Recruiting agencies and executive search
Executive Search Interview Scheduling: A Privacy-First Agency Runbook
Confidential search scheduling leaks sideways. A candidate’s current employer appears in a forwarded subject line. A client succession project lands in a personal calendar title. A panelist sees the full distribution list before the search lead approves it. None of that information is needed to find sixty minutes. The coordination record should know less.
Run confidential interview scheduling in eight steps
Use this workflow for an agency-led confidential search involving one candidate, an external hiring manager, two required panelists, and one optional adviser across Google and Microsoft. Decide the disclosure boundary before the first availability request.
- 1
Classify the search and appoint disclosure owners
Record the search owner, client owner, candidate owner, confidentiality class, approved participant groups, and the person who can widen disclosure. Decide whether the candidate name, client name, role title, incumbent status, location, compensation context, and panel membership can appear in outreach, calendar events, or neither.- Every disclosure field has an owner and approved audience.
- The recruiter can pause the workflow when a new participant changes the boundary.
- Sensitive search notes never enter the general scheduling record.
- 2
Create a minimal scheduling identity
Link the scheduling record to the ATS or protected search system with an opaque search ID. Use approved display labels such as ‘candidate conversation’ or a recruiter-managed alias only when they match the firm’s policy. Store stage, duration, format, date window, scheduling deadline, and time zone without copying evaluation notes, source details, or reasons for confidentiality.- The record contains enough information to coordinate and no hidden copy of the search file.
- Aliases map to real identities only inside an access-controlled service.
- The candidate and client can still identify legitimate outreach.
- 3
Lock required roles and approved substitutes
List the candidate, recruiter, hiring decision-maker, required interview roles, optional advisers, and any client-approved substitutes. Keep the full panel hidden from participants who do not need it until the disclosure owner approves. A role substitution changes the scheduling revision and may change who can see the event.- Required and optional participation are distinct.
- No slot is proposed without the candidate and all required roles.
- A substitute is used only inside written client authority.
- 4
Collect bounded candidate availability
Ask for windows inside the agreed date range, in the candidate’s local time, through the approved channel. Explain the meeting duration, format, response deadline, and the limited use of the answer. Do not ask for a full personal calendar or for the candidate to expose current-employer meetings.- Calendar connection is optional for the candidate.
- Ambiguous dates or time zones receive one narrow clarification.
- The candidate can decline, correct availability, or request recruiter contact.
- 5
Read client free/busy at the narrowest useful level
Use approved Google or Microsoft availability operations for connected client participants. Normalize busy intervals, source, retrieval time, time zone, and errors. Keep event subjects, locations, descriptions, and unrelated attendee lists out of the search. For an unconnected panelist, request bounded windows under the same disclosure policy.- Provider failure is missing evidence, not an open calendar.
- The scheduling service requests only the permission needed for availability or the approved write.
- A participant’s private event reason never becomes a recruiter note.
- 6
Generate proposals inside the disclosure boundary
Intersect the candidate with every required role. Score remaining slots for optional attendance, working hours, notice, buffers, time-zone fairness, and the deadline. Show the recruiter and client owner the exact people and evidence freshness. Show each participant only the information needed to respond or attend.- Do not expose vote grids or other participants’ unavailable times.
- No-overlap returns the smallest role, duration, date, or substitute decision that could help.
- A changed required participant invalidates prior proposals and approval.
- 7
Approve wording, recipients, and the booking together
Bind approval to the current scheduling revision, exact recipient list, event title, description, conferencing details, organizer calendar, and selected slot. Re-check current required availability, write one canonical event, and verify invitations. If the candidate and panel need different context, send approved participant-specific messages without creating conflicting calendar records.- A repeated command cannot send another invitation or create a second event.
- The final calendar fields match the approved disclosure template.
- An uncertain provider write enters reconciliation before retry.
- 8
Close or retain records by declared purpose
On booking, cancellation, withdrawal, or search close, record the outcome and apply the firm’s retention schedule to messages, availability evidence, aliases, logs, and event links. Keep the ATS process record separate from operational scheduling traces. Review access and exports for the small group that actually needs them.- Retention is defined before collection begins.
- A participant correction updates active evidence and the authoritative record.
- Audit data proves access and action without copying sensitive message content into every log.
Data minimization is an operating design choice
The UK Information Commissioner’s Office describes data minimization as keeping personal information adequate, relevant, and limited to what is necessary for the stated purpose. For a scheduling record, the purpose is to coordinate and confirm the interview—not to become a second candidate profile or client search file.
Apply the principle field by field. Availability can be represented as intervals. Calendar access can be represented as permission class and freshness. Panel membership can be role-based until disclosure is approved. The scheduling service can link to the ATS without copying notes it will never use.
The ATS and scheduling record have different jobs
Greenhouse describes API access to jobs, candidates, interviews, and related recruiting data. Ashby exposes interview schedule operations. Those systems hold valuable process truth. A cross-company search still needs a coordination record for current participants, mixed calendar evidence, outreach state, time zones, proposals, approvals, provider event identifiers, and repair.
Link the records with an opaque ID and clear ownership. Do not put the scheduling service in charge of candidate assessment. Do not make the ATS inbox the only place to discover that a required client panelist has not answered.
