Speak Up
1. What it is
Speak Up is a protected-disclosure channel: a way for someone to report serious
wrongdoing — fraud, harassment, discrimination, safety or data-protection
failures — and be sure the report reaches a named, impartial person rather than
their own manager. It is built around the EU Whistleblowing Directive
(2019/1937) and its national transpositions, so it runs two statutory clocks,
keeps a register an auditor can read, and accepts reports from people who no
longer work for you.
Reports go to a designated adviser panel that you choose. Reporters can file
anonymously, confidentially, or openly, and an anonymous reporter keeps a
one-time reference code that opens a two-way thread — the panel asks follow-up
questions, the reporter answers, and no identity is ever stored.
- Enablement: Speak Up requires a licence and is off by default. A business
administrator enables it from the Apps Marketplace, then designates the
adviser panel. It does nothing until both are done. - What it is not: it is not an app administrators read by default. There
is no administrator screen that opens a case — business admins configure the
channel (the panel, the clocks, retention) and that is all the role gives
them. This is deliberate and it is the point of the app: the plausible subject
of a protected disclosure is an administrator, so the usual
admin-sees-everything rule is inverted here (Directive Art. 9(1)(c)). The
honest caveat, set out in §3: designating the panel is itself an administrator
setting, and the panel can grant a named person into a single case — so the
control is accountability (every grant and every case-body read is recorded),
not impossibility. It is also not the anonymous-feedback channel in Surveys,
which is a pulse tool with no legal clock, no register and no retention rule.
2. Standing it up
Three things must all be true before a single report can be filed. Doing two of
them looks identical to doing all three from inside the app.
- Enable the app. Go to Apps → Marketplace → Speak Up and enable it for
your business. A licence is required. - Create the group that will be your adviser panel. Go to
Admin → Notification Recipient Groups and create a group containing the
people who will read disclosures — typically two to five: a compliance lead,
an HR director, sometimes an external counsel account. Add the people to it. - Designate that group as the panel. Go to Apps → Speak Up → Settings
and choose it under Adviser Panel. Only a business administrator can set
or change this — a delegated app administrator can open Settings but the
panel control is read-only for them, because designating the panel is the
same act as granting access to every disclosure. - Publish the app to your employees. Enabling an app and publishing it to
non-administrators are separate switches. Until it is published, every
non-admin employee is refused — the app will look completely configured to
you and be invisible to them. - Confirm it worked. Open Apps → Speak Up. You should see the intake
form. If you see a “not accepting reports” page instead, the panel has not
resolved — see the pairing note below.
The pairing that silently blocks everything: the app being enabled is not
enough. With no panel designated, every intake surface — in-app, mobile and the
public portal — returns a “not ready” page and refuses reports. You will also
receive an email telling you which of the four states you are in and what to do
about it. Two of those states are easy to hit by accident:
- The group you chose has no members. Add people to it; do not pick a
different group. - The group you chose is too large. A group covering most of the company is
refused, because reports are readable only by the panel and a panel that is
most of the workforce is not a confidential channel. Groups that cannot be
used are marked too large to be a panel in the Settings dropdown. Note that
the broad system groups — All Employees, All Staff, Full-Time Employees — sort
to the top of that list and are all too large. Choose a narrower group.
To accept reports from outside the company — ex-employees, contractors,
suppliers and applicants, which the Directive requires — turn on the Speak Up
public portal from the tenant’s portal catalogue. That publishes an
unauthenticated reporting page on your own tenant domain. It is always
anonymous-only, whatever reporting modes you allow internally.
3. How it fits together
The adviser panel is the whole access model. Panel membership is what grants
the ability to see the case list, open a disclosure, message a reporter,
acknowledge, investigate and close. It is a Notification Recipient Group, so it
is not tied to any platform role — a panel member is very often an ordinary
employee, and an administrator is not a panel member unless you put them in the
group. Changing the group changes who can read every disclosure in the tenant,
which is why only business administrators can do it.
Per-case grants are the exception that keeps the panel small. When one case
needs a specialist — a fraud disclosure needing someone from Finance — a panel
member grants that person access to that one case. Grants carry an expiry, are
revocable at any time, and every grant and revocation is recorded. A grantee sees
the single case they were granted, never the case list.
Recusal is how the panel handles a disclosure about one of its own members.
An adviser recuses themselves from a case; they immediately lose access to it and
stop being alerted about it. The last remaining adviser cannot recuse — a case
must always have somewhere to go. A disclosure naming the entire panel has no
destination today; if that is a real risk for your organisation, keep an
alternative channel documented outside the product.
