Whistleblower intake
This page covers both halves of the intake flow: the reporter's experience filing a concern, and the ethics admin's experience receiving and triaging it. The intake is designed to be low-friction for the reporter (multiple channels, anonymous by default, mobile-friendly) and high-fidelity for the workspace (structured metadata, statutory routing, retaliation-protection attachment).
TL;DR — Reporters file from
/ethics/report-a-concern, the hotline, the dedicated email, or an in-office kiosk. Every intake produces a confidential case + a reporter access code for two-way messaging. Ethics admins triage from Ethics → Intake, route to the right reviewer (ethics / audit committee / EEO / legal), and run the confidential investigation through to resolution.
Reporter experience
What the reporter sees
/ethics/report-a-concern is the workspace's intake landing page. It
opens with an honest scope statement (what the channel is for, what
it isn't), a confidentiality + retaliation-protection statement, and
the option to file anonymously OR identified.
The form has four sections:
| Field | What it does | Accepted values / default |
|---|---|---|
| What category best describes the concern? | Financial / bribery / leadership conduct / retaliation / safety / other. | Drives routing; reporter can pick 'I'm not sure' and triage decides. |
| Where + when? | Location + timeframe — single incident, ongoing pattern. | Free-text + structured fields. Encouraged but not required for anonymous submission. |
| What happened? | The narrative. | Free-text. The form supports paste of files, photos, and supporting docs. |
| Who was involved? | Subject(s) + witnesses. | Optional. The reporter may name as much or as little as they choose. |
After submission
The reporter receives a report code (e.g. R-7Y2K-91Q) + a
single-use access code. They use these two together to log
back into the confidential thread without revealing identity —
even on an anonymous report. The reporter is encouraged to save
both somewhere private.
The thread allows:
- The investigator to ask follow-up questions.
- The reporter to add information, documents, or corrections.
- The investigator to share progress updates ("we've assigned an investigator; expect contact within 5 business days").
- Final notification when the matter resolves.
Channels other than the web form
- Hotline — third-party multilingual service, available 24/7. Operator captures the same intake data + issues a report code. Lands in the same Intake queue as web submissions.
- Email —
ethics@<workspace>.com(workspace-configurable). Auto-acknowledged with a report code; converts to a structured case on receipt. - In-office kiosk — a tablet at a non-trafficked location (typically by HR or building security) with the same web form.
- Physical mail — to the audit committee chair, addressed externally. Converted to a case by the chair's staff (with the chair's direct review).
Ethics admin experience
Triage a new report
Open Ethics → Intake
The queue lists new reports oldest-first. Anonymous reports show as
Anonymous; identified reports show the name + role. Each row carries the reporter's category guess + severity flag.Click "Triage"
A side panel opens with the report. Read it once before classifying.
Classify + route
Pick the category. The form recommends a route: ethics (default) / audit committee (financial misconduct, senior-leader allegations) / EEO (discrimination / harassment) / ELR (workplace conflict) / legal (regulatory, contractual). You can override with a documented reason.
Run the conflict check
If you appear in the reported parties OR you supervise one, the form blocks self-assignment and surfaces the alternate intake path.
Attach a retaliation-watch window
Default 12 months. Any subsequent adverse action against the reporter within the window is flagged for review by Ethics leadership.
Send the first reporter message
Confirm receipt + set expectations. Use the template; the confidential thread is now active.
Work the case
The case file mirrors the EEO + ELR file shape with one critical addition: the reporter-identity firewall.
| Field | What it does | Accepted values / default |
|---|---|---|
| Reporter identity (when anonymous) | Stored encrypted with a separate key. | Cannot be accessed without explicit unlock + reason. Unlock is logged + reviewable by the audit committee. |
| Reporter identity (when named) | Visible to the assigned investigator. | Still masked from anyone outside the investigation scope. |
| Confidential comms thread | All messages between investigator + reporter. | Append-only. Each message timestamped + signed. |
| Investigation tasks / interviews / evidence | Same shape as ELR investigation file. | Reuses the [ELR investigation](/elr/investigations) pattern. |
| Audit committee notification (where applicable) | Committee receives the report intake + status updates. | Automatic when the matter touches financial reporting or senior leadership. |
Run the audit-committee channel
For reports routed to the audit committee:
The committee chair is notified on intake
Through their secured workspace channel; the report content is available in the file for committee members only.
The committee chair (or designee) acts as case lead
Outside counsel often investigates; the file tracks counsel activity at a high level (engagement, periodic status updates, final memo) without breaching counsel's work-product privilege.
The disposition is recorded
The committee's disposition is recorded in the file. The ordinary ethics admin sees the case existed + closed; the underlying narrative is restricted to committee + counsel.
Every field, explained
| Field | What it does | Accepted values / default |
|---|---|---|
| Report code | Public identifier for the report. | `R-XXXX-XXX` format. Reporter uses this + access code to log into the thread. |
| Access code | Single-use sign-in for the reporter to access the thread. | Reset on each successful login. |
| Category | Top-level classification of the matter. | Drives routing + statutory protection determination. |
| Severity | How urgent the response must be. | Pulled from category + the file's interpretive heuristics. Adjustable on triage. |
| Route | Where the report goes after intake. | Ethics (default) / Audit committee / EEO / ELR / Legal. |
| Retaliation-watch window | Period during which adverse action against the reporter is auto-flagged. | Workspace default (typically 12 months); extendable per case. |
| Reporter-identity firewall | Whether the reporter's identity is gated behind explicit unlock. | Always on for anonymous; on by default for named (until the reporter waives). |
Common gotchas
- "A manager wants to know which of their reports filed an ethics report." Don't speculate. Disclosure of reporter identity to a subject — directly or indirectly — is the single most reportable violation in the module.
- "The reporter's narrative doesn't quite match a category." Triage to the closest match + document why. Routing into the wrong category is a recoverable error; refusing to route delays the response.
- "The investigator wants to interview the reporter." Send the request through the confidential thread first; never go outside the thread (a hallway approach, a personal email) unless the reporter has explicitly consented to direct contact.
- "The report is clearly false / vexatious." Document the basis for that conclusion in detail. A bad-faith conclusion reached lightly is itself reportable; the bar for it is high.
- "A subsequent reporter named the same subject — should we merge?" Don't merge silently. Link the cases; let each reporter's thread stay distinct. Merging removes the separately-protected paths.
Troubleshooting
| Error code | What it means | Fix |
|---|---|---|
REPORT_CONFLICT_OF_INTEREST | You're in the parties list. | Route through the alternate intake (committee or designee). |
REPORT_IDENTITY_UNLOCK_REQUIRES_REASON | You tried to unmask the reporter without a justification. | Provide the documented basis and re-attempt. Unlock is logged. |
REPORT_RETALIATION_WATCH_FLAG | An adverse action against the reporter was detected within the watch window. | Review the action with leadership; the file shows what action + when. |
REPORT_REPORTER_ACCESS_CODE_RESET_REQUESTED | The reporter lost their access code. | The thread surface offers a self-serve reset (their identity stays anonymous through the flow). |
How this is recorded
The intake form, every reporter message, every triage decision, every investigator action, every audit-committee notification — all written to the case ledger. Anonymous reporter identity is stored encrypted with a separately keyed reveal flow; every reveal is itself a ledger row reviewable by the audit committee. Retention follows the longest of the statutory minimum (SOX § 802: 7 years for matters related to financial reporting), the workspace's audit-log retention policy, and any litigation hold attached during the matter.
Related