Arcoro will be introducing a role-level permission that restricts candidate visibility so that users can only view candidates associated with jobs they are explicitly assigned to. This permission improves data privacy and access control for hiring teams by ensuring users only see candidates relevant to their responsibilities.
Enhancements
New Permission
- Permissions for users will now include the new "View Candidates for Assigned Jobs Only" permission.
- This permission will be independent of other candidate-related permissions and will be disabled by default for existing and newly created roles.
Candidate Visibility Restrictions
- Users with the "View Candidates for Assigned Jobs Only" permission will only be able to view candidates who have applied to jobs they are assigned to.
- The Application History tab shows only jobs the user has access to.
- For multi-job candidates, only job-specific information for assigned jobs is displayed.
- Bookmarked candidates become inaccessible if the user loses job assignments.
Additional Permission Updates
Validation has been added at the role level, so both ‘View All Jobs’ and ‘View Only Jobs They are Assigned to’ cannot be assigned to the same role
- When both roles are enabled, a warning will appear at save: You must either select “View All Jobs” OR “View Only Jobs They are Assigned to” for this role.
Validation has been added so users cannot have both the "Contact Only User" role and another role.
- When the Contact Only User role is selected and another role is selected, both roles are enabled. A warning will appear at Save: If “Contact Only User” is selected, no other role can be selected.
Candidate Pool Management
- Restricted users can add candidates to candidate pools only when assigned to at least one of the candidate's jobs.
- Full-access roles (System Administrator) can add any candidate.
- There will be a clear error message: "You can't add this candidate to a Candidate Pool because you're not assigned to any of their jobs."
System Behavior
- Permission changes take effect when the user logs back into the system.
- Visibility rules are enforced consistently across:
- List views
- Candidate profiles
- Search results
- Reports
- Job dashboards
- Bulk actions
- Activity logs