Why anonymous ratings still need structure

Anonymous public ratings are useful only when the system limits easy manipulation without asking honest contributors to publish their identity. Deskbrew uses a narrow question, office-bound submission tokens, rate limits, human verification, pattern review and scoring rules that discount thin samples.

If anyone can rate, why trust the score?

It is the right question to ask. A rating box that anyone can reach is a rating box that anyone can abuse, and plenty of public scores are worth exactly what it cost to move them. The useful question is not whether open contribution can be gamed — it can — but where a system should spend its defences.

Spending them at the entrance is the intuitive answer and the wrong one. Anything placed in front of the rating box is a real cost to every honest contributor and, at most, an inconvenience to someone determined to move their employer's number. It turns away the person who had thirty honest seconds, which is precisely the rating that would have been most representative.

Spend difficulty where it actually costs an attacker

So Deskbrew leaves the rating box open and puts the cost behind it. Before a rating is written, the exact office has to be confirmed against a server-issued token bound to that office, that company, and that contributor. A rating cannot be redirected to a different office after the fact.

Weight then comes from agreement over time rather than from who is rating. No contributor can acquire a standing that makes a single opinion decisive: a score only leaves the neutral prior once enough independent ratings agree, and recent ratings carry more of that weight than old ones.

Rate limits that survive a cleared cookie

Any limit keyed only to a self-issued identity is advisory: the caller discards it and receives a fresh allowance. Limits therefore also apply to a hashed network key, which a script cannot rotate for free.

The address itself is never stored. It is put through a keyed hash, so the system can count repeat behaviour without holding data that identifies anyone — the same reasoning that keeps contributor identity off the public page.

Patterns beat individual judgments

Detecting whether a single rating is sincere is close to impossible. Detecting that one contributor rated four unrelated companies within half an hour is straightforward, and that pattern is far more diagnostic than any individual score.

Ratings that trip such a pattern are retained but held out of scoring pending review, rather than silently deleted. The contributor is not accused of anything; the ranking simply does not move on evidence that has not settled.

Privacy and credibility are the same requirement

These are usually framed as a trade-off: identify contributors to make scores trustworthy, or protect them and accept noise. That framing assumes credibility comes from knowing who spoke.

It comes from the structure of what was asked and how it was counted. A tightly scoped question, a target that cannot be swapped, a weighting scheme that rewards corroboration and recency, and a prior that refuses to be moved by three ratings — none of that requires knowing anyone's name.