2. Information architecture
Four surfaces. Three audiences. One hard rule: the surface a person can reach is determined by role and tenant scope, not by navigation. A client viewer cannot type their way into Firm HQ. A contractor cannot see an engagement they are not staffed on.
| Surface | Audience | Brand shown | Data shown |
|---|---|---|---|
| Firm HQ | Firm users (Partner, Practice Lead, EM, Analyst, Contractor-scoped, Firm Admin) | Firm | Cross-client, aggregated; methodology IP |
| Engagement Workspace | Firm users staffed on the engagement | Firm (+ client co-brand in previews) | One client; k-safe aggregates; identifiable data only with audited permission |
| Respondent | Client employees | Firm, optional co-brand | Their own responses only |
| Client Portal | Client Sponsor, Client Admin, Client Viewer, Client Manager | Firm, optional co-brand | Published Insight Objects, k-safe aggregates, actions. No microdata. |
The vendor name appears only on Firm HQ login, billing, and the legal footer of firm-facing pages.
2.1 Firm HQ
Firm HQ
├── Home
│ ├── Portfolio pulse active waves, completion risk, readouts due in 14 days
│ ├── Approvals queue Insight Objects awaiting partner sign-off, pack reviews
│ └── Drift alerts clients where a former strength is sliding
├── Engagements
│ ├── Pipeline proposed → contracted → fielding → analysis → readout → retainer
│ ├── All engagements filter by practice, partner, package, stage, client
│ └── New engagement package → client → pack → team → dates
├── Clients
│ ├── Client list longitudinal index trend per client
│ └── Client record engagements, waves, contract flags (book opt-in, AI opt-in, residency)
├── Methodology Studio
│ ├── Packs draft / in review / locked / retired
│ ├── Pack editor framework canvas, items, scoring, bands, interpretations, recommendations
│ ├── Version diff item, weight, band, and copy changes between versions
│ └── Peer review reviewer assignments, comments, sign-off
├── Library
│ ├── Item bank tagged items, forks, validation status, translations
│ ├── Open-end and probe bank
│ ├── Video prompt bank
│ ├── Interview guides exec / middle / frontline, coding scheme per pack
│ ├── Recommendation library moves mapped to bands and service catalog
│ ├── Pattern library approved finding language harvested from past engagements
│ └── Launch kit templates sponsor email, FAQ, poster, manager talking points, works-council pack
├── Benchmarks
│ ├── Book of business norm sets, contributing clients, eligibility rules
│ ├── External references licensed / published sets, "indicative" labels, expiry
│ └── Norm builder filters: industry, size, region, growth stage, union, deskless share
├── Offerings
│ ├── Packages Rapid / Full Census / Transformation Pulse / Portfolio
│ └── Service catalog sellable modules linked from recommendations
├── People
│ ├── Consultants roles, practices, staffing, utilization by phase
│ └── Contractors engagement-scoped access, expiry dates
├── Brand
│ ├── Firm brand kit logo, type, palette, email domain, custom domain
│ └── Templates PPT master(s), PDF leave-behind, Excel appendix
└── Admin
├── Security SSO/SAML, SCIM, MFA, session policy, IP allow-list
├── Data policy residency default, retention, AI processing opt-in (firm level)
├── Integrations HRIS, comms, storage, CRM
├── Audit log identifiable-data access, exports, permission changes
└── Billing seats, engagement credits, completes, video minutes
2.2 Engagement Workspace
One client, one engagement. A retainer is an engagement with many waves.
