Chapter 15 of 17

Team & Permissions in Canvider

Inviting teammates, pending invitations, role-based permissions, deactivation and the multi-tenant isolation that keeps every company's data separate.

5 features Click-by-click steps

Invite Team Member #

Send an email invitation for a colleague to join Canvider.

Why it exists Grows your recruiting team with the right access level.

Hiring is never a solo activity — hiring managers review, interviewers give feedback, coordinators schedule — but the more people who can see candidate data, the larger your exposure if any one account is compromised. Invitations resolve that by making access deliberate: someone decides who joins and, at the same moment, what they are allowed to do. Choosing the role at invitation time rather than afterwards is the important habit, because a role assigned "temporarily" as Administrator almost never gets downgraded later.

How to use it

  1. Go to Settings and click the "Invitations" card.
  2. Click "Invite New Member".
  3. Enter First Name, Last Name and Email Address.
  4. Select a "Role": Administrator, Recruiter, Hiring Manager, Interviewer or Read Only.
  5. Read the role descriptions shown below the dropdown.
  6. Click "Send Invitation".
  7. Track the invitation's status and expiry date in the "Invitations" tab.

Good to know

  • Grant the least access that lets the person do their job — an interviewer rarely needs Recruiter permissions.
  • Invitations expire. Check the expiry date in the Invitations tab if someone says they never got in.
  • Use a work email address; the invitation and all later notifications go there.
  • The role you pick is what the invitee sees on their acceptance page, so it should be right before you send.

Manage Pending Invitations #

Track, cancel or delete invitations that have not been accepted.

Why it exists Cleans up stale invites and revokes ones sent in error.

An unaccepted invitation is a live path into your candidate data, and they accumulate quietly — a candidate hire who never started, a typo'd address, an invite sent to a contractor whose engagement ended before they logged in. Being able to see and revoke them turns a forgotten loose end into a managed one. This page is also where you answer the most common onboarding question ("I never received it"), because it shows whether the invitation was sent, when it expires, and whether it has already been used.

How to use it

  1. Go to Settings → Invitations and click the "Invitations" tab.
  2. Review each row: Name, Email, Role, Sent Date, Expiry Date and Status.
  3. Filter the list with the "Status:" and "Role:" dropdowns.
  4. Click the "Cancel" action on a row to revoke an invitation without deleting it.
  5. Click the "Delete" action to remove the invitation record entirely.
  6. Send a fresh invitation with "Invite New Member" if the person still needs access.

Good to know

  • Cancel keeps the record for audit purposes; Delete removes it entirely. Prefer Cancel unless the invitation was a mistake.
  • Review pending invitations periodically — stale ones are unnecessary exposure.
  • Revoke immediately if an invitation went to the wrong address; do not rely on it simply expiring.
  • An expired invitation cannot be extended; send a new one instead.

Role-Based Permissions #

Five roles controlling what each teammate can see and do.

Why it exists Limits sensitive candidate data to the people who need it.

Candidate data is personal data, and data-protection law expects access to be proportionate to someone's actual job — an interviewer who needs to give feedback on one candidate does not need the ability to export your entire pipeline. Five roles cover the real division of labour in hiring without becoming a permissions matrix nobody maintains. In practice the discipline that matters is resisting Administrator as the default: it is the convenient answer and the one that turns a single compromised account into a company-wide incident.

How to use it

  1. Go to Settings → Invitations → "Team Members" tab.
  2. Review each member's Name, Email, Role and Status.
  3. Use the "Role:" filter to see everyone with a given role.
  4. Assign roles when inviting: Administrator (full access), Recruiter (jobs, candidates, interviews), Hiring Manager (review and decide), Interviewer (interview and feedback), Read Only (view-only).
  5. Adjust permissions after a user accepts their invitation.

Good to know

  • Analytics requires Administrator, Recruiter, Hiring Manager or Read Only — Interviewers cannot see it.
  • Keep the number of Administrators small; audit the list periodically using the Role filter.
  • Read Only is the right role for finance, leadership or anyone who needs visibility without the ability to change anything.
  • Roles can be adjusted after someone accepts, so start restrictive and widen if needed.

Deactivate / Reactivate Team Member #

Suspend or restore a teammate's access to Canvider.

Why it exists Cuts off access instantly when someone leaves.

Offboarding is where access control most often fails, because revoking accounts is nobody's favourite task and a departing recruiter's login can survive for months after their last day. Deactivation makes it a single immediate action: the person is logged out, loses access at once, and disappears from mention autocomplete so colleagues stop expecting a reply. Crucially it is reversible and destroys nothing — their comments, decisions and history remain intact, which is exactly what you want for parental leave, secondments or an accidental deactivation.

How to use it

  1. Go to Settings → Invitations → "Team Members" tab.
  2. Find the member in the list.
  3. Click "Deactivate" on their row.
  4. Read the warning — they lose access immediately and are logged out.
  5. Click "Confirm Deactivation".
  6. To restore access later, click "Activate" and then "Confirm Reactivation".

Good to know

  • Effective immediately, including for a user who is currently signed in — they are logged out.
  • Nothing is deleted. Their comments, activity and history stay, which preserves your audit trail.
  • Reassign their in-flight candidates before deactivating, or those applications lose their owner.
  • Disconnect any integration connected under their account too — deactivation alone does not revoke that mailbox connection.
  • Prefer deactivation over deletion for anyone who might return.

Multi-Tenant Data Isolation #

Every record is locked to the company that owns it.

Why it exists Guarantees no company can ever see another's candidates.

Canvider is one application serving many companies, which is what makes it affordable — and it means the boundary between employers is the single most important guarantee in the system. If it failed, one company could see another's candidates, salaries and hiring plans, which is both a catastrophic breach and a competitive disaster. Isolation is therefore enforced on every request at the data layer rather than being something the interface merely hides, and it extends to API and MCP keys so an integration cannot become a way around it.

How to use it

  1. Nothing to configure — enforcement is automatic on every request.
  2. Sign in and you only ever see your own employer's jobs and candidates.
  3. Team members inherit the same boundary.
  4. API and MCP keys are scoped to one employer too.

Good to know

  • There is nothing to switch on and no way to disable it — the boundary is structural.
  • This is the answer to the question security reviews always ask about shared infrastructure.
  • Role-based permissions operate within your company; isolation is what separates companies from each other.
  • The one shared feature is the opt-in shared talent pool sourcing source, which is explicit and chosen per search.