Skip to main content

The Science Behind Sensitive Comment Management

Decide what to redact, who reviews, and how to handle urgent comments before you share.

Written by Jessie Walsh

🔐 Who can use this feature?

  • Roles: Account Administrator, Surveys Full Permissions, Survey admin

  • Survey types: Any

  • Subscriptions: Any


Sensitive Comment Management brings the comments that may need a closer look into one place, so you can decide what to do with them before you share results.

For many organizations, it's likely that very little or even nothing will need redacting. Depending on the size of your organization, reading through what has been identified should not usually take long. For larger organizations, the feature helps you prioritize which comments to review, saving you time and effort. The point of the review is the confidence it gives you.

This article covers what to agree before you launch, how to decide what each comment needs, and how to handle the most serious content.

For how to set up keywords, redact a comment, and manage the review in the platform, see Sensitive Comment Management.

What it helps you do

Reviewing open-text comments before results are shared can be time-consuming, particularly at volume. Sensitive Comment Management gives you a consistent first pass across every comment in the survey, and a shortlist to work from, so your attention goes to the comments most likely to need it.

The benefits:

  • More confidence when you share comments. Comments are often the richest part of a survey. If concerns about what might be in them have made you cautious about sharing comments, or about asking for them at all, this gives you a way to check before you do.

  • Protection for the people involved. A comment that names someone, describes a personal situation, or complains about a manager by name should reach HR before it reaches a shared report.

  • Potentially serious situations identified quickly. A comment about self-harm or a threat is easy to miss when there are thousands to read. A shortlist makes it much more likely that someone sees it.

  • Feedback is kept intact. Removing a name or some offensive wording, rather than a whole comment, leaves you the substance of the comment to act on.

Honest feedback depends on trust. People comment openly when they believe their identity is protected and their comments will be handled with care, so being clear about how comments are reviewed protects that trust.

Agree on your criteria with your legal or compliance team before you start

Whether a comment creates an obligation to investigate or act depends on what it says and where you operate. So does how you handle a disclosure of self-harm or a threat. We recommend agreeing your review criteria and escalation routes with your own legal or compliance team before your first survey. If you operate in more than one country, set them to meet the strictest requirements you are subject to.

What the feature does

Open-text comments sometimes contain things you would want to see before results go out, for example a colleague's name, swearing aimed at a manager, or a description of potential bullying.

Sensitive Comment Management brings those comments together in one place, the Sensitive comments tab in your survey report, which only your admin team can see. AI assesses each comment against Culture Amp's sensitive topic list, covered in the list below. Separately, if you have decided to add specific keywords to any of the topics, a keyword search is completed and matched against the comment text. Either of these can bring a comment into the review tab.

Importantly, nothing is changed automatically. You review the comments, decide what each one needs, and carry out any redaction yourself. Redacting means replacing part or all of a comment so the original wording no longer appears in reports. A full redaction replaces the whole comment. A partial redaction removes only the sensitive part and keeps the rest, so a comment about a named colleague can still be read as feedback about the team.

A topic is a prompt to read, not a verdict

The feature is designed to apply an abundance of caution, including a comment wherever there is doubt, so expect to see more than you need to act on.

A topic tells you what a comment might contain, not what happened. A comment under Harassment may contain a harassment risk, and it does not mean harassment has taken place. A comment under Discrimination is one where someone has described treatment they see as unfair, which may not involve a protected characteristic and does not establish that the treatment occurred. The same holds across the other topics.

Use the topics to decide which comments to read. Action may not be required beyond that.

What gets identified

Topic

What it could indicate, and what’s worth considering

Name

Anything that could identify the person who wrote the comment or the person it is about.

Worth considering: product and system names are sometimes picked up as people’s names.

Location

A place that could identify someone, such as a site or an office.

Worth considering: a location on its own is often harmless. What matters is whether it narrows the field in such a way that one or several people are identifiable.

Profanity

Swearing and other language unlikely to be acceptable at work.

Worth considering: what counts as offensive differs between organizations, so some of this may be fine in your culture.

Insult

Insults to a person or their character, including “they always” and “they are incompetent” type statements.

Worth considering: deliberately broad, so that serious insults are not missed. Expect comments here that need nothing done.

Discrimination

Unfair treatment, including favoritism or bias, based on a protected characteristic such as age, gender, ethnicity, disability, sexual orientation, religion, family status, or socio-economic status.

Worth considering: it’s important to read this as possible discrimination. Comments about potential unfair treatment can appear here with no protected characteristic involved.

