calhire
Capability

Identity broker and staged reveal

Anonymous screening only works if someone answers the obvious question: at what point, and on whose say-so, does the employer find out who they are talking to?

A staged identity reveal is a consent-gated release of a candidate’s real identity to one specific employer at a defined point in the hiring process. CalHire acts as identity broker: the employer never holds the candidate’s identifying data during screening, and can request a reveal only at an allowed stage. The candidate consents or declines. Consent releases identity to that employer alone, and every request, consent, decline and disclosure is written to an immutable log both parties can see.

Last reviewed

The short version

  • The employer never holds identity during screening. CalHire does, as broker.
  • A reveal can only be requested at an allowed stage, so it cannot be used as a shortcut around anonymous screening.
  • Consent is per employer. Revealing to one company reveals nothing to any other.
  • Requests, consents, declines and disclosures are all written to an immutable log visible to the candidate.

Why a broker, rather than a setting

Anonymity the employer can switch off is not anonymity. It is a setting. If the identifying data sits in the employer’s tenant behind a permission, then somebody has that permission, somebody else can be granted it, an export contains it, and an admin can read it on a Tuesday for no particular reason. The guarantee is only as strong as the weakest role in the customer’s own access model, which is not a guarantee at all.

So identity lives with CalHire and is released by an explicit, logged act. The employer-facing record is built without identifying attributes, and there is no employer-side permission that reads them, because the data is not in their tenant to read.

This is the same structure that escrow uses, for the same reason. Neither party has to trust the other about the moment of exchange, because neither party controls it.

The four steps of a reveal

  1. 1

    The employer requests

    Only at a stage the platform permits, and typically when they want to move to a human conversation or an offer. The request states which organisation is asking and why, because a candidate deciding whether to identify themselves deserves both facts.

  2. 2

    The candidate decides

    Consent or decline. Declining is a normal, supported action with no penalty attached: the candidate stays in the pipeline as an anonymous participant, and the employer is told the reveal was declined rather than given a reason they were not offered.

  3. 3

    Disclosure happens once, to one party

    Consent releases identity to the requesting organisation only. There is no propagation to a shared pool, a partner, a job board or another tenant. A second employer wanting the same thing has to ask separately.

  4. 4

    The record is written and cannot be altered

    Who asked, when, for which role, what the candidate answered, and what was disclosed. Written to a hash-chained audit trail, exportable by the employer and viewable by the candidate.

What reveal unlocks, and what it does not

  • A named conversation

    Interviews, references and everything else that requires knowing who someone is. Screening is over; this is a normal hiring process from here.

  • Right-to-work checks

    Work authorisation is verified after reveal, which is the correct order. It is a legal requirement attached to a person, not a screening criterion.

  • ATS and HRIS sync

    Identity flows to your systems of record only after reveal. Nothing about an anonymous candidate is ever synced out to a downstream system.

  • Nothing retroactive

    A reveal does not unlock past anonymous activity in other pipelines. What was anonymous stays anonymous, including in your own historical records.

What this changes for a candidate

The most common reason a good candidate does not apply is that their current employer might find out. Confidential job searching is a widespread, entirely reasonable behaviour that most hiring processes treat as somebody else’s problem, and the cost falls hardest on people who cannot afford to be seen looking.

Under a broker model, a candidate can be assessed, ranked, interviewed in text and shortlisted without any employer learning who they are. They find out that they are strong for a role before deciding whether to identify themselves for it. The exposure comes at the point where there is something concrete to weigh, rather than at the point of curiosity.

It also means a decline carries no cost. None at all. A candidate who does not want to proceed with a particular company simply does not consent, and that company never learns which anonymous participant declined them.

What this does not do

It does not stop a candidate identifying themselves. Someone who mentions their employer in a free-text answer has revealed something the flow was designed to protect. Answers are structured to make it uncommon, and candidates are warned, but no system can enforce discretion on a person who wishes to abandon it.

It does not survive re-identification from outside data. A sufficiently unusual combination of skills, market and timing can narrow a field to one person in a small enough industry. The protection is strong in a large market and weaker in a small one, and the honest version of this claim depends on where you hire.

It does not delay compliance obligations indefinitely. Right-to-work checks, nationals-quota reporting and background screening all attach to a real person, and all of them wait for reveal. If your process requires one of them earlier than reveal, the sequence needs designing rather than assuming.

It does not remove bias after the reveal. Everything that happens once the employer knows who they are talking to is subject to the same biases as any other hiring process. The broker protects the screening stage; it does not follow the candidate into the interview room.

Questions people actually ask

Can an employer see identity before the candidate consents?
No. Identifying attributes are not held in the employer tenant, so there is no role, export or admin view that reaches them. Release happens only through a consented disclosure.
What happens if a candidate declines a reveal?
They remain in the pipeline anonymously and nothing is disclosed. The employer sees that the request was declined. The candidate is not required to give a reason and is not penalised for it.
Does revealing to one employer reveal to others?
No. Consent is scoped to the requesting organisation and the role it asked about. Any other employer wanting the same information must request it separately and receive its own consent.
Can a candidate withdraw consent after revealing?
A disclosure that has happened cannot be un-happened, and claiming otherwise would be dishonest. What a candidate retains is the full set of data rights that attach to their record, including access, correction and erasure, all handled through the privacy console.
Is there a record we can show an auditor?
Yes. Every request, consent, decline and disclosure is written to a hash-chained audit trail with actor, timestamp and role, and it exports as evidence.
When is the right stage to request a reveal?
Most teams request it when they are ready to move to a human interview or an offer. Requesting earlier gets more declines, because a candidate weighing exposure against a maybe usually chooses privacy.

Where this connects to the rest of the platform.

  • Anonymous candidate screening

    Employers evaluate candidates with no name, photo, age, school or employer attached, because that information is never sent rather than merely hidden.

  • ATS integration and the public API

    Deep connectors for Workday, Greenhouse, Lever and SAP SuccessFactors, a generic webhook connector, and a REST API. Identity syncs only after a reveal.

  • AI governance, bias auditing and the audit trail

    Adverse-impact analysis on the four-fifths rule, a hash-chained audit trail, candidate appeals, and DSAR handling. The evidence exists before anyone asks for it.

Read the reasoning

The evidence and the argument behind what is on this page.

Fairness7 min read

Name-blind recruitment: the weakest form of blind hiring

Name-blind screening is the most adopted and least effective form of blind hiring. What a name signals, what survives redaction, and what to do instead.

Read
Fairness9 min read

Blind hiring: what the evidence supports, and what it does not

Blind hiring has one of the cleanest natural experiments in labour economics behind it, and real limits. What it fixes, what it cannot, and how to implement it.

Read

Browse all topics on the blog

See a verified pipeline for one of your roles

Post a role free and review anonymous, skill-ranked candidates. No card, no sales call to get started.