The OTP survey form and its fields
What the one-time passcode (OTP) survey form is, when CultureMonkey uses it to verify survey-takers on shared and QR-code links, which profile fields you can require on it, how to enable and configure them, and how to balance verification against friction and anonymity.
On this page
Most CultureMonkey surveys reach people through a personal link - a unique URL, emailed or messaged to each employee, that already knows who they are. But sometimes you can't send a personal link. You want to print a QR code on a break-room poster, drop a single shared link into a company-wide announcement, or open a survey to a group you don't have individual addresses for. In those cases, the link is the same for everyone, so it can't tell one person from the next.
The OTP survey form - OTP stands for one-time passcode - is how CultureMonkey closes that gap. Before a shared or QR-code survey opens, the form asks the taker to identify themselves (by email, phone number, or employee ID), verifies them, and only then resolves them to the right person and hands over their response. This guide explains what the form is, when it appears, which profile fields you can require on it, how to enable and configure them, and - importantly - how to weigh tighter verification against the friction and anonymity concerns it can create.
The OTP survey form is a verification gate that appears on shared and QR-code survey links (not on personal links). By default it collects an email address and sends a one-time passcode to confirm identity. You can instead - or additionally - require a phone number, an employee ID, or an employee ID scoped to a location, using a handful of account settings. More verification means cleaner, correctly-attributed data; it also adds a step for the respondent, so choose the lightest form that meets your needs.
What the OTP survey form is
A personal survey link carries a hidden identifier that maps straight to one participant. When someone opens it, CultureMonkey already knows who they are, so it can show their survey immediately - no sign-in, no form.
A shared link or a QR code works differently. It's a single, generic URL - for example a link you paste into a Slack channel, or a code employees scan from a poster. Because everyone uses the same link, it carries no personal identity. If CultureMonkey simply opened the survey, it would have no way to know whose responses these are, whether the person is actually part of the audience, or whether the same person is answering twice.
The OTP survey form solves this. It's the first screen a taker sees on a shared or QR-code link, and its job is to establish who is answering before the survey opens. Depending on how you've configured it, the taker enters an email, a phone number, or an employee ID; CultureMonkey looks that value up against your employee list; and only a match that is active and part of the survey's audience is let through.
If you distribute a survey through personal email, SMS, or WhatsApp links, respondents never see the OTP form - those links already identify the person. The OTP form is specific to shared and QR-code distribution. See Distribution channels overview for how the channels differ.
When the form appears
The OTP form is tied to the kind of link, not to a per-user setting. It shows up for two families of shared access:
- Shared (custom) survey links - a single URL generated for a survey that everyone in the audience can use. This is the classic "one link for the whole company" pattern.
- QR-code and lifecycle links - codes and generic links designed to be scanned or opened by anyone in a defined group, without a personal address.
For the form to appear at all, the survey has to be live and accepting shared access. A survey that's still in draft won't serve the OTP page, which prevents links from leaking responses before you're ready. Once the survey is running, opening the shared link renders the verification form first, and the survey itself second - only after verification succeeds.
What the form collects
Out of the box, the form asks for one thing: the respondent's work email address. But you can change which identifier it asks for, using account settings. The form always runs in exactly one of these modes at a time, and the mode is decided by which settings you've turned on:
| Mode | What the taker enters | When it's used |
|---|---|---|
| Email (default) | Work email address | No special settings enabled |
| Email or phone | Email address or mobile number in the same field | Phone-number OTP is enabled |
| Employee ID | Their employee ID | Employee-ID verification is enabled |
| Employee ID + location | A location, then their employee ID | Employee-ID and location verification are enabled |
Whatever mode is active, the identifier field is required - the taker can't proceed without it. There is no separate name field, and phone numbers (when allowed) are entered in the same box as the email rather than a field of their own. You can also add a line of custom help text above the submit button to explain what to enter and why.
Enabling employee-ID verification takes priority: when it's on, the form asks for the employee ID (and location, if you've enabled that too) instead of email or phone. If you want people to verify by email or phone, leave employee-ID verification off.
The settings that control the fields
All of the following live in your account configuration. Each is off by default, so a brand-new account uses the plain email form until you change something.
| Setting | Default | What it does |
|---|---|---|
| Require employee ID | Off | The form asks for the employee ID instead of email/phone, and verifies it against your employee list. When a match is found, the taker goes straight into the survey - no passcode is sent. |
| Require location with employee ID | Off | Adds a location picker before the employee-ID field, so the ID only needs to be unique within a location. Only meaningful when employee-ID verification is also on. |
| Allow phone-number OTP | Off | Lets the taker enter a mobile number as an alternative to email in the identifier field; the passcode can then be delivered by SMS/WhatsApp as well as email. |
| Phone-field note | Empty | A short note shown under the identifier field - handy for telling people what number format to use. |
| Form help text | Empty | Custom guidance shown above the submit button. Only appears when you set it. |
| Skip passcode step | Off | Once the identifier matches an employee, opens the survey without sending or asking for a passcode. Trades a verification step for lower friction. |
The location setting only does something when employee-ID verification is also enabled. Turning on location by itself has no effect. Enable both if your employee IDs are only unique within a site (for example, when different offices reuse the same ID numbers).
