Loading
Loading
Whole Insights
Written for People teams, People Analytics and anyone running a security or DPIA review of what an employer would actually be able to see.
The tension
An organisation investing in wellbeing needs to know whether it is working, and where support is needed. Without that, the spend is a matter of faith and the next budget conversation has nothing in it.
An employee needs to know their employer is not reading them. Not as a legal assurance, as a working assumption, because a wellbeing tool only receives honest input from someone who believes the honest input is private. A platform that loses that belief does not get worse data. It gets false data, which is worse than none.
Almost everything specific about how Whole reports is a consequence of trying to satisfy both of those at once.
What you get
The list below is what the dashboard actually contains today, not a roadmap. Every figure carries its basis: measured, estimated with the reasoning shown, or marked unavailable where a source is not connected.
The floor
A team with fewer than 5 participants is suppressed entirely. Not rounded, not blended into a neighbouring team, not shown with a wider error bar. Suppressed, and labelled as suppressed.
This matters more than it sounds. Aggregate reporting stops protecting anyone once the group is small enough that a reader can infer the individual, and a five-person team where one person is visibly struggling is not an aggregate. The number lives in the code as a single constant and the check runs before data reaches any dashboard.
The open demo includes a team held back for exactly this reason, so the behaviour is something you can see rather than something we assert.
The boundary
The same table appears on our trust page, generated from the same source, so the two can never drift apart.
| Can they see it? | People admin | Manager | Whole |
|---|---|---|---|
| An individual wellbeing score | No | No | No |
| An individual check-in or reflection | No | No | No |
| Connected wearable or health data | No | No | No |
| Team aggregate, 5 or more participants | Yes | Limited | Yes |
| Team aggregate, under 5 participants | No | No | No |
| Whether a named person is enrolled | Yes | Yes | Yes |
| Whether a named person is active this week | No | No | Yes |
| Names of people meeting the check-in threshold, via an audited requestDuty-of-care path only. See the break-glass conditions below. | Limited | No | Yes |
The exception
An organisation admin can request the names of employees who meet a fixed threshold on their own check-ins: average energy at or below 2.0 and average mood at or below 2.5 over 30 days. It is a deterministic rule applied to self-reported numbers, not a model or a prediction.
An employer with a genuine duty of care needs some way to act, and a system with no path at all invites a worse one outside the product. The design principle is that the path exists, it is narrow, and it is never silent: nobody is looked at without being told.
We publish this because a privacy claim is only worth what its exceptions are worth. A reviewer who finds an undisclosed path stops believing the rest of the page, and they are right to.
Proof
The employer dashboard is public. No account, no form, no call. It runs on a fictional company and includes a suppressed team, so you can check the privacy behaviour yourself in about a minute.
Using it well
Aggregate patterns are useful for deciding where to look and what to try. They can tell you that engagement fell in one part of the organisation after a reorganisation, that the coaching allowance is being used in one function and ignored in another, or that recovery scores are drifting in a quarter you already suspected was heavy.
What they cannot do is establish cause. A dashboard showing a decline is a reason to ask a better question, not an answer. We are not going to tell you that Whole lets you diagnose burnout in a team, because it does not, and any vendor who tells you their dashboard does that is selling you a correlation with a confident voice.
The honest framing: this is instrumentation for a conversation, not a verdict.
Questions
No. The dashboard reports aggregates only, and no cohort of fewer than 5 participants is reported on at all. That floor is a condition in the query layer, so there is no configuration or permission level that turns it off.
A wellbeing index and its trend, participation and engagement rates, sub-scores across Body, Mind and Soul, team-level patterns above the reporting threshold, uptake of the support you fund, and operational baselines such as headcount and retention where you provide them. Each figure is labelled as measured or estimated, and estimates show their reasoning.
No. Managers see less than People admins do, not more, and no individual health or wellbeing data is available to either.
Nothing is reported. A team with fewer than 5 participants is suppressed entirely rather than rounded or blended into a neighbouring team, and the dashboard says it has been suppressed. The open demo includes a suppressed team so you can see the behaviour rather than take our word for it.
One, and it is deliberately narrow. An organisation admin can request the names of employees who meet a fixed threshold on their own check-ins: average energy at or below 2.0 and average mood at or below 2.5 over 30 days. It is a deterministic rule applied to self-reported numbers, not a model or a prediction. It requires a written reason and intended action, returns names and departments only with no scores or health data, expires after 24 hours, is permanently audited, and every person named is notified within the hour of who asked and why.
No. There is no productivity measurement, no activity tracking, no screen or keystroke data, and no individual dashboard for a manager to open. Health sources and calendars are connected by the employee, individually, and can be disconnected without losing the rest of the app.
The security pack is published rather than gated: privacy architecture, sub-processors, data residency, retention, and the certifications we hold alongside the ones we do not.