11. Risks and how the design absorbs them
Each risk is stated with the mechanism in the product that absorbs it, what remains, and the signal we watch.
11.1 The four named risks
Low response
Why it matters. Below ~50% census completion, unit-level cuts collapse under k, non-response bias becomes a legitimate executive objection, and the readout loses its best evidence.
| Design response | Where |
|---|---|
| Cell-size simulator before launch shows which cuts will survive at 50/60/70% response; EM merges cuts before invitations go out | Setup → Cell-size simulator |
| Frontline form ≤ 8 min, no reverse items, voice-to-text, kiosk/QR, shift-aware send times | Catalog §7.3, Launch Command |
| Unit-level completion map with pace-to-target and drop-off item | Launch Command |
| Champion network with completion-only view | Launch Command → Champions |
| Unit-level nudges that never reveal individuals | Nudge rules |
| Post-stratification weighting with the unweighted result always shown, and a banner if they differ by > 2 pts | Scoring §5.4 |
| Method appendix states response by segment, so bias is disclosed, not hidden | Deliverables |
Residual. Some populations (night shift, contractors) stay under-represented. Signal: median completion by package; share of planned cuts suppressed at close.
Works council or union block
Why it matters. In the EU and unionized sites a council can delay or veto a survey. A delay moves the steering date; a veto ends the engagement.
| Design response | Where |
|---|---|
| Works-council mode: higher k (8–10), text-k 15, filter depth 1, no manager view until sign-off, no free-text export to client managers | Anonymity policy |
| Auto-generated review packet: full item list in every language, anonymity rules in plain language, data flows, residency, retention, sub-processors, DPIA template | Setup → Consent & legal (manual in MVP, generated in v1.1) |
| Frozen instrument: once the council approves version X, launch is blocked for any other version | Pack lock + Wave guard |
| Council observer role (v1.1): read-only view of completion and published aggregates | Roles |
| Retention and purge controls visible and demonstrable | Settings → Retention |
Residual. Timelines still depend on council calendars. Signal: days from packet sent to approval; share of EU engagements in works-council mode.
AI hallucination
Why it matters. One invented finding in front of a CEO costs the firm the client and the partner's trust in the tool permanently.
| Design response | Where |
|---|---|
| AI drafts only Insight Objects; nothing reaches a client surface without partner approval | Insight spec §6.5 |
| Evidence-first generation: model selects EvidenceRefs, then writes; numbers must bind to evidence (linter blocks unbound numbers) | §6.6, §6.7 |
| Theme model seeded by the pack's constructs; emergent themes marked and confidence-rated from human-validated samples | Scoring §5.8 |
| Every quote traceable to a source response, clip, interview, or document span | Quote / Clip objects |
| Causal language blocked on associational evidence | Linter |
| Interpretations are consultant-authored pack content, never regenerated | Methodology Studio |
| Provenance (model, prompt version, input hash) stored on every AI draft | Insight fields |
Residual. Subtle mischaracterization of tone in a theme. Signal: share of AI-drafted insights approved without substantive rewrite (target ≥ 60%); theme-coding agreement on validation samples.
Partner skepticism
Why it matters. Partners are the buyer and the bottleneck. If they reread every comment the night before, OrgDiagnostic saved nothing.
| Design response | Where |
|---|---|
| "Show me the n": every number resolves to Scorecard, cut, n, CI, and method on click | Diagnostic Room, exports |
| Deterministic, replayable scoring; golden tests; version stamps in the appendix | Scoring §5.12 |
| Partner voice preserved: approved text frozen; interpretations authored by the firm | Insight spec, Studio |
| Export to the firm's own PPT master, so the deck looks like the firm, not the tool | Deliverables |
| 8-minute spine tested in design-partner sessions | Diagnostic Room |
| Quote book organized by construct and segment, so rereading is fast when a partner still wants to | Evidence → Text |
Residual. Some partners will never use the room and only want the deck. That is fine. Signal: % readouts delivered from room or unmodified export; partner NPS by firm.
11.2 Additional risks
| Risk | Design response | Signal |
|---|---|---|
| A client identifies a commenter | k and text-k, complementary and differencing suppression, PII redaction including role-unique titles, quote permission tiers, video consent tiers | Anonymity incidents (target 0); redaction miss rate on audits |
| Cross-client data leak | Schema-per-workspace, per-workspace keys, RLS, contractor expiry, no cross-workspace query path, hash-chained audit | Pen-test findings; audit anomalies |
| Org changes break longitudinal claims | Hierarchy mapping between waves; mapping-coverage banner; composition check | Mapping coverage per wave-2 |
| Junior analyst over-claims | Significance + effect size + FDR on by default; "meaningful" threshold; borderline band rule; "indicative" stamp on external norms | Linter waivers per engagement |
| Firm treats shipped pack as its IP claim without validation | Validation status labels; psychometric QA; firm_validated only after thresholds |
Share of firm packs with QA report |
| External norm misrepresentation | Separate benchmark layer, mandatory labels, licence expiry | Label-lint failures at export |
| Video creates legal exposure | Separate consent, retention clocks, one-click purge, transcript fallback, no emotion scoring shown | Purge SLA; consent withdrawal rate |
| Firm uses OrgDiagnostic once and leaves | Retainer Pulse wholesale; action portfolio linked to items; drift alerts; book norms that improve with tenure | Wave-2 / SOW attach within 12 months |
| OrgDiagnostic looks like HR software to the buyer | No per-employee-only pricing; firm OS features; editorial design; zero vendor chrome | Win/loss notes |
| Scope creep into performance, recognition, or form building | "What not to build" list in product principles; roadmap reviews against it | Feature requests declined with rationale |