Disclosure controls
These controls are part of the product, not a setting page. Changing the minimum cell size visibly changes what the charts are allowed to show.
Participation over time
synthetic · aggregateDistinct participants recorded per month, plus sessions run. Counts are club-level; no participant identity is retained beyond a per-club roster row.
Local projects by type
Service projects logged by an adult lead. Location granularity is region only.
Completions by track and age band
Suppression activeThis is the chart most likely to leak: small cells at the edges of age bands can identify a specific club or a specific young person. Cells below the minimum size are withheld, not rounded, not estimated.
| Track | Age band | Published value | State | Reason |
|---|
Individual-record probe
Proof surfaceTurn the probe on and try to reach a child. The store this page queries contains aggregate cells only — there is no child table to join against, so the lookup cannot be satisfied even by an administrator.
Schema exposed to this page: month, region, track, age_band, count. There is no participant identifier, no name field, no free text and no story reference anywhere in it.
What this app refuses to do
- No child ranking. No score, percentile, leaderboard, "most improved" list or cross-club comparison of young people.
- No sensitive stories. Sealed submissions are excluded from every count. There is no theme breakdown of disclosures, because that is itself identifying.
- No small cells. Values below the minimum cell size are withheld with a visible marker and a stated reason.
- No drill-through. Charts do not link to a person, a club roster or a story record.
- No location pins. Region codes only; a club never resolves to an address.
- No silent exports. Every export is logged in the Leader Console audit trail with scope and requester.
Reading the suppression marker
A hatched bar with an n<min tag means the value exists in the private store but is not publishable at the current minimum cell size. Increasing the minimum hides more; setting it to 0 is possible in this prototype only to demonstrate the difference and is labelled unsafe.