11. Risks and how the design absorbs them

Each risk is stated with the mechanism in the product that absorbs it, what remains, and the signal we watch.

11.1 The four named risks

Low response

Why it matters. Below ~50% census completion, unit-level cuts collapse under k, non-response bias becomes a legitimate executive objection, and the readout loses its best evidence.

Design response Where
Cell-size simulator before launch shows which cuts will survive at 50/60/70% response; EM merges cuts before invitations go out Setup → Cell-size simulator
Frontline form ≤ 8 min, no reverse items, voice-to-text, kiosk/QR, shift-aware send times Catalog §7.3, Launch Command
Unit-level completion map with pace-to-target and drop-off item Launch Command
Champion network with completion-only view Launch Command → Champions
Unit-level nudges that never reveal individuals Nudge rules
Post-stratification weighting with the unweighted result always shown, and a banner if they differ by > 2 pts Scoring §5.4
Method appendix states response by segment, so bias is disclosed, not hidden Deliverables

Residual. Some populations (night shift, contractors) stay under-represented. Signal: median completion by package; share of planned cuts suppressed at close.

Works council or union block

Why it matters. In the EU and unionized sites a council can delay or veto a survey. A delay moves the steering date; a veto ends the engagement.

Design response Where
Works-council mode: higher k (8–10), text-k 15, filter depth 1, no manager view until sign-off, no free-text export to client managers Anonymity policy
Auto-generated review packet: full item list in every language, anonymity rules in plain language, data flows, residency, retention, sub-processors, DPIA template Setup → Consent & legal (manual in MVP, generated in v1.1)
Frozen instrument: once the council approves version X, launch is blocked for any other version Pack lock + Wave guard
Council observer role (v1.1): read-only view of completion and published aggregates Roles
Retention and purge controls visible and demonstrable Settings → Retention

Residual. Timelines still depend on council calendars. Signal: days from packet sent to approval; share of EU engagements in works-council mode.

AI hallucination

Why it matters. One invented finding in front of a CEO costs the firm the client and the partner's trust in the tool permanently.

Design response Where
AI drafts only Insight Objects; nothing reaches a client surface without partner approval Insight spec §6.5
Evidence-first generation: model selects EvidenceRefs, then writes; numbers must bind to evidence (linter blocks unbound numbers) §6.6, §6.7
Theme model seeded by the pack's constructs; emergent themes marked and confidence-rated from human-validated samples Scoring §5.8
Every quote traceable to a source response, clip, interview, or document span Quote / Clip objects
Causal language blocked on associational evidence Linter
Interpretations are consultant-authored pack content, never regenerated Methodology Studio
Provenance (model, prompt version, input hash) stored on every AI draft Insight fields

Residual. Subtle mischaracterization of tone in a theme. Signal: share of AI-drafted insights approved without substantive rewrite (target ≥ 60%); theme-coding agreement on validation samples.

Partner skepticism

Why it matters. Partners are the buyer and the bottleneck. If they reread every comment the night before, OrgDiagnostic saved nothing.

Design response Where
"Show me the n": every number resolves to Scorecard, cut, n, CI, and method on click Diagnostic Room, exports
Deterministic, replayable scoring; golden tests; version stamps in the appendix Scoring §5.12
Partner voice preserved: approved text frozen; interpretations authored by the firm Insight spec, Studio
Export to the firm's own PPT master, so the deck looks like the firm, not the tool Deliverables
8-minute spine tested in design-partner sessions Diagnostic Room
Quote book organized by construct and segment, so rereading is fast when a partner still wants to Evidence → Text

Residual. Some partners will never use the room and only want the deck. That is fine. Signal: % readouts delivered from room or unmodified export; partner NPS by firm.

11.2 Additional risks

Risk Design response Signal
A client identifies a commenter k and text-k, complementary and differencing suppression, PII redaction including role-unique titles, quote permission tiers, video consent tiers Anonymity incidents (target 0); redaction miss rate on audits
Cross-client data leak Schema-per-workspace, per-workspace keys, RLS, contractor expiry, no cross-workspace query path, hash-chained audit Pen-test findings; audit anomalies
Org changes break longitudinal claims Hierarchy mapping between waves; mapping-coverage banner; composition check Mapping coverage per wave-2
Junior analyst over-claims Significance + effect size + FDR on by default; "meaningful" threshold; borderline band rule; "indicative" stamp on external norms Linter waivers per engagement
Firm treats shipped pack as its IP claim without validation Validation status labels; psychometric QA; firm_validated only after thresholds Share of firm packs with QA report
External norm misrepresentation Separate benchmark layer, mandatory labels, licence expiry Label-lint failures at export
Video creates legal exposure Separate consent, retention clocks, one-click purge, transcript fallback, no emotion scoring shown Purge SLA; consent withdrawal rate
Firm uses OrgDiagnostic once and leaves Retainer Pulse wholesale; action portfolio linked to items; drift alerts; book norms that improve with tenure Wave-2 / SOW attach within 12 months
OrgDiagnostic looks like HR software to the buyer No per-employee-only pricing; firm OS features; editorial design; zero vendor chrome Win/loss notes
Scope creep into performance, recognition, or form building "What not to build" list in product principles; roadmap reviews against it Feature requests declined with rationale