Why the safest place for a complaint is not a trusted inbox

There is one objection we hear in almost every implementation conversation with either the HR or the Legal teams, and it comes up early. These cases are too sensitive to put in a system. They are safer with one trusted person. We understand the instinct entirely. It comes from the right place. Sexual harassment complaints…

PoSH Simplified β€’ July 22, 2026 β€’ 7 views β€’ By Ungender Team

There is one objection we hear in almost every implementation conversation with either the HR or the Legal teams, and it comes up early.

These cases are too sensitive to put in a system. They are safer with one trusted person.

We understand the instinct entirely. It comes from the right place. Sexual harassment complaints are among the most sensitive documents an organisation will ever hold, and the reflex to keep them close, in few hands, with someone you trust, is a protective one.

It is also, almost always, wrong. And the reason it is wrong is worth setting out carefully, because it is not obvious, and because getting it wrong has consequences that fall hardest on the person who came forward.

What is actually happening while you are trusting

Picture a live inquiry, six weeks in.

The complaint arrived by email. It went to the HR lead, who forwarded it to the presiding officer of the Internal Committee. She read it on her laptop, then again on her phone on the way home. The external member needed a copy, so it was forwarded again. A witness statement was shared with a colleague for a second opinion on how to phrase a question. The draft report went to legal for review. Someone worked on the file over a weekend and, for convenience, emailed it to a personal account.

Not one of those steps was malicious. Most of them were conscientious. Every one of them was a person trying to do the inquiry properly.

Now ask the room a simple question.

Who has read this?

Nobody can answer. Not because anyone did anything wrong, but because nothing was ever built to keep count. The complaint now exists as an unknown number of copies, on an unknown number of devices, in the possession of an unknown number of people, and there is no instrument anywhere in the organisation that could reconstruct the list.

That is not confidentiality.

That is an absence of tracking, mistaken for discretion.

The distinction the law actually draws

Section 16 of the POSH Act prohibits the publication or making known of the contents of a complaint, the identity and addresses of the complainant, respondent and witnesses, the conciliation and inquiry proceedings, and the recommendations and action taken. Section 17 provides for a penalty where that prohibition is breached.

Read that list again and notice what it protects. Not the organisation’s reputation. The identities and the proceedings. It exists to protect the people inside the file.

Now notice what the law does not say. It does not say the file must be held by one trusted person. It does not say confidentiality is achieved by keeping the circle small. It imposes an obligation on the employer, and an obligation is a thing you must be able to discharge β€” and, if challenged, demonstrate that you discharged.

Here is the uncomfortable question that follows. If a breach occurred, would you know? If someone in your organisation forwarded a complaint to a person who had no business reading it, or discussed its contents with a colleague, or took a copy when they left β€” could you establish that? Could you even establish who had legitimate access in the first place?

For most organisations we work with, the honest answer at the start is no.

An obligation you cannot evidence is an obligation you are meeting by hope.

The Digital Personal Data Protection Act adds obligations that most POSH conversations have not yet absorbed. Complaint files contain personal data of a highly sensitive nature, held by the employer as a data fiduciary, with duties around purpose limitation, security safeguards, retention, and breach notification. A complaint sitting in three personal inboxes and an unmanaged laptop is difficult to reconcile with any of those duties.

Confidentiality is not a behaviour. It is an architecture.

This is the reframe that changes the conversation, and once an organisation sees it, the objection tends to dissolve.

When people say “we keep these cases confidential,” they are describing a behaviour: a set of intentions held by careful people. Behaviours degrade. People get busy. Someone travels and works from a personal device. Someone leaves. Someone forwards a file in good faith to a colleague who genuinely needs it, and that colleague forwards it to someone who does not.

Confidentiality as an architecture means something entirely different. It means the properties hold whether or not anyone is being careful today.

Access is role-based, and scoped to the matter. The committee inquiring into a complaint can open that complaint. Nobody else in the organisation can. Not other committees. Not HR colleagues who are not on the matter. Not a manager who is curious. Not a director. The circle is defined by role and by matter, not by seniority or by who happens to be trusted.

