Identity broker and staged reveal
Anonymous screening only works if someone answers the obvious question: at what point, and on whose say-so, does the employer find out who they are talking to?
A staged identity reveal is a consent-gated release of a candidate’s real identity to one specific employer at a defined point in the hiring process. CalHire acts as identity broker: the employer never holds the candidate’s identifying data during screening, and can request a reveal only at an allowed stage. The candidate consents or declines. Consent releases identity to that employer alone, and every request, consent, decline and disclosure is written to an immutable log both parties can see.
Last reviewed
The short version
- The employer never holds identity during screening. CalHire does, as broker.
- A reveal can only be requested at an allowed stage, so it cannot be used as a shortcut around anonymous screening.
- Consent is per employer. Revealing to one company reveals nothing to any other.
- Requests, consents, declines and disclosures are all written to an immutable log visible to the candidate.
Why a broker, rather than a setting
Anonymity the employer can switch off is not anonymity. It is a setting. If the identifying data sits in the employer’s tenant behind a permission, then somebody has that permission, somebody else can be granted it, an export contains it, and an admin can read it on a Tuesday for no particular reason. The guarantee is only as strong as the weakest role in the customer’s own access model, which is not a guarantee at all.
So identity lives with CalHire and is released by an explicit, logged act. The employer-facing record is built without identifying attributes, and there is no employer-side permission that reads them, because the data is not in their tenant to read.
This is the same structure that escrow uses, for the same reason. Neither party has to trust the other about the moment of exchange, because neither party controls it.
The four steps of a reveal
- 1
The employer requests
Only at a stage the platform permits, and typically when they want to move to a human conversation or an offer. The request states which organisation is asking and why, because a candidate deciding whether to identify themselves deserves both facts.
- 2
The candidate decides
Consent or decline. Declining is a normal, supported action with no penalty attached: the candidate stays in the pipeline as an anonymous participant, and the employer is told the reveal was declined rather than given a reason they were not offered.
- 3
Disclosure happens once, to one party
Consent releases identity to the requesting organisation only. There is no propagation to a shared pool, a partner, a job board or another tenant. A second employer wanting the same thing has to ask separately.
- 4
The record is written and cannot be altered
Who asked, when, for which role, what the candidate answered, and what was disclosed. Written to a hash-chained audit trail, exportable by the employer and viewable by the candidate.
What reveal unlocks, and what it does not
A named conversation
Interviews, references and everything else that requires knowing who someone is. Screening is over; this is a normal hiring process from here.
Right-to-work checks
Work authorisation is verified after reveal, which is the correct order. It is a legal requirement attached to a person, not a screening criterion.
ATS and HRIS sync
Identity flows to your systems of record only after reveal. Nothing about an anonymous candidate is ever synced out to a downstream system.
Nothing retroactive
A reveal does not unlock past anonymous activity in other pipelines. What was anonymous stays anonymous, including in your own historical records.
What this changes for a candidate
The most common reason a good candidate does not apply is that their current employer might find out. Confidential job searching is a widespread, entirely reasonable behaviour that most hiring processes treat as somebody else’s problem, and the cost falls hardest on people who cannot afford to be seen looking.
Under a broker model, a candidate can be assessed, ranked, interviewed in text and shortlisted without any employer learning who they are. They find out that they are strong for a role before deciding whether to identify themselves for it. The exposure comes at the point where there is something concrete to weigh, rather than at the point of curiosity.
It also means a decline carries no cost. None at all. A candidate who does not want to proceed with a particular company simply does not consent, and that company never learns which anonymous participant declined them.
What this does not do
It does not stop a candidate identifying themselves. Someone who mentions their employer in a free-text answer has revealed something the flow was designed to protect. Answers are structured to make it uncommon, and candidates are warned, but no system can enforce discretion on a person who wishes to abandon it.
It does not survive re-identification from outside data. A sufficiently unusual combination of skills, market and timing can narrow a field to one person in a small enough industry. The protection is strong in a large market and weaker in a small one, and the honest version of this claim depends on where you hire.
It does not delay compliance obligations indefinitely. Right-to-work checks, nationals-quota reporting and background screening all attach to a real person, and all of them wait for reveal. If your process requires one of them earlier than reveal, the sequence needs designing rather than assuming.
It does not remove bias after the reveal. Everything that happens once the employer knows who they are talking to is subject to the same biases as any other hiring process. The broker protects the screening stage; it does not follow the candidate into the interview room.
Questions people actually ask
Can an employer see identity before the candidate consents?
What happens if a candidate declines a reveal?
Does revealing to one employer reveal to others?
Can a candidate withdraw consent after revealing?
Is there a record we can show an auditor?
When is the right stage to request a reveal?
Related
Where this connects to the rest of the platform.
Anonymous candidate screening
Employers evaluate candidates with no name, photo, age, school or employer attached, because that information is never sent rather than merely hidden.
ATS integration and the public API
Deep connectors for Workday, Greenhouse, Lever and SAP SuccessFactors, a generic webhook connector, and a REST API. Identity syncs only after a reveal.
AI governance, bias auditing and the audit trail
Adverse-impact analysis on the four-fifths rule, a hash-chained audit trail, candidate appeals, and DSAR handling. The evidence exists before anyone asks for it.
Read the reasoning
The evidence and the argument behind what is on this page.
Name-blind recruitment: the weakest form of blind hiring
Name-blind screening is the most adopted and least effective form of blind hiring. What a name signals, what survives redaction, and what to do instead.
ReadBlind hiring: what the evidence supports, and what it does not
Blind hiring has one of the cleanest natural experiments in labour economics behind it, and real limits. What it fixes, what it cannot, and how to implement it.
ReadSee a verified pipeline for one of your roles
Post a role free and review anonymous, skill-ranked candidates. No card, no sales call to get started.