A private link is not scheduling execution
A booking link can limit what the candidate sees. A poll can collect choices. A calendar-sync utility can expose conflicts. An ATS can store the interview stage. An AI assistant can draft careful outreach. Each helps, but the recruiter remains the dispatcher if no system combines required roles, candidate windows, client calendars, disclosure rules, approval, booking, and repair.
Scheduling execution carries that protected coordination state to one verified interview or one bounded exception. WonderCal’s direction is to coordinate candidates, hiring managers, and panels across company and calendar boundaries while recruiters keep candidate judgment, client relationships, disclosure decisions, and exceptions.
Run the confidentiality failure test
Use one candidate on a personal Google account, a hiring manager on Microsoft, a panelist on Google Workspace, and an optional adviser with no connected calendar. Force a forwarded outreach message, an unapproved participant addition, ambiguous time zone, provider error, stale slot, duplicate booking command, and panel substitution.
Pass when each person sees only approved context, the required set remains intact, the recruiter receives one bounded disclosure decision, and one verified event uses the approved wording. Fail when a private client or candidate detail appears in a calendar title, trace, poll grid, or unrelated inbox.
Compare confidential scheduling by finished work and exposure
Privacy is not only a settings page. It is the amount of search information copied into every step while candidate, agency, and client calendars are being coordinated.
| Decision vector | Recruiter relay and manual holds | ATS self-schedule, booking link, or poll | WonderCal execution direction |
|---|---|---|---|
| Coordination completion | The recruiter collects both sides, masks context, resolves the panel, books, and repairs every change. | Can finish standard interviews when configured availability and disclosure fit the stage. | Designed to carry minimal candidate and client evidence through one verified interview or bounded exception. |
| Cross-company reach | Works because the recruiter translates each tenant, provider, and participant by hand. | Candidates can open a surface; full client-panel coverage depends on host setup and access. | Target path combines Google, Microsoft, agency, client, candidate, and unconnected participants. |
| Privacy | Depends on careful aliases, masked holds, access lists, and thread hygiene on every search. | Depends on configuration and the fields supplied; separate surfaces can still duplicate candidate and panel data. | Target model uses private free/busy, bounded responses, approved wording, and a minimal coordination record. |
| Exception handling | The recruiter sees every disclosure exception but also carries every routine step. | May stop at no slot, added panelist, substitute, or changed disclosure without one shared decision record. | Designed to route identity, panel, deadline, approval, and booking exceptions to the correct human owner. |
| Time and cost | No new system path, but placement time becomes calendar dispatch and privacy checking. | Fast for standard stages; returned time depends on external coordination and disclosure work left behind. | Value comes from completing the agency-client coordination loop while recruiters retain search and relationship judgment. |
Coordination completion
Recruiter relay and manual holds
The recruiter collects both sides, masks context, resolves the panel, books, and repairs every change.
ATS self-schedule, booking link, or poll
Can finish standard interviews when configured availability and disclosure fit the stage.
WonderCal execution direction
Designed to carry minimal candidate and client evidence through one verified interview or bounded exception.
Cross-company reach
Recruiter relay and manual holds
Works because the recruiter translates each tenant, provider, and participant by hand.
ATS self-schedule, booking link, or poll
Candidates can open a surface; full client-panel coverage depends on host setup and access.
WonderCal execution direction
Target path combines Google, Microsoft, agency, client, candidate, and unconnected participants.
Privacy
Recruiter relay and manual holds
Depends on careful aliases, masked holds, access lists, and thread hygiene on every search.
ATS self-schedule, booking link, or poll
Depends on configuration and the fields supplied; separate surfaces can still duplicate candidate and panel data.
WonderCal execution direction
Target model uses private free/busy, bounded responses, approved wording, and a minimal coordination record.
Exception handling
Recruiter relay and manual holds
The recruiter sees every disclosure exception but also carries every routine step.
ATS self-schedule, booking link, or poll
May stop at no slot, added panelist, substitute, or changed disclosure without one shared decision record.
WonderCal execution direction
Designed to route identity, panel, deadline, approval, and booking exceptions to the correct human owner.
Time and cost
Recruiter relay and manual holds
No new system path, but placement time becomes calendar dispatch and privacy checking.
ATS self-schedule, booking link, or poll
Fast for standard stages; returned time depends on external coordination and disclosure work left behind.
WonderCal execution direction
Value comes from completing the agency-client coordination loop while recruiters retain search and relationship judgment.
Frequently asked questions
What is confidential interview scheduling software?
Should a confidential search use candidate aliases in calendar events?
Does the candidate need to connect a personal calendar?
How should a search firm separate the ATS from scheduling?
Where can recruiting agencies review WonderCal?
Primary sources
- ICO: A guide to the data protection principles — official UK guidance on purpose limitation, data minimization, accuracy, retention, security, and accountability
- Google Calendar Help: Share your calendar — official free/busy-only sharing level that hides event names and details
- Microsoft Graph: calendar getSchedule — official availability operation and least-privileged permission guidance
- Greenhouse Developer Resources — official jobs, candidates, interviews, webhooks, ingestion, and audit-log API entry points
- Ashby Developer API: Create interview schedule — official interview-schedule operation and recruiting-system boundary
Coordinate the interview without copying the search
Give WonderCal the minimum scheduling brief and approved disclosure boundary. Keep candidate judgment, client trust, search context, and exceptions with the recruiter.
See WonderCal for recruiting agencies