Harassment

Unwanted or harmful conduct, including aggressive pressure, threats to someone’s job, belittling or degrading treatment, rudeness, intimidation, bullying, and humiliation.

Worth considering: it’s important to read this as possible harassment. Comments describing a hostile or toxic environment can also appear here.

Threat

A threat of physical harm to a person or property, or negligence that could lead to physical harm.

Worth considering: covers threats to anyone, including customers, not just employees. Exaggeration and figures of speech can be read literally. Where a threat is deemed as imminent, it needs to be treated as urgent, see Urgent comments for more detail.

Self-harm

A threat or intention to harm oneself.
Worth considering: always treat these as urgent. See Urgent comments for more detail.

Using the feature

We recommend taking some time before you launch to decide how you will approach the review. In a larger organization with several reviewers, it helps to write that approach down so everyone works the same way.

When

What you do, and who is involved

Before you launch

Agree on your review criteria, who reviews, and your escalation routes. Decide whether you want to add keywords. Set your review timeline.

Who is involved: survey or HR admin, HR lead, your legal or compliance team.

While the survey is open

Nothing needed. You can start reviewing before it closes if you want to.

Who is involved: survey or HR admin.

After it closes, before you share

Review the comments identified as sensitive, decide what needs redacting or investigating, and escalate anything urgent straight away.

Who is involved: survey or HR admin, HR, your legal team, Culture Amp Support if required for urgent cases.

After you share

Keep a record of what you redacted and why. Check a sample of comments that were not identified. Adjust keywords for next time.

Who is involved: survey or HR admin.


Before you launch

1. Agree what you will redact, investigate, or leave

Where more than one person reviews, write your criteria down and brief them, so everyone applies the same standard. Two people reading the same comment without agreed criteria can reach different decisions. You can use the list below as a starting point, and adapt it to what fits your organization:

Examples of what you might redact:

  • A name, contact details, or a role, team, or site specific enough to point to one person or a few specific people

  • An incident described in enough detail that only one person could have been involved

  • Abusive or offensive wording aimed at a named individual

  • Content that would be distressing for other people to read

Example: a partial redaction of an individual's name


Original: "The team is frustrated with Jim Brown because he keeps changing our priorities."

Redaction options:

  • "The team is frustrated with [REDACTED] because he keeps changing our priorities."

  • "The team is frustrated with our manager because he keeps changing our priorities."

  • "The team is frustrated with [manager name] because he keeps changing our priorities."

What might need investigating, on top of redaction, for example:

  • Discrimination, harassment, threats, and intent to self-harm or anything your organization would define as serious misconduct

  • These often need redacting before you share as well, so one comment can need both

What isn't usually worth redacting:

  • Profanity or blunt language that is normal in your organization and not aimed at anyone in particular

  • Strong criticism of a decision, a policy, or leadership in general, where no individual is identifiable

  • Sarcasm or exaggeration that reads worse taken literally than it was meant, such as "this process is killing me"

💡 Tip: Where you do redact, our people scientists recommend taking out as little as possible. Remove the name or the offensive wording and keep the substance, so you still have feedback you can act on. Cut a comment back until its meaning is gone and you have lost the feedback you asked for. We recommend sharing as many comments unchanged as you can, so you keep transparency high.

2. Decide who reviews

Only account admins, survey admins, and super users can see the comments identified as sensitive. If you want to split the work between several people, you can share the exported file rather than giving more people admin access to the survey.

3. Set your review timeline from the way you share results

You have probably already decided whether managers and report viewers see comments. That decision sets your deadline for the review:

  • If you share comments, we recommend you finish the review and any redaction before you share. Identified comments stay in your Comments Report until you redact them, so anything you have not dealt with becomes visible the moment you share.

  • If you share AI Comment Summaries rather than the comments themselves, we recommend you finish the review and any redaction before you generate a summary. A summary is built from the comments as they stand at that moment, so one generated beforehand is built from the unredacted comments, meaning a name or a detail could potentially appear in the summary text itself.

  • If you share summaries and comments together, treat your timeline the same as sharing comments. Report viewers given access to both can open the Representative Comments behind each summary and read up to five of them in full.

  • If you don't share comments or summaries, no sharing date sets your deadline, however we still recommend reviewing soon after your survey closes. This means you will be able to see if there are any urgent comments that need to be addressed.

4. Decide whether you want to add keywords

Sensitive Comment Management is designed to pick up most instances of sensitive content. Occasionally, however, there may be times you want to add keywords of your own to any of the topics above, to catch terms specific to your organization that we could not anticipate.

