Role-based access control for employee engagement surveys

Who gets which role, what each role sees, and how to keep it right after every reorg. Engagement surveys collect candid opinions about named managers, pay, and leadership, so a single loose permission can fail your HR, InfoSec, and Legal reviews all at once.

Who sees what

Program owner

HR operations or people analytics

Whole organization

  • Every team and location
  • Comments above the threshold
  • Exports and account settings
  • Break anonymity
1 of 4
Written by
Kriti Mishra, AI Content Marketing Specialist at CultureMonkey
Kriti Mishra
AI Content Marketing Specialist
Specializes in writing about employee engagement, workplace culture, and manager effectiveness.
Reviewed by
Engineering and Compliance Team
CultureMonkey's engineering and compliance team, which maintains the platform's roles, data scopes, and anonymity thresholds.
Published
20 min read

What happens when the wrong person sees your survey results?

Survey access control matters because engagement surveys collect candid opinions about named managers, pay, and leadership. HR needs employees to trust who reads their answers. InfoSec needs the fewest people holding sensitive data. Legal needs access limited to what each purpose requires. One loose permission can fail all three reviews at once.

What each reviewer needs from the survey access model
ReviewerCore concernQuestion they will askWhat satisfies them
CHRO or HR leaderEmployees answer honestlyCan a manager work out who wrote a comment?A written manager access policy tied to team size
InfoSec or ITThe fewest people hold sensitive dataWho can export raw comments, and is that recorded?A role matrix with named export holders
Legal or privacy leadAccess limited to purposeIs survey data open only to people who need it?Documented scopes and a review cadence
Works council or employee representativeFair use of employee voiceWill results be used to single out individuals?An agreed report scope with no individual-level access
People managersA useful, fair view of their teamWhat will I see, and when?A published timeline and team-size rule

This page is for information only and is not legal advice. For hosting region, processing agreements, and SSO, see our guide to data residency and GDPR review for employee surveys.

How do roles, scopes, and thresholds decide who sees what?

Role-based access control for employee engagement surveys is a permission model that gives each platform user a role, such as program admin, HR partner, or people manager. The role decides what the user can do. A data scope decides whose results they see. An anonymity threshold then hides any group too small to protect.

Role-based access control (RBAC): a way of granting access by job role. Each role carries a fixed set of permissions, and people receive a role instead of individual permissions.

RBAC limits people, while thresholds limit data, so an employee survey program needs both.

What each access control decides
ControlQuestion it answersExample in an engagement surveyWho usually sets it
RoleWhat can this person do?A people manager can view reports but cannot export commentsSurvey program owner
Data scopeWhose results can this person see?An HR partner sees only the EMEA sales organizationSurvey program owner
Anonymity thresholdHow small a group can be shown?A team's results appear only after enough people respondSurvey program owner, within vendor limits

Anonymity threshold: the minimum number of responses a group needs before its results appear in a report. See how anonymity thresholds and minimum group sizes work.

Role names differ between vendors, so compare the permissions behind each role, and keep in mind the difference between anonymous versus confidential surveys.

Which roles does an employee survey program need?

Most employee survey programs need five access levels: an account owner, scoped admins for HR partners, people managers, read-only report viewers, and respondents. Add a configuration-only IT role where the platform offers one. Map every job title to the narrowest level that still lets that person do the job, before the survey launches.

Least privilege: The principle that a security architecture is designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.

Source: NIST SP 800-53 Rev. 5, via the NIST CSRC Glossary

Employee survey role and permission matrix
Person in your organizationAccess levelData scopeCreate surveysView reportsRead commentsExport dataChange settings
Survey program owner (HR operations or people analytics)Account ownerWhole organizationYesAllYes, above thresholdYesYes
CHRO or Chief People OfficerAccount owner or report viewerWhole organizationOptionalAllSummariesSummary filesNo
Regional HR or HR business partnerScoped adminAssigned regions, units, or sitesWithin scopeWithin scopePolicy decisionScoped summariesNo
People manager with 3 or more reportsManagerOwn reporting lineOff by defaultOwn teamPolicy decisionNoNo
Executive sponsor or division headReport viewerTheir divisionNoDivisionNoNoNo
Works council or employee representativeReport viewerAgreed populationNoAgreed reportsNoNoNo
External consultantReport viewer, removed on a set dateAgreed populationNoAgreed reportsNoNoNo
IT or identity adminConfiguration only, where offeredNoneNoNoNoNoSSO and integrations only
Legal or privacy reviewerNo standing loginNoneNoNoNoNoNo
EmployeeRespondentOwn responsesNoResults shared backNoNoNo

