Sensitive investigations often create a difficult access-control problem.
Investigators, case managers, supervisors, and other participants may all need access to the same case — but that does not necessarily mean they all need to know who submitted it.
In many situations, revealing the reporter’s identity adds no value to the investigation itself. Instead, it can increase confidentiality risks or give more people access to personal information than the process requires.
Ethicontrol’s Case Author Pseudonymization helps organisations separate access to the case from access to the identity behind it.
The case remains available to the investigation team, while the reporter’s identity can be hidden from users who do not need to see it.
Traditional case access often works as an all-or-nothing decision.
A user either has access to the case or does not.
But investigations are more nuanced than that. Someone may need to review allegations, evidence, tasks, findings, or decisions without needing access to the reporter’s name or other identifying information.
This becomes especially important when:
Pseudonymization introduces another layer of access control: the case can remain visible while the author’s identity is restricted.
Case Author Pseudonymization allows authorised users to hide the identity of a case author from case members who should not have access to it.
When the author is pseudonymized:
Pseudonymization changes who can see the reporter’s identity without removing the reporter or breaking their connection to the case.
An authorised user opens the case, goes to the Involved section, finds the author under Reporter, and changes their visibility using the eye icon.
Once hidden, users without the required confidentiality permission no longer see the reporter’s identity.
If access needs change later in the investigation, an authorised user can reveal the author again.
Visit our Help Center for a step-by-step guide to hiding and revealing a case author and reviewing visibility changes.
Consider a workplace misconduct investigation involving an employee’s direct manager.
The investigation may require participation from HR, Compliance, Legal, and several operational stakeholders. All of them may need to review the incident details, supporting documents, tasks, and investigation progress.
But not everyone needs to know who submitted the original report.
With Case Author Pseudonymization, the reporter’s identity can be hidden from ordinary case members while remaining available to the authorised investigator or supervisor responsible for the case.
The investigation continues normally, but identity exposure is reduced.
Changing someone’s visibility is itself a sensitive action.
For that reason, Ethicontrol records hide and reveal actions in the Activity log.
Authorised users can review:
This creates a documented history of confidentiality changes instead of relying on informal knowledge about who had access to the reporter’s identity.
Need-to-know access |
Flexible visibility |
|
| Teams can work on the same case without automatically giving every participant access to the reporter’s identity. | Authorised users can hide or reveal the reporter as access needs change during the investigation. |
Traceable confidentiality changes |
Preserved case context |
|
| Every visibility change is recorded in the Activity log. | Pseudonymization does not break the connection between the reporter, their Dossier, and the case. |
It is important to distinguish the two concepts.
An anonymous report is submitted without the organisation necessarily knowing the reporter’s identity.
With pseudonymization, the identity exists in the system but is hidden from users who do not have permission to view it.
This allows authorised roles to retain access when necessary while reducing broader exposure.
It also means that hiding the Reporter field does not automatically remove every piece of identifying information from the case.
Personal information may still appear in:
Those areas should be reviewed separately when additional pseudonymization is required.