← Back to the method library
Facilitation (Pronoia)· facilitator, researcher, developer-partner

Anonymity: identity modes and group reporting

Facilitation (Pronoia)

Principle

The core of the Delphi method is to reduce social-conformity pressure and dominance through (semi-)anonymity. In Pronoia, panelists are strictly anonymous to one another yet identifiable through a pseudonym, so that in dialogue a participant recognises the same conversation partner as the same person. Anonymity protects honest judgement; it must not break accidentally through small groups, AI participants, or comparisons.

Group-level reporting runs along the panel matrix — the expertise (primary) and stakeholder (secondary) axes — rather than a single legacy grouping. The same k≥3 protection applies to every axis and to the panel-pulse group dots.

Three identity modes (per-panel setting)

A. Pseudonymous (default)

A stable word handle per panelist (e.g. Aurora, Vega) — memorable and distinctive, giving no hint of identity or status, stable for the whole study. Real identity sits only behind the invite link (invite token). Full functionality: Home, dialogue, revisions, recognition, arena.

B. Role play (optional layer on top of A)

The panelist writes a role or perspective they answer from (e.g. Municipal finance director in 2035) and places it in a box of the panel matrix. Off by default. The division of work is clear: the facilitator owns the structure – the axes and categories of the panel matrix – and the panelist chooses the box their role fits best.

C. Fully anonymous one-shot poll

No identity, a single response – a seminar or mobile poll the facilitator shares as a QR code or link. No sign-in, own page, arena, revisions, recognition or persistent handle. Voters answer the theses and may write a short reason; the writer is never named. Each submission is stored as an anonymous participant who does not appear on the panel roster or in group comparison, and the answers go into the round's results and distribution like any other answers.

The duplicate-vote guard is per browser: the same browser answers once. It stops accidental repeats but not deliberate ones – another browser or a private window can answer again. The one-shot poll therefore suits taking the temperature of a room, not a vote whose outcome is binding.

Cross-cutting rules (always on, in every mode)

AI is always disclosed. Every AI panelist is marked with "AI" plus a short role description, 2–3 words (e.g. AI · Economist, AI · Labour Researcher). Shown everywhere an AI panelist appears: dialogue arguments and comments, panel lists, pulse group labels, reports. Never hidden, never presented as human.

k-anonymity (k = 3) across all group-level views. No sub-group with fewer than three people is reported at group level — comparisons, sentiment and panel-pulse group dots included — and the rule applies independently on each matrix axis. Complementary protection: when a group falls below the threshold it is folded (into an "Other" group) until every cell has at least three; if "Other" is still below three, the breakdown is not shown at all. Panelists with no value on an axis are excluded from that axis — they never form a residual bucket. The same threshold applies to cross-tabulations (group × thesis): a numeric cell is hidden when n < 3. On small panels the facilitator is steered to a 2–3 group split; anonymity wins. In the extreme, the pulse is shown at whole-panel level only.

Visibility & the after-submit reveal. Per-round phase policy controls when a panelist sees others. The default classic preset uses after-submit for the response phase: no anchoring before you commit your own answer, but once submitted the panelist sees others' anonymized responses and the aggregate graph. Strict blind remains available in the facilitator policy editor. All revealed material stays pseudonymous and k≥3-protected; the reveal changes timing, not the identity rules.

What is available in each mode

Feature A Pseudonymous B Role-play C Fully anonymous
Persistent handle yes yes no
Recognisable in dialogue yes yes no (nameless)
Home / arena / recognition yes yes no
Revisions yes yes no (one-shot)
Commenting yes yes yes, anonymous (moderated)
Self-selected role in a box no yes (marked) no
AI labelling (if any AI) always always always
k≥3 group reporting (both axes) always always always
Facilitator sees person yes* yes* no (no identity)

*Unless blind-facilitator mode is enabled.

By default the facilitator sees real identities (for reminders and quality control); a per-panel blind-facilitator mode hides them, so the facilitator also sees only pseudonyms (the invite mapping still exists in the database).

Group comparison — current behaviour

In practice: role play and the one-shot poll

Each has its own working guide:

Data model (implemented) — for the developer-partner


Source: Pronoia — Anonymity Design (Metodix, June 2026, status: implemented).