Where a platform has no configuration-only role, IT works alongside the account owner instead of holding a login with data access.

Assign survey roles in this order

  1. List everyone who needs results, with job title and business reason. Owner: survey program owner.
  2. Match each person to the narrowest access level in the matrix. Owner: survey program owner with the HR partner lead.
  3. Set the data scope for every scoped admin and report viewer. Owner: survey program owner.
  4. Check manager eligibility against current team sizes in the HRIS. Owner: HRIS owner.
  5. Get sign-off on the matrix from InfoSec and Legal before launch. Owner: CHRO.

How should you scope survey data by business unit, location, or team?

Scope survey data to the smallest slice that matches a person's responsibility, such as one region, one business unit, or one site. Combine dimensions so access narrows instead of widening. Test every scope before launch, because in some platforms a scoped admin saved with no scope selected can see the whole organization.

Data scope: the set of employees whose survey results a user can see, defined by dimensions such as location, business unit, team, or a custom attribute.

How to scope survey data by organization shape
Organization shapeWho needs scoped accessScope byWatch out for
Under 250 employees, one or two sitesUsually no one beyond the account ownerWhole organizationSmall teams fall under the threshold, so plan roll-ups to department level
250 to 2,000 employees, several locationsHR partners by locationLocation, then departmentA location with a single team exposes that team's manager to location-level readers
Enterprise with subsidiaries or business unitsSubsidiary and business unit HR leadsBusiness unit or legal entity first, then regionDecide which entity owns shared services staff before you scope
Frontline, multi-site workforce (retail, manufacturing, hospitality, healthcare)Site or plant HR, regional operations leadsSite, then shift or departmentShift supervisors often have no login, and small shifts fall under the threshold

How much survey data should a people manager get?

A people manager should get aggregated results for their own reporting line, and only after enough people respond to protect identity. Scores and trends are usually safe to share. Open comments, demographic cuts, and exports need a written policy, because in a small team people can often guess who wrote what.

Three ways to open survey results to managers
Access modelHow it worksBest forMain risk
Automatic reporting-line accessManagers see their team as soon as thresholds are metPrograms with trained managers and teams of 5 or moreManagers react before HR has added context
Staged accessHR reviews results for a fixed, announced window, then opens manager viewsMost mid-market and enterprise programsNeeds a date that employees and managers can see in advance
Share by exceptionManagers see nothing until HR shares a specific viewA first survey, a low-trust period, or a restructuringSlow, and managers disengage from the results

Recommended starting policy by team size

Count the direct and indirect reports who received the survey.

  1. Fewer than 3: no manager view. Results roll up to the next level.
  2. 3 to 4: scores and trends only, with no comments and no demographic filters.
  3. 5 to 9: scores, trends, and comments that meet the threshold, with no demographic filters.
  4. 10 or more: the full team dashboard, with every filter still limited by the threshold.

Access is only half the job: check whether employees can rate their own manager honestly, then help managers turn team results into an action plan.

How should you control exports, downloads, and shared report links?

Treat exports as the highest-risk survey permission, because a downloaded file no longer follows the platform's access rules. Keep comment and raw data exports with the survey program owner, give scoped roles summary files only, and give every shared report link a named owner and a removal date.