Engagement: <Client> · <Package> · <Wave>
├── Overview
│ ├── Plan milestones, steering dates, team, status
│ ├── Scope pack + version, modules, population, languages, anonymity mode
│ └── Case file all evidence types in one index
├── Setup
│ ├── Client brand co-brand toggle, subdomain, sender identity
│ ├── Population import (CSV / HRIS), hygiene report, leavers, duplicates
│ ├── Hierarchy tree editor, spans & layers, attribute mapping
│ ├── Anonymity k, text k, works-council mode, manager visibility rules
│ ├── Cell-size simulator reportable cuts at expected response rates
│ ├── Instruments census / short form / frontline / 360 / interview guides
│ ├── Languages translation status, human review queue
│ └── Consent & legal privacy notice, video consent, DPIA checklist, works-council packet
├── Launch Command
│ ├── Comms sequencer channel × audience × date
│ ├── Champions named coordinators, their completion-only view
│ ├── Live fieldwork completion by unit, channel, language, device; drop-off item
│ └── Nudge rules unit-level, anonymity-respecting
├── Evidence
│ ├── Responses aggregate only by default
│ ├── Text themes, quote book, provenance
│ ├── Video clips, transcripts, reel builder, consent tier
│ ├── Interviews notes, transcripts, coding
│ ├── Documents strategy decks, org charts, prior surveys, coded excerpts
│ └── Structure spans, layers, cost bands (when present)
├── Analysis
│ ├── Scoreboard index → dimension → practice
│ ├── Heatmap unit × dimension / practice
│ ├── Drivers relative importance for this client
│ ├── Contradiction radar method disagreement
│ ├── Wave compare locked items, mapped hierarchy
│ └── Workbench filters, significance, effect size, outliers, saved cuts
├── Insights
│ ├── Insight board draft → reviewed → partner-approved
│ ├── Spine builder order 5–7 findings into the narrative
│ └── Recommendations moves from the pack; service-catalog links
├── Diagnostic Room live steering-committee mode
├── Deliverables
│ ├── Deck export firm PPT master
│ ├── PDF leave-behind
│ ├── Excel appendix k-safe tables, method, item text
│ ├── Clip reel consent-cleared only
│ └── Manager packs per-unit, k-safe, team actions only
├── Actions
│ ├── Initiatives owner, due date, leading indicator, linked items
│ └── Next-wave design auto-highlights linked items
└── Settings
├── Team firm users and roles on this engagement
├── Client users sponsor, admin, viewers, managers
├── Retention video / text / microdata clocks, purge
└── Audit engagement-scoped log
2.3 Respondent
Mobile-first. Firm-branded. No account. One screen, one decision.
Respondent
├── Entry magic link / SSO / QR / kiosk code / SMS / WhatsApp
├── Welcome who is asking, why, how long, what happens to answers
├── Privacy "Your manager will never see your individual answers." k rule in one line
├── Language picker remembered per device
├── Core instrument blocks of 5–8 items; progress by block, not by item
├── Open-ends prompted, routed probes; voice-to-text on mobile
├── Video (optional) separate consent, practice take, re-record, skip without penalty
├── Demographics only what is not already in the hierarchy file
├── Review & submit
├── Done what happens next, date of results share-back
└── Save & resume token-scoped, 14-day expiry
360 raters see a variant: ratee name, relationship, rater-group anonymity rule (e.g., "Peer ratings are shown only when 3 or more peers respond").
2.4 Client Portal
Read-scoped. Only partner-approved Insight Objects and k-safe aggregates.
Client Portal
├── Summary the spine: 5–7 findings, each expandable to evidence
├── Scores index, dimensions, practices; vs last wave; vs book (labeled)
├── My area (managers) k-safe team view, if unit clears k; otherwise rolled up with an explanation
├── Wave compare
├── Actions initiatives, owners, status, linked items
├── Documents deck, PDF, appendix
└── Share-back kit all-staff summary, manager talking points
2.5 Role × surface matrix
| Role | Firm HQ | Engagement Workspace | Identifiable data | Client Portal |
|---|---|---|---|---|
| Firm Admin | Full | Settings only unless staffed | Never by default | No |
| Partner / Practice Lead | Full | Staffed engagements; approve insights | With purpose + audit | Preview as client |
| Engagement Manager | Pipeline, library (read), benchmarks | Full on staffed | With purpose + audit | Preview |
| Analyst | Library (read), benchmarks | Setup, evidence, analysis, insights (draft) | Only if granted per engagement | Preview |
| Contractor | None beyond own profile | Named engagements only; expiry date | Never | No |
| Client Sponsor | No | No | Never | Full |
| Client Admin | No | Population upload, comms review | Never | Full |
| Client Viewer | No | No | Never | Read published |
| Client Manager | No | No | Never | Own k-safe area |
"Identifiable" means row-level responses joined to person attributes. Access requires a stated purpose, is time-boxed (default 24h), and is written to the audit log with the purpose text.