Data · Governance · Safeguards

The reading is structured.Its use should be too.

VITALIS™ separates who may see the full record, what the employee receives and what may be retained for research—so each use has a stated purpose and boundary.

See how the data is handled

VS1 brings evidence, dialogue and analysis into one management loop. Its governance must keep different responsibilities apart: the organisation controls access to its identifiable report records; the employee-facing layer concentrates on relevant findings and improvement; and AERTHEIX uses a separately anonymised analytical dataset for benchmark development and research.

This page explains that separation. It does not replace the applicable Privacy Notice, Personal Information Collection Statement, customer agreement or internal employment policy.

  1. Purpose
  2. Access
  3. Lifecycle
  4. Human & AI

The first safeguard is to define why the record exists and who is accountable for each use.

One system · Distinct responsibilities

One record.Different responsibilities.

VITALIS™ is designed to support a defined people-management purpose—not to create an unrestricted personnel record.

The purpose of a deployment should be stated before information is entered. That purpose may include structured talent diagnosis, development planning, coaching direction, role deployment or follow-up against a later reading. Access should then follow that purpose rather than curiosity, seniority or convenience.

  • Role 01
    The participating organisationDefines the authorised use.

    The organisation sets the stated purpose, assigns report permissions and determines which authorised roles may see the complete report. It also sets the retention and deletion period for the identifiable report records held under its licence, subject to applicable law and agreement.

  • Role 02
    Authorised managers and reviewersUse the layer their role requires.

    Access to the complete report is permission-based. A manager, reviewer, HR partner or other authorised role should see only what the organisation has assigned for the stated purpose and remain accountable for how that information is used.

  • Role 03
    The observed employeeReceives an improvement-facing view.

    The employee-facing layer presents the evidence and analysis relevant to development, the areas that may be improved and the next discussion. It also provides a route to add context, correct factual error or preserve disagreement. It is not automatically identical to the organisation's complete analytical report.

  • Role 04
    AERTHEIXMaintains the system and the research boundary.

    AERTHEIX operates the VITALIS™ framework and receives an anonymised analytical version of completed reports for benchmark development and research. The research layer must not contain information from which an individual can reasonably be re-identified.

Access follows purpose—not curiosity or seniority.

Clear roles matter only if the identifiable report and the research dataset remain genuinely separate.

Two data layers · One disclosed flow

The report can be deleted.The anonymous learning can remain.

VS1 separates the organisation's identifiable report layer from the non-identifiable analytical data used by AERTHEIX for benchmark development and research.

  1. Evidence entered for a stated purpose
  2. Organisation's complete report layer
  3. Permission-based access
  4. Employee-facing improvement layer
  5. Analytics separated and anonymised
  6. AERTHEIX benchmark and research dataset

The organisation's report layer

Controlled by the organisation

The participating organisation controls how long its identifiable report records remain available and when they are deleted.

The complete report is available only to roles authorised by the organisation. The organisation may set different access, retention and deletion rules according to deployment purpose, internal policy, agreement and applicable law.

Deleting the organisation's identifiable report removes that customer-controlled record from the applicable operational layer. The exact deletion process, backup treatment and timing must be stated in the relevant agreement and privacy documentation.

The employee-facing layer

Built around improvement

The employee-facing view is designed around improvement rather than unrestricted disclosure of every internal analytical element.

It should show the relevant observations, development analysis and next discussion in language the employee can understand. It should also make the route for factual correction, added context and recorded disagreement clear.

The AERTHEIX research layer

Separated and anonymised

AERTHEIX may retain analytical data on an ongoing basis only after it has been separated and anonymised so that an individual cannot reasonably be re-identified.

When VS1 information is entered, the analytical fields required for benchmark development and research are separated from the organisation's identifiable report layer. Direct identifiers are removed, and combinations such as organisation, role, location, timing and free text must be assessed for re-identification risk before the data is treated as anonymous.

Once an analytical record has been irreversibly anonymised and separated from the identifiable report, it can no longer be traced back to or selectively retrieved for one employee. It may then remain within the AERTHEIX benchmark and research dataset on an ongoing basis.

Removing a name alone is not anonymisation. If an individual can still reasonably be reconstructed from the remaining information, the record remains protected as personal data and must not be treated as permanent anonymous research data.

Boundary

The benchmark and research purpose, recipient categories, separation process and retention approach must be disclosed before collection. Public copy should not claim that data is anonymous until the corresponding technical and operational controls are in place.

Identifiable records follow retention rules. Truly anonymised research data no longer points back to a person.

The same clarity is required when software or AI assists the process.

Current use · Future integration

AI can extend the process.Its role must remain explicit.

VITALIS™ is designed for AI integration, but each AI-enabled use should state whether it is organising data, generating preliminary diagnostic input or supporting human review.

Current operating role

AI organises. The observer decides.

At the present stage, AI assists with organising information rather than independently issuing the VS1 workplace reading.

AI may support transcription, evidence organisation, consistency checks, administrative preparation and the presentation of entered information. The accountable observer remains responsible for the evidence entered, the context attached to it and the current workplace reading.

Future SJT-based integration

Preliminary input, stated at the point of use.

Future VITALIS™ modules may use structured situational judgement interactions to provide preliminary diagnostic input.

An SJT-based module may help structure an initial view before, alongside or between workplace observations. When introduced, its purpose, data use, evidence status, limitations and human-review requirements should be stated at the point of use.

Preliminary AI-supported input should remain distinguishable from evidence confirmed through the applicable VS1 process. Future integration is not excluded; its role should simply be visible and proportionate to the decision context.

AI involvement should be visible at the point of use—not hidden inside the workflow.

Visible roles make it possible to define what a person may review and what no user may do with the record.

Reviewable record · Defined limits

A reading can be reviewed.Its use has limits.

The observed employee should be able to understand the relevant evidence, respond to it and know the purpose for which it is being used.

Employee-facing rights

  • Receive the employee-facing information relevant to development and improvement.
  • Understand the stated purpose of the reading and the route for questions.
  • Add context, request correction of factual error or preserve disagreement.
  • Use the organisation's stated process for access, review or escalation.

Prohibited uses

  • Do not use the record for an undisclosed or incompatible purpose without the required authority, notice or consent.
  • Do not access, disclose or circulate complete-report information outside the organisation's assigned permissions.
  • Do not attempt to re-identify a person from the AERTHEIX benchmark or research dataset.
  • Do not present current AI-supported organisation or future preliminary SJT input as a final, independently confirmed VS1 reading.
  • Do not use a VITALIS™ reading or preliminary AI input as the sole basis for a hiring, promotion or exit decision.

These limits do not remove management accountability. They make the record's purpose, evidence and use more inspectable. The organisation remains responsible for applying its own employment, privacy, access and review procedures.

A review right does not weaken the record. It makes the record more accountable.

Understand the system · Learn to apply it

Begin with the levelyour role requires.

The VITALIS™ Practitioner Pathway is planned for 2027, with separate routes for understanding VS1, applying it and interpreting its deeper analyses.

T0 is the starting point for leaders, HR practitioners and managers who want to understand the system. Those who intend to apply VS1 in practice may begin with T1. T2 develops the report-reading and analytical judgement required after the observation and calibration foundations are in place.

Planned for 2027. Programme sequence, assessment requirements, dates, delivery format and fees remain subject to confirmation. Interested in understanding VITALIS™? Begin with T0. Planning to apply VS1? Ask about the T1 route. An expression of interest is not an enrolment or payment commitment.

Request 2027 Programme Information Contact AERTHEIX

Understand the structure. Learn the evidence discipline. Apply the reading responsibly.