New in CultureMonkeyJuly 1, 2026

Speak Up. A confidential channel for workplace concerns

Serious workplace concerns too often stay in inboxes and corridor conversations. Employees can now report anonymously by default, and your HR or compliance team triages, investigates and closes every case on a dedicated board.

Anonymousby default, identity optional
No loginpublic reporting portal
Case boardtriage → investigate → close
Full recordof every step

Serious concerns stop living in inboxes and corridor conversations. Speak Up is two things at once: a public reporting portal where any employee can raise a concern without logging in to anything, and a case-management workspace where your HR or compliance team triages, investigates and closes what comes in - with a record of every step.

The reporter portal employees see, and the case board your team works from.
Availability

To enable Speak Up for your organisation, contact your Success Manager - that includes access for your Super Admins, who don't get it automatically. The analytics dashboard is enabled separately.

What Speak Up is

Speak Up has two surfaces that never mix. Which one you're looking at depends entirely on who you are.

SurfaceWho uses itSign-in
Reporter portalAny employee raising a concernNone. It's a public page at yourcompany.culturemonkey.io/speak-up
Case workspaceYour HR, compliance or investigation teamEither an existing CultureMonkey admin account granted Speak Up access, or a Speak Up-only login for staff who don't have one - CultureMonkey admins outside the Speak Up team never see these cases

That second point matters: a compliance officer who has never used CultureMonkey doesn't need an admin seat to work cases. They get a Speak Up login of their own, scoped to Speak Up and nothing else.

Reporting a concern

The reporting page needs no CultureMonkey login, so an employee can raise something without signing in - and without an account existing for them at all. The form is guided rather than a blank text box.

What an employee sees before they've signed in to anything.
  1. 1Open the reporting page, or scan the QR poster.
  2. 2Choose to report anonymously or identified.
  3. 3Pick a category - each one asks its own follow-up questions.
  4. 4Describe what happened, and answer the follow-up questions for that category.
  5. 5Add a location, and attach files if there's anything to evidence.
  6. 6Set a password. This is what lets you come back to the case later.
  7. 7Review everything, then submit - your report number is given on the confirmation screen. Save it with your password.

Every report gets a reference in the form SU-2026-00013 - the year plus a running number. Submitting offers the choice to download a PDF copy of the report, so a reporter can keep their own record of what they filed.

The confirmation a reporter lands on right after submitting.

A reporter can attach supporting documents, screenshots, photos or recordings - up to 5 files per case, each with a size cap - if your workspace allows uploads. Files can be added, removed or skipped entirely before continuing.

Attachments are optional to offer

Whether reporters can upload files at all is a setting you control - switch it off if you'd rather not accept them.

Anonymous or identified

A reporter chooses their mode at submission, and it can never be changed afterwards - not by them, and not by your team. Someone who reported anonymously stays anonymous for the life of the case.

ModeWhat your team sees
AnonymousNo name, no email. The case carries only what was written.
IdentifiedThe reporter's name and email, given deliberately.

Identified reporting can be turned off, leaving anonymous as the only route. If you keep it on, you can additionally require email verification: the reporter is sent a 6-digit code and must enter and verify it before the report will submit.

Anonymity and follow-up are separate choices

Reporting anonymously does not mean losing contact. An anonymous reporter can still track the case with their report number and password together, and can still receive email notifications - see below.

Following a case as a reporter

The report number and password are the reporter's way back in. From their case page they can read replies from your team, send follow-up messages, see where the case has got to, and download the attachments they submitted.

Reporters do not see your internal stage names. They see a plain-language status instead:

Your team's stageThe reporter sees
New, TriageReceived
InvestigationUnder review
ConcludingResolved
ClosedClosed

The notification email your team can't see

A reporter can optionally store a personal email address to be notified when the case moves or when your team replies. That address is kept private to the reporter - it is never exposed as their identity to the case team.

There is no password recovery

The report number and password are the only way back into a case, and there is no self-service recovery for either - not by email, not by any form. If a reporter loses both, the case is unreachable to them, even to your team on their behalf. Encourage reporters to record their report number and password somewhere safe at the point they submit.

The notification email doesn't change this - it only decides whether a reporter is proactively told about updates. Without one stored, a reporter sees replies the next time they sign back in with their report number and password; nothing is pushed to them in the meantime.

Once a case is closed, the reporter can no longer send new messages on it.

The case queue and workflow

Every report lands in a shared queue, filterable by stage, category and risk level. Opening a case gives your team the full intake, the message thread, and the attachments side by side.

The shared queue your team works from.
A case opened from the queue - the full intake next to stage, assignee and category.

Cases move through five stages:

  1. 1New
  2. 2Triage
  3. 3Investigation
  4. 4Concluding
  5. 5Closed

A case can be closed from any stage, and a closed case can be reopened back into investigation. Anything else is blocked - you can't skip triage or run a case backwards by accident.

Replies and internal notes

Your team replies to the reporter from the case page, in a two-way thread that works even when the reporter is anonymous.

The reporter's message and your team's reply, in the same thread.

Alongside that thread, your team can write internal notes. These are visible only to the case team - the reporter never sees them, and they are never included in anything sent out.

