One Response Per Person: Why Browser-Based Limits Aren't Enough
The "one response per person" option in most form builders relies on a cookie — and is defeated by an incognito window.
When you run a workplace survey and want each employee to respond only once, there's usually an option called "one response per person." But how does that option decide who "a person" is?
The common method: cookies and browser fingerprints
After submission, a cookie is set in the browser, and next time, if the same cookie is present, the form is closed. Sometimes a browser fingerprint (a combination of settings, fonts, screen resolution) is added on top.
Its problems:
- An incognito window has no cookie.
- A different browser or a second phone has a different cookie.
- Clearing browser data removes the limit.
- And the reverse: in an organization where several people share one computer, the second person is unfairly blocked.
The robust method: an identity key
Instead of the browser, rely on something the person enters themselves: an employee ID, a national ID number, a work email or a mobile number.
Each value can submit exactly one response, regardless of which device it came from.
The critical detail: normalization
"۱۰۰۲" typed in Persian digits and "1002" in Latin digits have to count as the same person. If they don't, the first person who wants to answer twice will try exactly that. The same goes for stray spaces, and for upper and lower case in email addresses.
The second detail: the guarantee has to be in the database
If the application checks "does this ID already exist?" before saving, two people who submit at exactly the same moment both get "no" and both get saved. The real guarantee is a uniqueness constraint in the database itself.
You don't lose anonymity
The fair question that comes up: if I collect an employee ID, it's no longer anonymous.
The employee ID doesn't need to appear in the reports. You can keep it purely as a uniqueness key and strip it from all reporting. If the sensitivity is high, you can keep only a cryptographic hash of it — enough to detect a repeat, but impossible to turn back into the original ID.
Tell employees this too; otherwise the mere sight of an employee ID field makes them answer cautiously.
The third method: single-use invitations
Send each person a unique link that burns after one use. It's the strongest method and requires no identity entry at all — but it does require having everyone's email address or mobile number.