The two statutory clocks run automatically from the moment a report is filed.
Acknowledgement is due within 7 days (Art. 9(1)(b)); feedback to the reporter is
due within 3 months (Art. 9(1)(f)) and starts when the case is acknowledged.
Both are configurable downwards only — the defaults are the Directive’s
ceilings and the app will not accept a longer window. Breaches raise a panel
alert and mark the case red on the panel’s list and on the register.
The register and retention are one mechanism. Closing a case starts its
retention clock. When that expires, an overnight job purges the disclosure —
the report body, the message thread and any evidence are destroyed — while
keeping the minimal register row an auditor needs: reference, category, dates,
status and closure reason. Deleting the row would destroy the Article 18
register; keeping the content would breach retention. The purge is irreversible
and it records itself on the case’s audit trail.
The Safety Hub boundary. A psychosocial case can be referred into Safety Hub
as an incident, so psychosocial and physical safety share one corrective-action
register. Nothing identifying crosses that boundary — the incident carries no
reporter, no reference code and no case body. Referral is a one-way, terminal
step: a referred case is read-only afterwards.
4. Running it
Everything below is done by a panel member, not by an administrator.
Working a new disclosure
- Open Apps → Speak Up → Cases. New and overdue cases are marked.
- Open the case and read it. Every read of a case body is itself recorded on
the audit trail — including yours. - Acknowledge it. This is the Art. 9(1)(b) obligation and it starts the
feedback clock. - Start investigation when you begin work, then use the message thread to
ask the reporter follow-up questions. An anonymous reporter can answer
without ever identifying themselves. - Close the case with a closure reason and the feedback the reporter
receives. Closing starts the retention clock.
Bringing in a specialist
- On the case, add a grant naming the person and an expiry.
- They reach that case from their own Speak Up view — they never gain the case
list. - Revoke the grant when their work is done. Both actions are on the record.
Handling a retaliation claim
A reporter whose treatment changes after speaking up can flag retaliation on the
open case. The panel is re-alerted on a recurring cadence until the case closes.
Flagged cases are filterable on the register.
Producing the register for an auditor
- Open Apps → Speak Up → Register.
- Filter by date window, status, category, retention state or retaliation flag.
- Export to CSV. By default the export asks you to verify your identity again
at that moment rather than trusting an old session, because the register is
the one artefact that outlives the case content. Sample rows loaded for demo
purposes are labelled as such, on screen and in the export.
5. Settings
All at Apps → Speak Up → Settings. Every setting here has a real runtime
consumer.
| Setting | Default | What it changes |
|---|---|---|
| Adviser Panel | (none) | The group whose members can read and work every disclosure. Until it is set and resolvable, no surface accepts reports. Business administrators only. |
| Allowed Reporting Modes | Anonymous, Confidential, Open | Which modes the in-app and mobile intake forms offer. The public portal is always anonymous-only regardless of this. |
| Acknowledgement Window (days) | 7 | When acknowledgement falls due, Art. 9(1)(b). 7 is the Directive ceiling; lower values are accepted, higher ones are not. |
| Feedback Window (days) | 90 | When feedback to the reporter falls due, Art. 9(1)(f), counted from acknowledgement. 90 is the Directive ceiling. |
| Retention After Closure (months) | 60 | How long a closed case keeps its content before the overnight purge destroys it. Sixty months is common practice, not a legal determination — confirm the right value for your jurisdictions with counsel. |
| Require Identity Verification to Export the Register | On | Whether exporting the register requires re-verifying identity at that moment. On by default; a whistleblowing register export is sensitive by construction, so tenants opt out rather than in. |
| Open a Safety Hub Incident When a Case Is Referred | On | Whether referring a case also opens an anonymous Safety Hub incident. Off means referral only marks the case referred. |
Two controls that are deliberately not here: the public portal switch, which
lives in the tenant’s portal catalogue so that one control governs every public
portal; and any AI setting, because Speak Up registers no AI assistant. Case
content is excluded from the assistant, from search indexing and from
embeddings — an assistant would need a standing read path across every case,
which is exactly the access this app exists to deny.
Public intake is rate-limited per IP address, and reference-code lookups
separately so. Sample data can be loaded and removed from this same Settings
page.
6. More help
- Safety Hub Overview — the incident and corrective-action register that
referred cases feed into - Surveys Overview — anonymous pulse feedback, and where the boundary with
Speak Up sits - Ask AI — the assistant answers configuration questions about Speak Up from
these articles. It cannot read disclosures.