Keywords add to what the feature already picks up, rather than changing it. They match exact and similar terms (meaning that variations in spelling are caught as well), and any match comes into the review alongside the comments the feature identified.

You'll need to add your keywords before you launch, because your survey takes a snapshot of the list at launch.

ℹ️ Note: While it might be tempting to add a long list to be thorough, every keyword brings more comments into the review, so more keywords can cost you reviewing time without catching more sensitive comments. We suggest starting with the feature as designed, or with a handful of terms you're confident about, and adding more once you've seen how the feature performs on your own comments.

Examples you may want to include

Examples to leave out

Internal program, system, or site names that only your people would use

Broad concepts such as “bias,” “favoritism,” or “toxic,” which the standard topics already cover

The name of your own grievance, whistleblowing, or complaints process

Common words that turn up throughout ordinary feedback, such as “manager” or “pay”

Local terminology, including a word your organization uses for a place or for a group of people

A swear word or a slur, which Profanity and Insult already pick up

A term tied to something live in your organization, such as a restructure or a site closure

An individual’s name, which the Name topic already picks up

💡 Tip: The Sensitive Comment Management feature is tailored to surface sensitive topics, so it's best to keep any keywords you add specific to the topics listed. To explore other topics of interest, we recommend continuing to use the keyword search in the Comments Report.

5. Agree on an escalation pathway, if you need one

Agree who a reviewer contacts when a comment may need investigating, and who they contact when the duty to act is unclear where you operate.

To reach Culture Amp Support, reply with "Ask a Person" in a Support Conversation to speak with a Product Support Specialist. See Urgent comments for when that applies.

6. Decide how you will record your decisions

For every comment you redact or act on, we recommend that you record what you decided and why. The simplest approach is to work from two copies of the export: one you keep, with your notes alongside each comment, and one you upload with your redactions in it.

7. Cover comment handling in your survey communications

We recommend explaining, as part of your overall survey communications, that open-text comments may be reviewed before results are shared and that identifying or sensitive details may be removed where appropriate. A line or two in your existing communications is likely enough. For example:

"Comments may be reviewed before results are shared. Where appropriate, identifying or sensitive details may be removed to protect confidentiality and support a safe feedback process."

When you share results, if you have redacted anything, tell people that some comments were redacted, give a general reason such as protecting confidentiality or removing harmful content, and explain how a redacted comment appears, for example as [Redacted]. Doing this proactively means people aren't left to assume comments were removed to hide criticism.

While your survey is open

Comments are identified as they come in, so you can start reviewing and redacting before the survey closes if you would rather spread the work out.

After your survey closes

We recommend opening the Sensitive comments tab soon after your survey closes, rather than waiting until you are ready to share, since anything urgent is visible as soon as you look.

Review what has been identified against the criteria you agreed. A scan of the topics that have come up is often enough to tell you whether anything needs your attention, and in many cases the answer will be that no action is required. Where something does need attention, decide whether it needs redacting, investigating, or both.

For how to redact comments once you have decided, see Sensitive Comment Management.

💬 Example: a review before sharing results

A survey closes and the HR admin reviews the comments identified as sensitive before sharing results with managers. Most need nothing once read, and the admin works through them.

One names a colleague and describes their performance. The name points to one person, so it should not appear in a shared report. Another swears about a named manager. The complaint underneath it is real, but not in those words.

The admin redacts the name from the first comment and the swearing from the second, keeping the substance of both, and notes what changed and why in their own copy of the export. Then they share comments with managers.

Urgent comments

A comment indicating imminent self-harm or imminent harm to others requires immediate attention, before you continue the broader review or share comments. In these cases:

  • Follow your organization's duty-of-care process.

  • Involve your legal or privacy team where your obligations require it.

  • Contact Culture Amp Support if you need the participant's identity.

  • Record what was escalated, and when.

⚠️ Requesting a participant's identity:

The platform does not identify who wrote a comment as part of the standard review workflow, and does not show any demographic detail beyond what is already available to you.

Culture Amp discloses a participant's identity only where we are legally required to do so. If identifying the participant is necessary because of an imminent safety concern, "Ask a Person" in a Support Conversation to speak with a Product Support Specialist. They can send your request through our privacy and legal review process. Disclosure is not automatic or guaranteed.

After you share results

We recommend keeping your record of what you redacted or acted on and why.

Check a sample of the comments that were not identified, particularly in your first few survey cycles. Indirect or subtle language can be missed, and this is how you build a picture of how the feature performs on your own comments. If you see a pattern in what is being missed, it is worth letting Culture Amp Support know, since that feedback shapes how the feature improves.