Employee survey output risk ladder
OutputWhat it containsRiskRecommended holderControl to require
On-screen reportScores above the thresholdLowAnyone with a report role, within scopeScope and threshold applied
Summary PDF or slide deckScores and chartsMediumAccount owner, and scoped admins for their own scopeScope applied inside the file
Heatmap spreadsheetScores by demographic cutMediumAccount owner and program adminsSmall groups masked inside the file
Comment exportVerbatim open textHighSurvey program owner onlyThreshold applied inside the file, closed surveys only
Identified response exportNamed answers from identified surveysHighestA named program ownerWritten purpose, file deleted after use
Shared report linkA report anyone with the link can openHighAccount owner onlyNamed owner, removal date, listed in the access review
API accessEmployee or survey data through an integrationHighIT, one integration at a timeScoped keys where offered, rotated when staff change

Who should hold exports in your organization?

Bring your reporting lines, and a CultureMonkey specialist will walk the role matrix through with you.

How do you keep survey access accurate after reorgs, promotions, and exits?

Keep survey access accurate by tying it to HRIS events instead of memory. When someone joins, moves, is promoted, or leaves, their survey role and scope should change at the next HRIS sync. Then run a full access review every quarter and after every reorg, acquisition, or leadership change.

Survey access lifecycle: event, change, owner, deadline
EventWhat should change in the survey platformOwnerDeadline
New people managerManager view opens once the team meets the minimum sizeHRIS ownerNext HRIS sync
Manager moves to another teamThe old team's view closes, and you decide where historical reports liveHR partnerBefore the next survey closes
Team drops below the minimum sizeManager view closes and results roll up a levelSurvey program ownerBefore the next launch
HR partner changes regionNew scope added and old scope removedSurvey program ownerSame day
Admin or manager leavesLogin access removedIT, through the HRIS or SSOSame day
Acquisition or new legal entityNew business unit and scoped admins addedSurvey program owner and ITBefore the first survey in that entity
Quarterly access reviewEvery admin, scope, export holder, and shared link confirmed or removedSurvey program owner with InfoSecEvery 90 days

How do RBAC, ABAC, and hierarchy-based access compare for survey data?

Role-based access control grants permissions by job role. Hierarchy-based access gives a manager a view derived from the reporting line. Attribute-based access control decides using attributes such as location or business unit. Engagement survey platforms usually combine all three: the role sets actions, the reporting line sets manager scope, and attributes set admin scope.

Attribute-based access control (ABAC): a way of granting access by evaluating attributes of the user and the data, such as location, business unit, or job level.

RBAC, ABAC, hierarchy-based, and share-by-exception access for survey data
ModelHow access is decidedWhere it fits in a survey programFailure mode
Role-based (RBAC)A named role grants a set of actionsCreating surveys, exporting, changing settingsRole sprawl when every exception gets a new role
Hierarchy-basedThe manager field in the HRISManager dashboardsA wrong manager field gives the wrong person access
Attribute-based (ABAC)Attributes such as location, business unit, or job levelScoped HR partners, executives, works councilsStacking attributes can isolate a very small group
Share by exceptionA person grants one specific viewConsultants and one-off leadership reviewsShared views outlive the need

What happens when one person holds two roles?

A manager who is also an HR partner holds two roles. Some platforms give that person the most permissive combination of both. Decide which rule you want, confirm how your vendor behaves, and record the decision in the role matrix.

Should AI assistants follow the same survey access rules?

Yes. An AI assistant that answers questions about engagement survey data should see only what the person asking is allowed to see. It should apply the same role, scope, and anonymity threshold as the dashboard, decline questions about groups below the threshold, and keep a record of what was asked.

97%

of organizations that reported a breach of an AI model or application had no AI access controls in place.

IBM Cost of a Data Breach Report 2025, research by Ponemon Institute, July 30, 2025

AI access rules to require for survey data

  • The assistant inherits the signed-in user's role and data scope.
  • Answers never summarize comments from a group below the threshold.
  • Prompts and answers are recorded and visible to the survey program owner.
  • The assistant cannot export anything the user's role cannot export.

What should InfoSec and HR check in a survey platform's access model?

Check that roles are enforced in the data layer, not only hidden in menus, and that every path to survey data follows them: dashboards, exports, shared links, APIs, and AI features. Ask every vendor the same questions, CultureMonkey included, and ask for the help center article or security document that backs each answer.

