Skip to main content
ProductWorkspace admins

Batched release and the exit pool

Why the response count can be exact while results move in threes, what held back means at close, and how to run a standing exit pool.

5 MIN READUPDATED SEP 13, 2026
On this page

The count on the ballot is every answer that landed. The charts on the results page are not. They move only when at least three more people have answered since the last time anything was shown. That is the whole product promise after the first look: no change you see is smaller than three people.

When to use it

  • Any poll that will keep collecting after the first three answers, where a one-person jump would let two colluders subtract their own answers from the next refresh.
  • An Exit pool: one standing poll for leavers, sent on a last day or hung as a QR by the interview, with no useful close date.
  • Not the always-on speak-up channel. That is a permanent inbox. This is a results poll that stays open so later answers land in the same pool.

Why the two numbers differ

Until three people have answered, results stay locked. That has always been true. After that, every extra answer used to appear the next time an admin refreshed. Decrypt at three, decrypt at four, and the fourth answer is the difference.

Release now happens in sealed batches of three, four, or five. The first batch is always three, so the "results ready" email and the employee guide stay true. Later batches are a random size in that range so two people who submit together cannot force a one-person reveal.

The quiet line under the count says so: "Showing 6 of 8 responses. The next 2 are shown once at least one more arrives." The two waiting answers are counted. They are not in the charts, the CSV, the cuts, or the published document.

What held back means

If the poll closes with one or two answers still waiting for a batch, those answers are never released. They stay in the participation count. They appear in no chart.

You will see one sentence, in the same words, on the results page, the public page, the CSV header, and the evidence packet:

"2 responses were held back to protect anonymity. They are counted in participation and shown nowhere."

The published document's n is the released set. Merging the remainder into that n would recreate the leak this page is here to close.

A closed poll cannot reopen. If you need those two answers in a later read, you run a new poll.

How to run an exit pool

The Exit pool template is a standing poll. It has no useful close date. HR sends the ballot to each leaver on their last day, or hangs a QR by the exit interview. Nothing is readable until three leavers have answered, and then only in sealed groups.

  1. Start from Exit pool. Create from the template. Leave the far-future close date as it is. This is not the always-on speak-up channel; that one is a permanent inbox. This one is a results poll that stays open so leavers can land in the same pool.
  2. Send one at a time, or a group. Last-day send is the usual path. If you need tenure or department cuts, wait until five or more leavers can be invited together.
  3. Read batches, not weeks. The results page lists sealed groups (batch 1 of 3, batch 2 of 4). A row may show the ISO week your browser first recorded that group. That is when the batch sealed in this workspace, not the week a person left. Do not try to match a batch to a departure.
  4. Publish from the released set. The public page shows the document you published, plus the held-back sentence if anything was withheld at close. Close is optional on an exit pool; most stay open.

This is not a series and not a new wave each month. A count-triggered wave would need a fresh keypair, and the server cannot mint one. One long-lived poll with batched release is the protection.

What respondents see

The ballot counter still moves by one. That is how someone checks their answer landed. It is not how the admin's charts move.

Point people at How to stay anonymous in a workplace survey. The advice not to be the first or the only person to answer still holds: encryption does not hide a submission that is findable by timing.

Limits and gates

  • The first look is still three. Later batches are three, four, or five, drawn on the server, never shown to an admin as a target.
  • A remainder of one or two at close stays withheld until purge. Nothing resumes accumulating.
  • Demo polls do not batch. Their drip is the sales story and every ciphertext past three is visible, as today.
  • Sample polls do not keep a batch history.
  • Cuts still sit behind a floor of five on the dispatched roster. One last-day send is a roster of one.