Assignment

New cases can be distributed automatically, round-robin, among the members assigned to that category who are flagged for auto-assignment - so a report doesn't sit unowned overnight. Auto-assignment can be switched off if you'd rather triage manually. Either way, a case can be reassigned to a specific person at any time, and the new owner is emailed directly.

Who can see what

Visibility is decided by role, not by who happens to be on the team. There are three Speak Up roles, and a CultureMonkey Super Admin can also be given the same reach as an Admin - but only once they've been explicitly added to the case team.

RoleCases they seeChange stage & closeSettingsAnalytics
Admin
Full module admin
AllYesYesYes
Member
Manages cases in scope
Their assigned categoriesYesNoOften (scoped)
Viewer
Views and responds only
Cases assigned to them, or in scopeNoNoLimited

Being a CultureMonkey Super Admin doesn't grant Speak Up access on its own - like everyone else on the case team, a Super Admin needs to be explicitly given it before they can sign in and see cases. A Viewer can read the cases in their scope and reply to reporters, but cannot assign a case, move it between stages, or close it.

Category scoping is real isolation, not a filter on a screen. A Member assigned only to Workplace Harassment cannot open, search, receive live updates for, or see analytics on any other category's cases.

Members are added from your existing employee directory and are given their own Speak Up password, shown once at the point of creation. Removing a member deactivates their access immediately while keeping their history on the cases they touched.

Categories, questions and risk

Typical starting categories include Workplace Harassment, Safety Violation, Discrimination, Fraud / Misappropriation, and Policy Violation, plus an Other option for anything that doesn't fit. Each category carries its own description, its own set of follow-up questions, and a risk level.

All of it is editable - rename categories, rewrite the descriptions, rewrite the questions, change the risk levels, reorder them, deactivate ones you don't need, or add your own. Risk runs Critical, High, Medium, Low, and the queue can be filtered by it.

Risk is internal only

Risk levels are set by your team and used for triage. Reporters never see them.

The follow-up questions are what turn a vague report into an actionable one - each category asks its own, some required and some optional, so the reporter answers those instead of guessing what your team needs to know.

Who gets emailed, and when

Six notifications, each of which can be switched off on its own.

WhenWho is emailed
A report is submittedThe auto-assigned owner - or every Admin, if the case has no owner
A reporter sends a follow-up messageThe case owner - or every Admin, if unowned
A case is assigned to someoneThat person, directly
Your team repliesThe reporter, at their hidden notification email
A case changes statusThe reporter
A case is closedThe reporter

The wording of the new-case email to your team, and of all three reporter emails, can be replaced with your own.

Languages and translation

The reporter portal is multilingual - it offers whichever languages your organisation already has enabled in CultureMonkey. You choose which of those to expose on the portal, and which one is the default; English is always available. If more than one is enabled, reporters get a language switcher and the whole form - instructions, categories, guided questions, buttons - appears in the language they pick.

Enabling a language can trigger automatic translation of your categories, descriptions and follow-up questions into it. Those translations land as drafts you can edit and mark as reviewed - so a machine translation never goes out as final without someone signing off.

For the case team, translation works in the other direction - where it's configured for your account, a report or message can be translated into English, shown alongside the original rather than replacing it. Your team can also request or refresh that translation directly from the case.

Reaching frontline and deskless teams

Not everyone has a work laptop. Every workspace gets a shareable reporting link - copy it into an email, your intranet, or a chat message, and it opens straight to your reporting form. The same link also comes as a QR poster carrying your logo and organisation name, for factory floors, kitchens, depots and site offices. You can download the full poster, or just the QR code on its own to drop into materials you've already designed.

Regenerating the link retires every copy of it

One "Regenerate link" action replaces both the reporting link and the QR code together, and the old link stops working immediately. That includes every copy of it - printed posters, but also bookmarks, links pasted into an intranet page, or shared in a message. Regenerate when a link has ended up somewhere it shouldn't, and be ready to replace every copy of the old one, not just the printed posters.

Analytics

A dashboard over any date range you choose, showing program health:

  • Total cases, with the trend against the prior period of equal length.
  • Cases by stage, so you can see what's sitting in triage versus investigation.
  • Cases by category, with a risk badge on each, ordered by risk.
  • Export to spreadsheet for board or compliance packs.

Analytics respects the same category scoping as the queue: a Member sees the numbers for their categories only, never the whole organisation. Viewers typically don't have analytics access at all.

What you configure

  • The portal - on or off, its background (presets or your own image), and the trust and anonymity wording employees read before they file.
  • Whether the landing page shows a "Track report" button - alongside the primary "Start new report" action.
  • Identified reporting - whether it's offered at all, and whether it requires email verification.
  • Attachments - whether files can be uploaded at all.
  • Languages - which of your organisation's enabled languages the portal offers, and which is the default.
  • Categories - names, descriptions, follow-up questions, risk levels, translations, which are active on the intake form, and the order reporters see them in.
  • Your team - members, their roles, and which categories each can see.
  • Notifications - which of the six are sent, and the wording of the emails.
  • Assignment - whether new cases distribute automatically.
  • Your QR poster - generate, download and regenerate.
Built with our customers

See what a warmer engagement platform looks like

Book a walkthrough and we will show you the features on this page, live in your workspace.