records guidance.
Local privacy and employment requirements vary. Have the appropriate internal advisers approve the notice and the operating process for each jurisdiction. A vendor statement does not replace the employer's own decision.
Build an access matrix around the purpose
Start from the least access each role needs. Test the implemented system rather than relying only on a policy document.
| Role | Typical need | Possible view | Control to verify |
|---|---|---|---|
| Program administrator | Run invitations and resolve access issues | Status and limited metadata | Separate content and administration permissions |
| Authorized analyst | Review and code feedback | Source material for approved population | Named access, logging, periodic review |
| HR leader | Decide cross-team action | Reviewed themes with denominators | Small-group suppression and source links restricted |
| Manager | Improve a local practice | Manager brief with context and action request | No raw response access by default |
| Executive | Allocate resources | Organization-level themes and decision log | No identifying filters or searchable quotations |
| Vendor support | Resolve a technical issue | No content unless time-bound access is approved | Approval, logging, expiry, and review |
Try common ways the design can fail. Search a distinctive phrase. Combine team, location, tenure, and departure date. Open a notification email. Download a report. Change a filter after a chart loads. Inspect whether exports, audit logs, backups, and support tools follow the same access rules as the dashboard.
Treat small groups as identifiable until reviewed
Suppose a five-person maintenance planning team has one departure this month. The employee describes a cancelled schedule change and uses a phrase colleagues heard in the meeting. Removing the name does not hide the speaker. Grouping the comment under “work planning” may still be enough to identify the person.
A safer review might:
- combine the theme with a broader eligible cohort;
- delay reporting until the cohort is large enough;
- paraphrase only after checking that detail remains useful;
- remove a distinctive event that is not needed for the decision;
- route a serious allegation through the approved case process instead of a general report;
- record why the chosen audience needs the remaining detail.
Do not turn a minimum group size into an anonymity promise. Even a larger group can be identifiable when only one person experienced the event. Denominators and missing answers also matter: five eligible people are not five participants, and five participants may not all answer a question.
Separate feedback reporting from case handling
An exit conversation may contain a report about discrimination, harassment, health, safety, fraud, or another serious matter. A blanket promise that nothing will be shared may conflict with an employer's responsibilities or its stated process.
Design the route before launch:
- define which disclosures need review;
- show the participant the limits in plain language;
- identify the role allowed to receive the source;
- prevent a general manager report from becoming the case channel;
- record the handoff and access decision;
- explain follow-up where appropriate and permitted;
- keep case records under their applicable rules.
Automated classification can miss context or flag an ordinary statement. Use it to support an authorized reviewer, not to make the final escalation decision by itself. The AI exit interview test guide includes sensitive-disclosure cases for a pilot.
Report themes without overstating them
Confidential handling should still produce useful decisions. A report can state:
- the eligible, participating, and answering populations;
- the question and period covered;
- recurring themes linked to reviewed evidence;
- meaningful disagreements or exceptions;
- material missingness;
- disclosure controls applied;
- the owner, action, and review date.
Avoid reproducing vivid quotations merely because they sound persuasive. A paraphrase can still identify someone. Avoid claims such as “employees leave because of manager communication” when the evidence is a small, self-selected set of accounts. Write what respondents described and what the organization will examine next.
The exit interview analysis framework provides a codebook, cohort checks, and decision log for this work.
Keep only records the process needs
Map every record from collection to deletion: invitation status, contact details, consent or notice version, audio if any, transcript, response, code, summary, reviewer correction, access log, action, and backup. Give each a purpose, owner, access group, and retention rule.
Ask whether audio must be retained after a transcript is checked. Decide whether a quotation is needed once a theme is coded. Remove old administrator access when responsibilities change. Test deletion in the primary system, exports, and backups according to the approved schedule.
The objective is to retain the minimum record needed for the stated purpose, accountability, and applicable obligations.
Use a launch checklist
Before inviting participants, confirm:
- purpose and population are approved;
- the invitation and full notice match the system;
- voluntary participation and question skipping are clear;
- source access has been tested role by role;
- small-group rules cover filters, search, exports, and notifications;
- the exceptional-disclosure route has an owner and response procedure;
- analysts know how to paraphrase and preserve uncertainty;
- managers know what they will receive and how to act on it;
- retention and deletion have named owners;
- employees have a contact for questions or rights requests;
- the program has a review date and stop condition.
Recheck the notice whenever the purpose, model, vendor, integration, report audience, or retention practice changes. Trust depends on the practice matching the promise over time.
Where Lontra may fit
Lontra is an employee conversation platform, not an anonymous reporting channel, case-management system, or dedicated exit-management suite. A team can use one focused campaign, up to 30 invitations over 60 days with no credit card, to evaluate the conversation and reporting experience.
Review the current platform capabilities, then use the launch checklist to test contextual identification, administrator access, escalation, retention, and the reporting experience. In Lontra's current public model, managers receive a brief rather than raw employee responses. Aggregate HR views use a minimum of five respondents. That threshold is a reporting control and does not guarantee anonymity. Verify any required export or integration separately.


