Anonymisation concept in decídalo
When a user's permission profile restricts the visibility of certain people, decídalo applies anonymisation. Affected individuals are not removed from the application. They are shown in anonymised form, for example as Anonymous. This keeps the application usable while still protecting the identity of people the user is not (yet) permitted to see.
This page explains when anonymisation applies, why search results and candidate lists stay complete, when a person's identity becomes visible again, and how CV anonymisation is controlled separately.
How anonymisation works
If your permission profile does not allow you to see a particular person's full profile, that person is displayed anonymised throughout the areas where their identity is not required. Instead of a name, you see a neutral placeholder such as Anonymous.
Anonymisation hides the identity of a person, not the information that is relevant for your work. Skills, availability and other professional attributes can still be shown so that the application remains useful.
Search results and candidate lists
Search results and the candidate list of a resource request remain available even when the people in them are anonymised. This is intentional: relevant skills and availability can still be identified, even when a person's name is not yet visible.
- Skills remain discoverable. You can still see that the relevant expertise exists and request the right person, even if the name is not visible yet.
- Consistent results. Anonymised entries prevent result lists from appearing incomplete or unexpectedly short. The list you see is complete and understandable rather than artificially reduced.
This means a restricted user can still build a shortlist for a resource request based on what people can do and when they are available, and request access or staffing without first needing to see who they are.
Scope of "Profile View = Own"
The permission setting Profile View = Own should not be interpreted as a global rule that hides every other person's name throughout the application.
Instead, it primarily controls whose full profile you are allowed to open and view. In several functional areas, names may still be displayed where this is required for collaboration or operational processes. Seeing a name in one of these areas is expected behaviour, not a permission error.
Note: For the full list of profile-related permissions and their values, see the Permission concept.
When anonymisation is lifted
Anonymisation is lifted for specific individuals when there is a legitimate business context to show their identity. This follows the need-to-know principle: a person becomes visible by name only where their visibility is actually required, while all other restricted users stay anonymised.
Typical situations where anonymisation is lifted for a person include:
- Two users are assigned to the same project.
- Project-related permissions make a person's visibility necessary for collaboration, coordination, or staffing-related activities.
In these cases the affected person becomes visible by name, while every other restricted user remains anonymised.
CV generation and download
Profile view permissions and CV view or download permissions are controlled separately. The right to open or view a person's profile does not automatically determine whether you may view, generate, or download that person's CV.
CV templates can be explicitly marked as anonymised and are then made available accordingly:
- A user who is only permitted to generate anonymised CVs can use only anonymised templates.
- Such a user can view only CVs that were generated with an anonymised template.
As a result, a user restricted to anonymised CV output cannot reveal identifying information through non-anonymised templates or documents.
Note: The related permissions (View anonymous CVs, Create anonymous CVs, and Create non-anonymous CVs) are described in the Permission concept. Make sure anonymised CV templates are provided before assigning anonymised-only CV permissions.