Least privilege by role
Access in SkillCort is role-based and follows least privilege: a role grants the minimum access its work requires, nothing more. The four roles are owner, admin, recruiter, and evaluator. When someone reports they cannot see a report or an export, check their role before anything else — the scoping is deliberate, not a bug.
Role-scoped reports and results
Report and results access is scoped by role, so evaluation evidence is not visible to everyone in the workspace by default. The audit pack — the full decision file — is limited further: owners and admins can always export it, and recruiters can once results are released. This keeps decision records in the hands of the people accountable for the decision.
Named attribution of scores
Access control is not only about who can read — it is about who did what. Every score in the record is attributed to a named evaluator with a timestamp, and the same applies to AI-assisted work: a named person confirms or overrides every AI suggestion. When a decision is reviewed later, there is never an anonymous score in the trail.
Candidate-side access control
Access control also covers how candidates reach an assessment. Each delivery sets its own access method — email invitations, a public self-registration link, single-use invitation codes, or credential matching against a guest list — and every access decision is made server-side, with no candidate enumeration. A reviewable access log records every pre-exam access event, with filters and CSV export.
Workspace sign-in today uses password or email one-time-code login; single sign-on through an identity provider (OIDC/SAML) is on the enterprise roadmap.
At a glance
- Four roles — owner, admin, recruiter, evaluator — each granted only the access their work requires.
- Report and results access is role-scoped.
- Owners and admins can always export the audit pack; recruiters can once results are released.
- Every score in the record is attributed to a named evaluator with a timestamp.
- Candidate-side access is controlled per delivery: email invitations, public links, codes, or credential matching, with a reviewable access log.