ASK EVERY VENDOR
12 access-model questions to ask a survey vendor
#Question to ask the vendorWhat a strong answer includesWhy it matters
1Which roles exist, and what can each one do?A published role and permission tableYou can map job titles before signing
2Is data scope enforced in the data layer?Scope applies to reports, comments, exports, and APIsHidden menus can be bypassed by URL or export
3What does a scoped admin see if no scope is set?A documented defaultA blank scope can mean full access
4Can someone manage SSO or integrations without seeing results?A configuration-only role or a documented processKeeps IT staff out of employee opinions
5What is the minimum team size for manager access?A documented number with a hard floorStops a manager of one or two people seeing identifiable data
6Which roles can export comments, and are thresholds applied inside files?Per-role export switches and masking inside filesFiles leave platform controls behind
7Do shared report links expire, and can you revoke them?Expiry dates or one-click revokeLinks outlive the people they were meant for
8Is "view as" or impersonation off by default and recorded?Off by default, with a record of useImpersonation widens who sees whose results
9Is admin activity recorded in a log you can access?An exportable admin activity logNeeded for investigations and audits
10How is access removed when someone leaves?HRIS or SSO deprovisioning on the same dayFormer staff keep access otherwise
11How do admins use multi-factor authentication?Native MFA, or SAML SSO with MFA at your identity providerAdmin accounts hold the most data
12How are API keys scoped?Separate, least-privilege keys per integrationOne broad key can expose every employee record

For anonymity controls such as data masking and privacy by design, see anonymous employee survey controls, and for the rest of the evaluation, use the full survey vendor evaluation checklist.

How do you explain the survey access model to employees?

Explain the access model in the survey invitation and on the first survey screen. Say who can see results, at what group size, and who can never see individual answers. Keep it to four or five plain sentences. When employees know exactly who reads their answers, they do not have to guess.

40%

of employees said their organization gave no communication about what productivity data is collected and how it is used.

Gartner survey of more than 3,500 employees, April 2021, published August 18, 2022

Engagement survey data is more sensitive than productivity data, so it deserves at least that much clarity.

COPY THIS NOTICE

Who can see your answers. This survey is anonymous. HR survey administrators see results only for groups of [5] or more people. Your manager sees team results only when at least [5] people on your team respond, and never sees who said what. Comments follow the same minimum. No one, including senior leaders and HR, can link your answers to your name.

Replace the numbers in brackets with your platform settings, and delete any sentence your settings do not support.

These tools need to be seen not like police tools, but tools that give hints and sentiment to understand the situation of the people.

Maria Rosaria BonifacioMaria Rosaria BonifacioVP and People Head, Nokia.CultureClub X, Season 6, Episode 8.Watch episode →

After the survey closes, follow the same openness when communicating survey results back to employees.

How does CultureMonkey handle role-based access for surveys?

CultureMonkey uses five roles: Super Admin, Sub Admin, Manager, Report Viewer, and Employee. Sub Admin access is limited by a data scope, manager access follows the reporting line, and anonymity thresholds apply to every role. The details below come from the CultureMonkey Help Center, updated July 2026.

Roles

CultureMonkey "separates who someone is (an employee in your org) from what they can access (their role in the admin app)."

Sub Admin scope

a scope is built "from up to six dimensions": teams, locations, business units, business groups, sub-teams, and custom attributes. "It isn't a filter they can toggle off; it's a boundary drawn around their account."

Set a scope every time

"If you don't select any business group, team, location, business unit or attribute for a Sub Admin, they get access to all employees."

Manager eligibility

"CultureMonkey requires a minimum of 3 reportees before manager access can be switched on."

Manager visibility settings

"Hide free-text responses from managers", "Hide heatmap from managers", "Hide Strength and Weakness from managers", and "Disable survey creation for managers" are available as account settings.

Anonymity thresholds

anonymous surveys use a response threshold that defaults to 3, which is also the floor, and the dashboard anonymity threshold defaults to 5 and cannot be set below 3. "The one thing a Super Admin still cannot do is break anonymity."

