Recruitment work, candidate records and actions assigned to the role
Security and governance
Control access to people data.
Set role-based access, retention workflows and audit records across Hire, Onboard and Grow.
- HR administratorConfigured organisation and product administration
- RecruiterCandidate pipelines, communication and recruitment work
- Hiring managerRelevant jobs and associated hiring work
Accounts and permissions
Create an account for a specific job.
Give employees, managers, recruiters, HR and external affiliates access to the products, tasks, records and actions they need. Nothing else is included by default.
Create access for the work, not the whole platform.
The administration, employee journeys or learning work they own
Only the specific tasks, records and actions needed for the engagement
Exact permission names and product access follow the organisation's configuration and package.
Governed lifecycle handoff
Carry context forward without opening every record.
An accepted candidate can move into the employee handoff while recruitment work retains its own purpose and access boundary. Relevant context supports the next stage without turning the complete recruitment history into a general employee record.
Candidate data lifecycle
Configure retention and respond to candidate choices.
Hire supports organisation-configured retention periods, automatic deletion, extension requests, anonymisation and controlled deletion workflows. Candidates can withdraw through their application confirmation email, while talent-pool consent remains a separate choice.
- Application receivedOrganisation retention period applies
- Lifecycle reviewExtension request, anonymisation or controlled deletion
- Workflow recordedCompletion follows the configured process
These controls support the organisation's privacy process. They do not determine its legal basis, retention policy or regulatory obligations.
Audit evidence
Give legal, security and IT something they can examine.
Every sign-in, access event and data action enters the managed audit history. Workflow evidence stays attached to the record that produced it.
Trace a document through its signing route.
Where the selected signing method supplies the evidence, document records can identify:
- Actor
- Purpose
- Timestamp
- Location evidence
- Document version
- File hash
- Event identifier
- Signing-method identity evidence
Reconstruct who reached what.
Every sign-in, access event, data read, data change, permission grant and privileged support session is recorded in the managed audit history.
Keep revisions attached to the workflow.
Structured recruitment feedback includes auditable revisions and conflict handling, so reviewers can examine changes within the relevant hiring record.
Review technical access separately.
Scoped API keys, rotation, limits and usage logs are available according to package. API evidence remains distinct from human activity in Hire, Onboard and Grow.
Support independent customer review.
The DPA provides customer audit rights, normally once per calendar year with 60 days' notice. Law or a personal data breach can justify a different frequency.
Complete activity history, controlled visibility.
Audit visibility, retention and export requirements are configured for the relevant product area, package and agreement.
Document governance
Keep document work attached to the right context.
Hire supports scoped templates, PDF generation, secure delivery and view tracking. Onboard keeps file activity connected to the employee journey. Availability depends on package.
Scope templates before they are used.
Apply company, department, team or job scope. Editable defaults and concept watermarks help distinguish working documents from finished output.
Keep delivery evidence with the document.
Secure delivery, viewed states and signing evidence remain attached to the relevant document workflow.
Identity and data location
Set access and jurisdiction by organisation structure.
Use temporary one-time magic links or package-dependent SSO. Organisations with multiple entities can select a separate server and data-storage jurisdiction for each entity.
Identity options
- Temporary one-time magic links
- Google and Microsoft 365 SSO
- SAML 2.0 SSO
- Identity-provider MFA where configured
Tailored Scale implementations can include multi-tenant SSO within the agreed scope.
Export and deletion
Standard exports include commonly used formats such as CSV and JSON. Uploaded files can be delivered as a compressed archive. Standard deletion after service termination is 30 days, unless the controlling agreement sets a 60-day or 90-day migration period.
Entity-level data residency
Each entity can select its own jurisdiction. Its application servers, stored data and backups remain within that selected jurisdiction. Backup retention and recovery terms depend on package and agreement.
Product controls and platform security
Governance sits on a documented security baseline.
Product controls operate alongside encrypted traffic and storage, restricted production access, centralised logging, monitoring, vulnerability scanning, security-focused code review, encrypted backups and a documented incident response process.
Map CapoFine controls to your requirements.
Bring your access model, retention requirements and review process. We will show the relevant controls, identify package-dependent options and separate product configuration from contractual commitments.