Table of Contents
Available security measures were put in place to provide public or private access to candidate information when candidate resumes are added to calendar invites.
Configuration
You can configure document and resume security to ensure candidate information is safeguarded from bad actors with the help of a Company/Account Admin with full access to Client Setup or your CS Representative. Please contact them for assistance.
User experience
The user's experience will differ depending on whether they should be authenticated or not.
Without user authentication
If no user authentication is set for the account, then users with access to open and view a candidate’s resume from their Candidate Profile as well as from the interview calendar invitation. Once the interview is completed, then the resume URL expiration timeline set on the account will begin.
With user authentication
If user authentication is set for the account, then the process will differ depending on their account setup and access.
Single sign on (SSO)
If you utilize SSO for your account, then SSO will serve as the authentication method.
Non-SSO
If you do not utilize SSO, the system will check to see if the user has access to the document link.
- If they do have access, and they are not logged in – They will be redirected to the login page. Once logged in, then the document link will open.
- If they do have access, and they are logged in – They will be able to open the document.
-
If they don’t have access, and they are or are not logged in – They will not be able to access the document and a 404 error will display.
- Note: Learn more on 404 error messages here.
Basic/Limited User
If the user is a Basic/Limited User, then the system will utilize multi-factor authentication. This process is as follows:
- Select the resume/document link.
- On the new page that opens, enter in your email address.
- Receive a one-time authentication code.
- Enter this code into the new page.
- Have access to this document (and any additional candidate resumes/documents opened) for one hour for the device you used.
Basic User decline interview experience
When a Basic/Limited User declines an interview, they will receive an email that allows them to make changes to the original interview without multi-factor authentication. In clicking any of these buttons listed within the email, a new page will open where they can complete the necessary actions.
404 error page logic
The 404 error will display:
- If the user is logged into the system but does not have permission to view the candidate or the document.
- If the user is logged into the system but the document does not exist.
Troubleshooting user access
If you find that Basic/Limited Users receive a 404 error page while accessing candidate resumes/documents and the logic listed in the beginning of this section does not apply to your situation, troubleshoot with the following:
-
Enhance viewing permissions. Besides adding Basic/Limited Users to an interview, you can also check the following areas:
- Check to see if the Basic User has access to the necessary locations.
- Work with your CS Representative to change the Basic User’s access for the Candidates permission to View Access OR provide the Basic User Full Access to the Resume permission.
Candidate experience
The following logic will be applied to the candidate experience:
- The candidate will need to verify themselves via the verification page.
- If the candidate is the owner of the document, then the document link will open.
- If the candidate is not the owner of the document, then the document link will open to a 404 error page.
FAQs
How long will Basic/Limited Users have access to a document/resume once they are authenticated?
Currently, it will allow the user to continue to view alternative resumes without re-authenticating for 1 hour.
If you authenticate one resume, will it apply to all resumes for the time session?
Yes, users should not have to authenticate for each interview.
Does this enhancement apply to only new resumes or all resumes?
This pattern only applies to newly uploaded resumes via the conversation after this feature is enabled for your account.
What selections should I make in order for there to be no security restrictions for anyone viewing candidate resumes?
Set the Resume URL Expiration setting to Never and the Resume URL User Authentication to None. This will allow any User, regardless of User Role or SSO status, to view resumes/documents when clicking its resume/document URL.