Exports

"Exports respect the same anonymity thresholds as on-screen reports."

View as Manager

Sub Admins can view the product as a manager only when an account setting is on, and only for managers in their own scope. "Both settings are off by default for a reason: they expand who can see whose results."

Sign-in and leavers

admins and managers can sign in with SAML 2.0 single sign-on, so access follows the corporate identity they already have. When your HRIS marks someone inactive, "CultureMonkey deactivates them and removes any admin access they held."

Running role-based access in CultureMonkey

The Help Center articles behind the claims in this section, verified September 16, 2026.

  1. How CultureMonkey defines each role
  2. Setting a Sub Admin data scope
  3. Manager visibility settings

See role-based access for surveys in CultureMonkey and CultureMonkey security and compliance for the full product view.

Conclusion

Role-based access control for employee engagement surveys turns a promise of confidentiality into a rule the platform enforces. A role sets what each person can do, a data scope sets whose results they see, and an anonymity threshold hides groups too small to protect. Together they decide whether employees trust the survey enough to answer honestly.

This guide covered the roles a survey program needs, how to scope data by organization shape, how much a people manager should see, why exports and shared links carry the most risk, how to keep access accurate through reorgs and exits, and the questions InfoSec should ask a vendor. CultureMonkey supports that model with five defined roles, Sub Admin scopes enforced at the data layer, a three-reportee minimum for manager access, and anonymity thresholds that no role can bypass. If you are still shortlisting platforms, compare employee engagement survey tools against these checks.

Frequently asked questions

How many super admins should an engagement survey account have?

Keep super admins to the smallest number that still covers absence, usually two named people in HR. A super admin sees results for every team and location, so each extra one widens exposure. Give everyone else a scoped or read-only role, and review the super admin list every quarter.

Why can't a manager see their team's survey results?

A manager usually cannot see results for one of three reasons: the team is below the minimum size for manager access, too few people responded to meet the anonymity threshold, or the organization has hidden manager views. Check team size in the HRIS first, then the survey's response count, then the manager visibility settings.

Who should see responses on an identified exit or onboarding survey?

Limit identified exit and onboarding responses to the survey program owner and a named HR partner who acts on them. The departing employee's manager should not read identified exit answers, because many exit comments are about that manager. Share themes with managers only in aggregate, and state this rule in the survey invitation.

Should executives get access to raw survey comments?

Executives rarely need raw comments. Give them aggregated scores, trends, and themed summaries for their division through a read-only role. Raw comments carry the highest risk of identifying someone, so keep them with the survey program owner and scoped HR partners who are trained to handle them.

What access should a works council or employee representative get?

Give a works council or employee representative a read-only report role scoped to the population they represent, with no comment access and no exports. Agree the scope and the reports in writing before launch. Where works councils have consultation rights, agree the access design with them before the survey goes live.

Should HR business partners see results outside their region?

Not by default. An HR business partner should see results only for the regions, business units, or teams they support. Grant wider access for a named project, record who approved it, and remove it on a set date. Company-wide comparisons can come from the survey program owner's summary reports.

What happens to a manager's survey access after they change teams?

The manager's view should follow the new reporting line at the next HRIS sync, so they stop seeing the old team's current results. Decide in advance whether historical reports stay with the manager or with the team. Check any shared report links the manager created, and remove links that still point to the old team.

Can someone see survey results without a platform login?

Yes, if an admin creates a shared report link. Anyone holding the link can open that report, so treat links like exports. Only the account owner should create them, each link needs a named owner and a removal date, and the quarterly access review should list every live link.

Does single sign-on control what someone can see in survey reports?

No. Single sign-on controls how admins and managers log in, not what they can see. The role and data scope assigned inside the survey platform decide visibility. Use single sign-on with multi-factor authentication at your identity provider to protect admin logins, and use roles and scopes to limit the data.

Map your survey roles before launch day

Walk through roles, data scopes, and manager visibility settings with a CultureMonkey specialist, using an org structure like yours.