The client sponsor changed jobs in March. Their portal account still opens six confidential searches in August. Nobody behaved maliciously. Nobody reviewed the guest list either. That is how access risk usually arrives: quietly, under a familiar name.
How should a recruitment agency review client-portal access?
Review access per named person and mandate: verify identity, employer, role, business need, data scope, download rights, last activity, expiry and the client owner who re-approved access. Remove obsolete accounts immediately and investigate unexpected use.
Do not treat every employee at a client as one trusted audience. A board search, succession project and volume-hiring assignment have different stakeholders and confidentiality risks. Least privilege means each person sees only what they need for the work they are currently doing.
The EDPB advises differentiated authorisation profiles, removal of obsolete permissions and regular reviews. Recruitment portals need the same discipline, including for external guests who never appear in the agency’s staff offboarding process.
Inventory people, service accounts and shared links
A reliable review begins with every route into candidate information, not only the visible user list.
Export named client users, agency users, administrators, support access, API credentials and active invitation links. Include accounts that have never logged in. A dormant invitation sent to a former assistant can be as risky as a dormant account, particularly if it has no expiry.
Look for generic addresses such as hiring@, boardsearch@ or hrteam@. Shared inboxes make action attribution weak and remain accessible as membership changes. Replace them with named identities wherever possible. Where a shared address is unavoidable, document ownership, membership review and logging limitations.
Do not overlook copied files. Portal access control protects information inside the workspace; downloaded CVs, spreadsheet exports and email alerts create additional stores. Record whether each role can download, print, export or receive candidate details in notifications.
- Named users and their current client organisation.
- Pending invitations, public links and one-time share links.
- Administrators, support identities and machine integrations.
- Download, export, print and email-notification permissions.
Tie every permission to one current mandate
The client relationship alone does not justify access to every search or historical candidate.
Ask what decision the person is making. A hiring manager may need candidate presentations and interview feedback for one role. A finance approver may need fee milestones but no CV. A board member may need a restricted succession shortlist without access to other operational searches.
Map roles to actions rather than job titles. “HR” is too broad; so is “client admin.” Define who can view identity, reveal contact details, add feedback, download documents, invite colleagues and see compensation data. Then compare each user’s actual rights with that baseline.
Separate client-level settings from mandate-level access. When a person moves from one project to another, grant the new workspace deliberately instead of accumulating every past search. Permission drift is normal unless the design makes removal part of the change.
Verify identity and current affiliation
A familiar email address is not enough evidence that the same person still holds the same role.
Confirm the user through the named client owner and, for sensitive mandates, through an approved company channel. Check domain changes, external consultants and advisers whose engagement may have ended. Avoid routinely requesting identity documents; use proportionate verification based on risk.
Require multi-factor authentication for higher-risk workspaces and all administrative access. Unique accounts matter because they connect actions to people. If two directors share one credential, an access log cannot show who downloaded a profile or invited another guest.
Support access needs boundaries too. A software vendor or agency administrator should not browse candidate records merely because the role can technically do so. Use time-limited elevation, a ticket or reason and an auditable completion event for exceptional support.
Review downloads as a separate disclosure decision
Viewing a current profile and retaining a local copy create different control problems.
A portal can show the latest candidate status, hide a withdrawn presentation and enforce access expiry. A downloaded PDF continues to exist after every one of those events. Decide which roles genuinely need downloads and whether a watermarked, redacted or time-limited view serves the purpose better.
If downloads remain enabled, log the user, document, candidate, mandate and time. Explain to the client how downloaded information should be handled, who may receive it and what happens when the mandate ends. A generic confidentiality clause is not a substitute for operational controls.
Do not promise digital rights management can make every copy disappear. Screenshots and offline storage remain possible. Technical friction, clear responsibility and follow-up reduce risk, but honest governance still matters.
Portal revocation stops future portal access. It does not remotely erase every file a user already saved.
Set event-driven expiry, not one annual clean-up
Quarterly or annual review helps, but role changes and mandate closure should trigger removal immediately.
Create revocation triggers for a closed search, withdrawn client stakeholder, changed job, ended consultancy, suspicious login or extended inactivity. Invitations should expire automatically. Temporary reviewers should have a short end date selected when access is granted, not an open account somebody hopes to remember.
Use a periodic certification as a backstop. Send the client owner a clear list of named users, roles, mandates and special rights. Require an affirmative decision for sensitive access rather than assuming silence means approval. Escalate overdue certifications and suspend access where the risk warrants it.
The frequency should reflect sensitivity. A confidential CEO succession search deserves tighter review than a closed, de-identified reporting workspace. Write the rule down so teams can apply it consistently.