Every access is logged. Who opened the file, and when. Not because anyone is presumed guilty, but because a duty you can evidence is a duty you can defend β€” and because the existence of a log changes behaviour before it is ever read.

Nothing needs to be forwarded, because nothing needs to leave. This is the quiet one, and it is the most important. Files get forwarded because the work has to happen somewhere, and if the system cannot support the work, the work moves to email. Give a committee somewhere to actually conduct the inquiry β€” to record statements, share drafts within the committee, prepare the report β€” and the reason to email a copy to yourself simply stops existing.

The record survives the people. When the HR lead who has been carrying the program leaves, the file does not leave with her, and neither does the history of who touched it.

Aggregate and file are separated by design. The employer can see the picture it is accountable for β€” how many matters are open, how many are past timeline, where they are concentrated β€” without any individual file becoming readable. Oversight and access are different things, and a well-built system treats them as different things.

Trust is not a control. It is what you rely on when you have no controls.

The trusted person is a risk, not a safeguard

We want to say this plainly, because it is uncomfortable and it is true.

In most large organisations, POSH knowledge lives in one person. She is usually in HR or Legal. She knows which matters are open, what was promised to which complainant, and why the case from two years ago closed the way it did. She is conscientious, and she is often the reason the program works at all.

She is also a single point of failure, and the organisation has made her one without ever deciding to.

If she leaves, institutional memory leaves. If she is unwell, matters stall. If she is asked in an inquiry what access controls existed, the honest answer is that she was the access control. And if someone else in the organisation has been reading files they should not have been, she has no way of knowing.

Enterprises tolerate single points of failure in almost no other governance function. Financial controls are not held in one person’s judgment. Access to production systems is not governed by whether someone seems trustworthy. We do not ask the finance team to remember who has seen the ledger.

Harassment is not the place to make the exception. It is the place where the consequences of the exception fall on someone who already came forward at cost.

The part that surprises people

Organisations come into this conversation assuming a trade-off: that putting POSH on a system means loosening confidentiality in exchange for efficiency and oversight.

The opposite is true. A properly built system produces more confidentiality and more oversight at the same time, because it separates the two things that email fuses together.

In an email-run program, seeing anything means seeing everything. The only way for leadership to know how many matters are open is for someone to go and look through the files. The only way to check whether a matter has crossed 90 days is to open it. Visibility and access are the same act, so organisations resolve the tension by choosing blindness β€” and then discover, when something goes wrong, that they were blind and leaky at the same time.

A system built for this does not force that choice. The committee sees its matter, fully. The employer sees the shape of the whole, and never the contents. Everyone else sees nothing, and every one of those boundaries can be evidenced.

That is not a compromise between confidentiality and oversight. It is what makes both of them real.

What we would ask you to check

Not to buy anything. To find out where you stand.

One. Take your most recent complaint file. Produce a list of every person who has read it. Note whether you can, and how long it takes. That is your confidentiality posture, measured.

Two. Ask who in your organisation could open a POSH file today if they wanted to. Not who would. Who could. Include IT. Include anyone with access to the shared drive, the email archive, or the departing employee’s laptop.

Three. Ask what happens to the file when the person holding it leaves. If the answer involves a handover conversation, you do not have a record. You have an oral tradition.

Four. Ask whether your Internal Committee has anywhere to actually work. If it does not, it is working in email, and every forwarded attachment is a copy you will never be able to account for.

The claim, stated plainly

The safest place for a complaint is not a trusted inbox.

It is a system that can prove who opened it, and when.

Not because the people in your organisation are untrustworthy. Because the woman who came forward deserves better than an assurance, and because a duty you cannot evidence is a duty you cannot demonstrate you discharged.

If you were asked today to produce a list of every person who has read your most recent complaint file, could you?


Ungender has spent more than a decade in POSH advisory, inquiry, and Internal Committee work. Conduct is our case management and compliance platform: role-based access scoped to the matter, a full audit trail on every file, and an aggregate view for the employer that never exposes a single complaint.

Read more about Conduct β†’