Public employee rating and badge
Run the six-question employee rating, publish a signed score to a public page, and put a badge on your careers site that anyone can check.
On this page
An employee rating is a short, fixed survey your team answers anonymously, published as a score on a public page with a badge for your careers site. The number comes straight from a result your workspace signs, so a candidate doesn't have to take your word for it. Use it when you want to show what working here is like, in your people's own answers, and be able to prove nobody touched them.
The page and the badge can only show what the signed result says. There's no field anywhere to type a score into, and that's the point.
When to use it
- Your careers page says good things about the culture and you'd like evidence next to the claim.
- You run an engagement pulse already and want one number from it to be public.
- You want a rating that updates every quarter or every year, with the history kept in view.
If the result is for leadership only, publish it to a public results link instead, or don't publish it at all. The rating is always public.
Before you start: signing
Every employee rating is signed by your workspace. The signature is what lets anyone check that the published numbers are the ones your team gave. Without it the badge would be a picture of a number, so a rating can't run unsigned.
Signing is set up in the browser, by an owner or admin who has unlocked your workspace encryption on that device. It takes a moment, and you're offered it the first time it's needed: when you pick the Employee rating template, or when you switch the public rating on. Anyone else who tries sees "Employee ratings are signed by your workspace. An owner or admin needs to set up signing first." and can't carry on until one of them has.
Running the rating
- Create a poll from the Employee rating template. It asks six statements on a five-point scale, from strongly disagree to strongly agree.
- Leave the questions as they are. Editing a question turns the poll back into an ordinary poll, because a rating is only comparable if everyone answered the same six. Put the wording back and it's a rating again.
- Choose the contact lists your invitations go to. That's your roster. The page shows how many people are on it and the day an admin set it. People not on the roster can't get a ballot, even if they type their email on the public page. Someone who leaves during the window stays on it, and their answer still counts.
- Open the door. Paid and trial workspaces can send invitations by email or Slack. Every plan, including Free, can hang the public page as a poster: people type their work email there and get a code. Both doors draw from the same roster, and one address gets one ballot.
- Close the poll, or let it close on its date, then publish the result from the results tab.
The six statements:
- I would recommend working here to a friend.
- My manager is someone I trust.
- I can raise a concern here without it costing me.
- I'm paid fairly for the work I do.
- My workload is manageable.
- Leadership listens when people speak up.
The first one is the headline. The score on the page and the badge is its average, to one decimal place. The page shows the other five as the share of people who agreed or strongly agreed.
A rating poll can't have a results PIN. The page is public by design, so a PIN would only lock out the people it's for.
For a rating every quarter or every year, run it as a recurring pulse series. Each wave adds a row to the page's history.
People who leave during the window
The score includes people who left while the poll was open. Dropping them from the roster after it starts would let an employer pick who counts, so a leaving date keeps them in and the page says so: "Includes people who left during the window: N were invited."
Before they go, their work inbox gets one email asking where to send the ballot. They pick an address, we send the same code that would have gone to work, and we store nothing: not the address, not a hash of it.
You can also send that ballot to an address you hold, the same way you'd send an exit survey. Their work inbox is told when that happens, with the personal address masked. We keep the address for that one send and drop it. A second send for the same person is refused.
A code that's already opened a ballot says so: "This code has already been used. If that wasn't you, someone with access to your inbox may have used it. Tell the poll's contact." The email field never says whether a code was used.
Publishing the result
Publishing works the way it does for any poll, with one difference: a rating is never published unsigned. If the browser you're in can't sign, the Publish control is switched off and says "An employee rating can't be published unsigned. Unlock encryption on this device, or publish from a device that already has."
We check the signature again before storing anything. A result that doesn't verify against your workspace's key isn't stored, so the page can't end up showing one.
A score only goes public when it means something:
- At least 20 answers, and at least a quarter of the roster. Below either, the page and the badge say there isn't enough participation yet and show no score.
- Any question with fewer than 3 answers is hidden, as on every results page.
- A result more than a year old reads as stale. The score stays visible, greyed out, with the year it was last published.
Turning on the public page
The public page and badge live in Workspace settings, in the Public employee rating card. Owners and admins can change them.
- Switch on Show a public rating. If signing isn't set up yet, you're offered it here first.
- Check the address. It starts as a version of your workspace name, as in
invizipoll.com/rated/your-company. Change it and click Save address.- Choose what feeds the page. Pick the rating poll or the series it belongs to. Only rating polls from your workspace are listed.
- Copy the badge snippet and paste it into your careers page.
Changing the address later breaks every badge and link that uses the old one, and the old address is freed straight away. You're asked to confirm before it changes.
Switching the rating off takes the page down. The address stops showing anything about you, and it looks the same as an address that was never used.
