The Share Reporting Link button on the incidents page produces your organisation's public reporting link.
The public form lives at
/report/[slug]and needs no login.Each anonymous report generates a Report Key (
RPT-XXXXXXXX); the reporter can set an optional password.Reporters can check status at
/report/status, and a worker can later link a report to their account with the Report Key.
Producing your reporting link
Open Incidents → All Incidents (/app/identification/incidents) and select Share Reporting Link. This gives you your organisation's public reporting URL, in the form /report/[slug], where the slug is unique to your tenant.
Share the link wherever your workers will see it:
Onboarding materials.
Posters in shared spaces and break rooms.
Internal communications and intranet pages.
Email signatures for managers.
What the public form does
The link opens an anonymous intake form with the message that no account or login is required. The reporter works through: describe what happened, classify the type and severity, add dates and location, then review and submit. Two safeguards sit on the form:
Bot check: a Cloudflare Turnstile challenge must pass before the form can be submitted.
Consent: privacy and consent text is shown so the reporter knows how their report is handled.
The Report Key
On submission, the reporter is given a Report Key in the format RPT-XXXXXXXX. They can also set an optional password on the report.
The Report Key is the reporter's only handle on their submission. With it, they can:
Check the status of their report at
/report/status(entering the password too, if they set one).Later link the anonymous report to a ReFresh account, from the worker portal, if they choose to identify themselves.
The Report Key cannot be recovered: A Report Key is not tied to an email address or account, so ReFresh cannot look it up or reissue it. Make sure your reporting instructions tell people to save the key somewhere safe, and to set a password, when they submit.
How anonymous reports reach you
An anonymous report arrives in your incidents like any other, and goes through the same triage flow. See Triaging an incident for classifying and routing it, and Reporting an incident (admin view) for the full incident lifecycle. Reports flagged Restrict Access during triage are limited to named people, which matters most for sensitive anonymous reports.