How verification works, step by step
Here's the full journey a respondent takes on a shared or QR-code link, in the default email mode:
- 1Open the link - the taker scans the QR code or clicks the shared URL. CultureMonkey checks that the survey is live and serving shared access, then shows the OTP form instead of the survey.
- 2Enter an identifier - they type their work email (or, depending on your settings, a phone number or employee ID) and submit.
- 3Match against your people - CultureMonkey looks the value up in your employee list. It must match an active employee who is part of this survey's audience; otherwise the form shows an error and the survey stays closed.
- 4Receive a passcode - for email or phone verification, CultureMonkey generates a one-time passcode and sends it to that email (and, where a phone number is present, by SMS and WhatsApp).
- 5Enter the passcode - the taker types the code into the next screen. A resend link appears after a short wait if it hasn't arrived, with a small resend limit to prevent abuse.
- 6Open the survey - once the code checks out, the person is resolved to their participant record and the survey opens as their response.
Two shortcuts are worth knowing. In employee-ID mode, a successful ID match takes the person straight into the survey - no passcode is sent, because the ID lookup already establishes identity. And if you've enabled Skip passcode step, even the email/phone modes will open the survey immediately after a match, without the code exchange. Both trade a little rigor for a lot less friction.
Choosing the right level of verification
The fields you require are a genuine trade-off. Tighter verification gives you cleaner data - every response is attributed to a real, active member of the audience, duplicates are harder, and outsiders can't wander in. Lighter verification gets more people through the door with less effort. There's no universally correct setting; it depends on the survey.
A few rules of thumb:
- Frontline or deskless workforce? Employee ID (optionally scoped by location) often beats email, because many frontline staff don't have or check a work email. A QR code plus an ID they already know is the smoothest path.
- Everyone has a work inbox? The default email OTP is usually the lightest reliable option, and the passcode adds a second factor almost for free.
- Mixed audience? Enabling phone-number OTP lets people choose email or mobile, which widens reach without changing the flow much.
- Speed over strictness? For low-stakes or high-volume moments, Skip passcode step removes the code exchange while still checking that the identifier belongs to a real employee.
Always add help text when you require something less obvious than an email - a one-line prompt like "Enter the employee ID printed on your badge" prevents a surprising amount of drop-off.
Verification and anonymity
Requiring an identifier can feel at odds with anonymity, so it's worth being precise about what the OTP form does and doesn't do. The form's job is to confirm that a taker belongs to the audience and to route their answers to the right participant record. That's about access and attribution, not about exposing who said what.
Anonymity is enforced separately, by CultureMonkey's response thresholds and by whether a survey is set up as anonymous or identified. Even when someone verifies with an email or employee ID, an anonymous survey still masks their identity in reporting, and small groups stay hidden until enough people respond. In other words, verifying at the door doesn't unmask anyone inside - the same protections apply as on any other link. For the full picture, see How anonymity keeps your feedback safe.
Because a verification screen can look like it's collecting personal data, respondents sometimes hesitate. A short reassurance in the help text - that verification only confirms eligibility and that responses remain anonymous where the survey is anonymous - noticeably improves completion.
Best practices
- Match the identifier to the audience. Use email where inboxes are universal; use employee ID (with location if IDs repeat across sites) for frontline and deskless teams.
- Turn on both employee-ID settings together when IDs are only unique within a location, and neither alone otherwise.
- Always write help text for anything beyond a plain email prompt, and use it to reassure people about anonymity.
- Reserve Skip passcode step for low-risk surveys. The passcode is a cheap second factor; skip it only when speed genuinely matters.
- Test the exact link you'll distribute before you publish it widely - open the shared URL or scan the QR code yourself and walk through the form once.
Frequently asked questions
Do people using a personal survey link see the OTP form?
No. Personal email, SMS, and WhatsApp links already identify the recipient, so they open the survey directly. The OTP form only appears on shared and QR-code links, which carry no personal identity.
If someone verifies with their email or employee ID, is their survey still anonymous?
Yes, where the survey is set up as anonymous. Verification controls access and attribution, not what's shown in reports. Anonymity is enforced by response thresholds and the survey's anonymity setting, independently of how the person got in. See How anonymity keeps your feedback safe.
Can I ask for both an email and an employee ID?
No - the form runs in a single mode at a time. Enabling employee-ID verification switches the form to ask for the ID (and location, if enabled) instead of email or phone. Choose the one identifier that best fits your audience.
What happens if the identifier doesn't match anyone?
The form shows an error and the survey stays closed. The value has to match an active employee who is part of the survey's audience; unknown, inactive, or out-of-audience values are rejected, which is what keeps outsiders out.
How does someone receive their passcode?
By email to the address they entered. If phone-number OTP is enabled and a phone number is on file, the code is also sent by SMS and WhatsApp. A resend option appears after a short wait, with a small resend limit.
Can I skip the passcode step to make it faster?
Yes - the Skip passcode step setting opens the survey as soon as the identifier matches an employee, without the code exchange. Employee-ID mode already behaves this way. Use it when lower friction matters more than the extra verification factor.
Where to go next
- See how takers reach a survey in the first place: Distribution channels overview
- Understand the normal sign-in path: Logging in to CultureMonkey
- Reassure people their answers are safe: How anonymity keeps your feedback safe
Your feedback helps us improve the Help Center.