A hiring manager opens the same product an admin does and sees a smaller, different thing. That boundary holds on its own, so there's nothing for you to police by hand and nothing to leak by accident.
Roles are set when you invite someone and can be changed later without disturbing their open work.
An admin sees the whole account. A recruiting manager sees their team. A recruiter sees every job they run. A hiring manager sees only their own open roles, and nothing outside them.
This isn't a case of hiding a few buttons and hoping. Someone who shouldn't see a candidate genuinely can't reach them, however they go looking, and a download never quietly contains people they were never meant to have.
A vendor sees the candidates it sent you and nothing else. You can scope a vendor to particular countries and pause it whenever you like. Vendors are never deleted outright, so the submissions and answers they've already given you survive.
Anyone can turn on two-factor authentication and see the devices currently signed in, from one security page.
Removing someone can't quietly orphan a role.
Take a teammate off the account and you're asked where their jobs go first. You also can't remove the last admin, so an account never ends up with nobody who can run it.
Opening a candidate is itself recorded.
Reading someone's application leaves a trace, alongside the record of who was invited, removed or reassigned. If it's ever asked who saw a candidate's file, that has an answer.
We don't offer SAML single sign-on yet.
Signing in with an existing Google or Microsoft account works today. If your security review needs full SAML, tell us before you buy rather than after.
Free to try. No credit card, and no credit spent until you ask for work.