The badge
The snippet is a plain image inside a plain link to your page. There's no script. The image's alt text is filled in for you and matches what the badge says, so screen readers and search engines get the same claim a sighted visitor does.
The badge reads the latest published result and shows one of five things:
- The score, with "Rated by employees" and "as of" the month, when the result verifies.
- "Not enough participation yet", with no score.
- "Unverified", with no score, if the signature doesn't check out.
- The score in grey, with "last published" and the year, when the result is more than a year old.
- "Coming soon", when nothing has been published yet.
While a new wave is collecting answers, the badge keeps showing the last published result. On a dark background, add ?theme=dark to the end of the image address in the snippet.
The badge is checked on our server with the same rules the page uses in the visitor's browser, so the two can't disagree. It refreshes within about an hour of a publish. If something goes wrong on our side, the badge shows a plain "Employee rating" with no verdict, never "unverified" for a fault that isn't yours.
Hanging the poster
The public page is the poster. Print the address, put it on a slide, or share it in a channel. An employee opens it on a device of their choosing, types their work email, and we send a code to that inbox.
The email carries the code in two groups of four, and the page address as plain text. It has no button and no link that would open a ballot. A link in the inbox would open on whatever is reading mail, often a work laptop. A code lets them stay on the page they already opened, on their own phone, and type it there.
There's no QR in the email, and no QR anywhere carries a code. Screens get recorded, so a code inside a picture is one screenshot away from someone else's ballot. On a computer, the page shows a QR of its own address instead: scan it with a phone, and type the code there.
If a lot of people ask for codes at once from the same office network, the page says so and asks them to try again in a few minutes. It never tells someone a code is coming when it isn't.
A pushed invitation for a rating poll carries the same code beside the link, so people who already got an invite never need to claim. If they do claim anyway, they get that same unused ballot, not a second one. A code that's already opened a ballot says so, and on the device that opened it, typing the code again takes them straight back to that ballot. Typing an email never says whether a code was used.
The employer's mail server can see that a code email arrived. That's a person deciding to take part, about then. It can't be joined to an answer: responses carry no timestamps and no link to a ballot. Ask people to request the code when they see the poster and to answer later, on their own phone.
What respondents see
While the poll is open, the public page says so and offers a work-email field and a code field. That's the door for anyone who wasn't sent an invitation, and for anyone who wants to answer on a different device than the one that got the mail.
Once someone opens their ballot, it's saved on that device until they submit or the poll closes, so a reload or a dropped connection doesn't cost them their vote. It's saved locked with their code. Reloading the same tab picks up where they left off, but a new window asks for the code first, so on a shared computer the next person can't finish someone else's ballot.
It also gives the same advice as our guide to staying anonymous, and it's worth repeating in your own announcement:
- Answer on a personal device, on a personal network. A work laptop on the office network logs what was opened and when. The page puts it as "Answer on your own phone if you can. The code works until the poll closes, so there's no need to answer right now."
- Don't be the first or the only. Answering within a minute of the invitation, or at 2am, can make someone findable by timing alone.
Once a result is published, the page shows the score, the share who'd recommend working here, how many answered, how many are on the roster, and the participation rate. If anyone left during the window, a line names how many were invited. Under the numbers, a line says whether the signature checks out. Earlier waves are listed newest first, including any that were withdrawn, with the date.
The page shows aggregates only. It never shows written answers, per-person data, cuts by team, or anything else a roster attribute could narrow down.
Signing, in plain words
When you publish, your browser signs the result with your workspace's private key. The page and the badge check that signature against your workspace's public key, which anyone can download from the page. If a single number was changed after you published, the check fails and both surfaces say so.
We never hold the private key. It stays wrapped under your workspace encryption, so neither we nor anyone else can publish a rating in your name.
Keys can change. In Workspace settings, the Signing key card shows the key in use, when it was set up, and its history. Replace it whenever you like: results you've already published keep verifying, and new ones are signed with the new key. If you think a key has leaked, report it compromised instead. Every result it signed then shows as unverified until you republish it, and the card lists which polls those are before you confirm.
For the full check, step by step, see Verifying a published results document.
Limits and gates
- Every plan, including Free, can run a rating, publish the page, use the badge, and let people claim a ballot from the public page.
- Email and Slack invites for a rating poll need a paid plan or an active trial. Free workspaces hang the poster instead. Ordinary (non-rating) polls are unchanged.
- Free: a roster of up to 50 people, and one rating published per calendar quarter. Republishing that same rating is always fine.
- Trial: a roster of up to 2,000 people, and no quarterly limit. Trials can still send rating-poll invites.
- Paid plans: no quarterly limit, and the roster can be as large as your plan's per-poll recipient limit.
- A rating needs a workspace signing key and a browser that can sign. It can't have a results PIN.
- A rating's result carries no cuts, cohorts or written answers. Publishing one that does is refused.