Adjust your keywords for the next cycle based on what you saw, adding terms that would have helped and removing any that added noise.

Supporting the people who review

Reading through these comments can be difficult if there is content that is distressing. We recommend extending whatever support you already have for people who handle sensitive disclosures to whoever reviews comments.

Before you launch: checklist

  • Review criteria agreed and written down: what to redact, what to investigate, what to leave

  • Reviewer named, and confirmed as an account admin, survey admin, or super user

  • Escalation routes to HR and your legal team agreed

  • Culture Amp Support contact route agreed for urgent cases

  • Comment-handling policy reviewed and updated

  • Any keywords you want added, before launch

  • Review window set, with your sharing date after it

  • Reviewers briefed on what an identified comment means and does not mean

  • Survey communications explain that comments may be reviewed before results are shared

  • Somewhere set up to record your decisions

FAQ

What does the feature look for?

Comments you would want to read before results go out. That means a name or a location that could identify someone, offensive language, and more serious content like harassment, discrimination, a threat, or an intention to self-harm. The list above sets out what each topic covers. Every comment is also matched against any keywords you have added.

A comment was identified under Harassment. Does that mean harassment happened?

No. It means the comment may contain something in that area, so read it as a possible harassment risk rather than a conclusion. The feature applies an abundance of caution and errs toward bringing you a comment rather than risk missing one, which is why identification is a prompt to look and your own reading is what settles what a comment means.

Do I have to review everything before I share results?

If managers or report viewers will see comments, review before you share. Anything you have not dealt with will be visible to them the moment you share. That does not mean acting on everything: a scan of the topics that came up is often enough, and action may not be required.

If you share AI Comment Summaries instead, your exposure is lower but not gone. Summaries are written from the comments as they stand, and they do not filter out sensitive or identifying detail, so finish your review and any redaction before you generate a summary to share.

If you share neither comments nor summaries, you have more time, though the review is still how anything serious reaches you.

A lot of comments were identified. Does that mean a lot need redacting?

No, and a high number is normal. The feature would rather show you a comment than risk missing something serious, so a good proportion of what you see will need no further action beyond review. Some will use language that is unremarkable where you work. Others will have been picked up under Name for something that turns out to be a product.

Do we need to add keywords?

No. The standard topics work without them, and starting there for your first survey lets you see how the feature performs on your own comments. Keywords are useful for terms the topics could not anticipate, like an internal program name or the name of your own grievance process.

Leave out broad concepts such as "bias," which the topics already cover, and anything that will appear throughout ordinary feedback. Add them before you launch, and expect every keyword to bring more comments into the review.

Are we obliged to act on every comment that is identified?

Not automatically. Once your organization knows about a possible concern, you may have a legal or ethical obligation to look into it, and whether you do depends on what the comment says and where you operate. That obligation applies however you came to know, so this feature is not what creates it. What action is appropriate is your call. We recommend going through your comment-handling policy with your legal or compliance team before your first survey.

Does redacting a comment make it anonymous?

No. Culture Amp engagement surveys are confidential rather than anonymous, which means responses are linked to employee data so you can filter results, with reporting minimums that stop a small group being singled out.

Those protections do a different job from redaction. Reporting minimums keep someone from being identified through the filters. Redaction keeps a name or a detail written inside a comment out of your reports. Neither one disconnects the response from that person's data.

Should I tell a manager that a comment about their team was identified as sensitive?

We recommend against it. A topic describes what a comment might contain, so Discrimination means there could be a discrimination risk, not that discrimination happened. Presenting it to a manager suggests a conclusion nobody has reached, and it can make a fair process harder if the comment does turn out to need investigating.

Where a comment needs following up with a manager, use your normal HR process and talk about what the comment says.

What if a comment did not need to be identified?

Reading it and moving on is what the review is for. If the same kind of comment keeps appearing under one topic, tell Culture Amp Support, because that feedback shapes how the feature improves.

What if a sensitive comment was missed?

Contact Culture Amp Support and 'Ask a person', who can pick it up. Indirect or understated language is where misses are most likely, and a comment that was not identified will not show up in your review, so we recommend reading a sample of those comments in your first few survey cycles.

Does redacting change my topic and sentiment analysis?

Yes. A redacted comment is analyzed again, so your Topics chart reflects the new wording. Redact a lot of comments in full and the chart will shift.

➡️ Next steps


💬 Need help? Open a Support Conversation to speak with our Product Support team.

Did this answer your question?