Read access logs for behaviour, not decoration
Logs create value only when the agency knows which events should be reviewed and who responds.
Monitor repeated failed logins, access from unexpected locations, unusual download volume, invitations outside the approved domain and activity after a role change. A download is not automatically suspicious, but twenty candidate files at 02:00 deserves a question.
Retain logs for a defined security and accountability purpose, protect them from casual editing and limit who can read them. Logs themselves contain personal data about users. More logging is not automatically better; capture events that support access control and incident investigation.
Link alerts to an incident playbook. The owner should be able to suspend the account, preserve relevant evidence, establish affected candidates and decide whether the event may be a personal-data breach. An alert left unread is not a security measure.
Separate controller responsibilities from product settings
A well-configured portal supports compliance, but it does not determine the legal roles or lawful basis between agency and client.
Document who determines the purposes and means of each processing activity, who answers candidate rights requests and who handles incidents. Those roles depend on the real arrangement, not the label in a software contract. Agencies and clients may have different responsibilities across sourcing, presentation and employment decision-making.
Translate the arrangement into operational contacts. Portal administrators need to know who can approve a new reviewer, who handles a candidate withdrawal and who confirms deletion or retention at mandate closure. A data-processing agreement hidden in procurement cannot perform those tasks.
When the answer is uncertain, reduce access while the parties clarify it. Granting broad visibility “because the client owns the role” is not a defensible substitute for purpose limitation and appropriate security.
Run the review and close every exception
A completed review records removals, approvals, unresolved risks and the next certification date.
Give each account one outcome: retain unchanged, narrow, suspend pending confirmation or remove. State who approved retained access and why. For administrators and download-capable roles, add a second reviewer. Four eyes are useful where one click exposes an entire shortlist.
Test removals from the user’s perspective. Confirm old links fail, sessions are invalidated and email notifications stop. Check integrations separately; revoking a portal user may not remove an exported feed or calendar invitation.
Report exceptions to the mandate owner in plain terms: three former users removed, one shared account awaiting replacement, downloads disabled for two reviewers. Then set the next event or date. Access reviews are maintenance, not a certificate earned once.
Client-portal access review fields
These fields turn a user list into a decision record for confidential recruitment work.
| Review field | Decision evidence | Typical action |
|---|---|---|
| Identity | Named person, verified organisation and client owner | Replace shared or unverified account |
| Mandate need | Current decision role and assigned searches | Remove historical workspace access |
| Privilege | View, feedback, invite, export and admin rights | Reduce to minimum required actions |
| Time boundary | Expiry, last activity and closure trigger | Expire temporary and stale access |
| Use evidence | Login, download, invitation and alert history | Investigate unusual activity |
| Certification | Approver, date, exceptions and next review | Close or escalate unresolved permissions |
Limits of an access review
An access review cannot recover every offline copy or guarantee that an authorised user will act properly. It reduces exposure through identity, least privilege, logging, expiry and accountable client processes.
Specific security measures must match the risk, technology and legal roles in the real deployment. This checklist does not replace a security assessment, contract review or incident-response procedure.
Client-portal access review questions
Practical answers for recruitment agencies sharing identifiable candidate records with client teams.
How often should client-portal access be reviewed?
Review on events such as mandate closure, role change and inactivity, with a periodic certification as a backstop. Sensitive executive searches normally justify more frequent checks than low-risk workspaces.
Should clients be allowed to invite colleagues?
Only if the invitation flow has clear scope, verification, logging and an accountable approver. For confidential searches, agency or named-client-owner approval is usually safer than unrestricted invitations.
Do access logs prove the candidate data was handled lawfully?
No. Logs show events and support accountability; they do not establish purpose, lawful basis, transparency or necessity by themselves.
Should downloads be disabled?
Disable them where a current portal view meets the need. Where downloads are necessary, restrict the role, record the event, set client handling expectations and deal with copies at withdrawal or closure.
Official sources for access control and security
The GDPR, EDPB and NCSC describe risk-based security, differentiated authorisations, obsolete-access removal and account review.
- EUR-Lex: General Data Protection Regulation — principles, rights and security of processing
- European Data Protection Board: Secure personal data and review access authorisations
- UK National Cyber Security Centre: Identity and access management
Strengthen confidential client collaboration
Build a candidate-withdrawal propagation workflow · Close a search mandate cleanly · Review Yena’s client portal · See the recruiting CRM for agencies
Give every client reviewer the right-sized view
Yena helps search teams present candidates in a controlled client workspace, keep feedback with the mandate and remove stale access without returning to scattered attachments.
Explore the Yena client portal