Open questions
Seven things we cannot settle alone.
These are real rather than rhetorical, and four of the seven block a card in the build list above. If you have an opinion on any of them, that is more useful to us today than agreement with the rest of the page.
| # | Question | Blocks |
| 1 | How many questions, exactly? The cliff is around fifteen and the connector question alone could be twenty items if built carelessly | T1 |
| 2 | Is the connector question one multi-select, or a category then a count? The second is the banding made native, and it may lose people who want to see their own tool named | T1 |
| 3 | What does the guess screen ask? One number, or one number per category | T1 |
| 4 | Who writes the motivated-intruder assessment, and where does it live? It is a short document and it is a precondition for a word | D1 |
| 5 | Does the employer mode need a different instrument, or the same one with a different output? Same instrument is cheaper, and the consent problem does not care | T4 |
| 6 | What is the suppression threshold? Five is the cited standard, and a small early sample will suppress nearly everything | T3 · V2 |
| 7 | Does the shape schema become the published vocabulary, or stay internal until the fifth policy? Publishing early invites correction and locks a shape too soon | T2 |
Honest tensions
And seven we are choosing to live with.
| Tension | Both halves are true |
| banding the submission | It is what makes the data lawful to hold, and it throws away the brand-level detail that would be the most interesting thing to publish |
| computing locally | It is the strongest privacy position available, and it means we learn nothing at all unless somebody presses submit |
| not designing it as a game | The evidence is about completion rather than enjoyment, and the instinct about feel is what will make people start |
| the guess screen | It is the one mechanic with a published argument behind it, and it adds a screen to an instrument whose main lever is fewer screens |
| employer mode | It is a real second product, and it carries an impact assessment, a weak lawful basis, and an intruder who is the buyer |
| self-report | It reaches what telemetry cannot, and no incumbent treats it as legitimate |
| building the schema | It is a genuine gap, and it is the third schema this estate has taken on in a fortnight |
What this page deliberately is not. It is not a schema — the gap is established and the disciplines are named, but no field is defined. It is not a design — question count, ordering and the accumulating picture are constrained by evidence, and nothing is drawn. It is not legal advice. It is not a privacy claim, for the reason in
the section above. And it is not a completion promise: the evidence constrains the design and predicts nothing whatsoever about our numbers.
Written 12 September 2026 from a dev brief of the same date. Sources, all read 12 September 2026 — completion: the progress-indicator meta-analysis of 19 studies and 32 experiments, Villar, Callegaro and Yang 2013, Social Science Computer Review 31(6); the expectation-matching result, Yan, Conrad, Tourangeau and Couper 2011, IJPOR 23(2); the conversational comparison, Kim, Lee and Gweon 2019, CHI; the 2026 field experiment, Cavusoglu Deveci, Fuchs and Metzler, BMS 169-170(1), 6 March 2026; the item-by-item finding, Revilla, Toninelli and Ochoa 2015; the personalised-feedback trial, Kühne and Kroh 2018, SSCR 36(6); vendor completion claims at typeform.com, treated as marketing with no methodology. Schemas: cyclonedx.org, machine-learning component bill of materials v1.7, standardised as an international specification December 2025; the alternative family's profile at spdx.github.io/spdx-spec. Neither describes a deployed configuration. Identifiability: the regulator on effective anonymisation, the singling-out test, the motivated-intruder test and groups of five, at ico.org.uk; Sweeney on postcode, gender and date of birth; Eckersley 2010 on 470,000 browser samples and 83.6% instantaneous uniqueness. Storage and submission: the guidance on storage and access technologies, published 29 April 2026, at ico.org.uk, including the strictly-necessary test assessed from the user's point of view, the statistical-purposes conditions, the objection mechanism that may not be a browser setting, and the statement that the exception is not a broad one covering all analytics. Employment: the regulator on monitoring workers, October 2023 and last updated 16 June 2026, at ico.org.uk. The market: a ten-vendor comparison published 7 September 2026; nudgesecurity.com for the one transparent price found; the free seven-question assessment at aona.ai, which recommends telemetry over self-report. Inside the estate: the capability map and its 23 primitives at what-can-it-do.games.sgit.ai; the belief-before-answer mechanic at games.sgit.ai. The entropy arithmetic in the second section is ours, derived from stated assumptions rather than measured.