NewRecruitly + WhatsApp — message from your CRM
Recruitly LogoRecruitly

For large, multi-brand agencies

Scale without buying a second system

At enterprise size the questions stop being about features and start being about control: who can see what, what happens when someone leaves, what the auditor is shown, and how this connects to everything else you run. Those answers are built in rather than bolted on.

What gets asked before anything gets signed

Who can see which records
What happens to data on a deletion request
Who changed this, and when
How it connects to the rest of the stack

Four questions no feature list answers, and every one of them stops a rollout.

Recruitlyone record
RolesData privilegesAudit logAPIWebhooksSSO

Governed at the record

Access, retention, attribution and integration are platform behaviour, not a services project.

19 modules, one database

What actually makes this desk hard

Every brand thinks it is a special case

Three acquisitions, three ways of working, three sets of statuses. Standardising means a fight, and not standardising means you can never compare two desks honestly.

Compliance is somebody's whole week

Right-to-erasure requests, CV retention limits and consent tracking handled by hand across a large database is both slow and the sort of slow that turns into a fine.

The stack is the integration

Nothing new gets adopted unless it talks to the accounting system, the calendar, the mail platform and the reporting the board already reads.

What changes when it all runs in one place

01

An access model built for an org chart

A role grants modules; data privileges decide scope — own, team or all. Users are managed centrally, and what someone can see follows the role rather than a per-person exception nobody remembers making.

02

GDPR as behaviour, not a policy document

Anonymise a candidate to satisfy erasure while keeping the record's integrity, and reverse it if the request is withdrawn. CV and resume expiry triggers age data out on a schedule, with renewal reminders before deletion.

03

Every record carries its own history

A full audit log on candidates, jobs, companies, contacts, leads and deals — every change, with attribution and a timestamp. The answer to "who did this" is a tab, not an investigation.

04

Integration you control

Public API keys, webhooks on the events you care about, two-way Gmail and Outlook sync, Google and Outlook calendars, Xero and QuickBooks, and a marketplace of apps you enable per tenant.

05

Sending infrastructure that holds up at volume

Authenticated sending domains, managed mailboxes, dedicated IPs, suppression lists and a blacklist — so campaign volume across several brands does not put the group's deliverability at risk.

06

One database, nineteen modules

BD, delivery, marketing, calling, e-signature, analytics and billing share one record. The integration budget that usually joins those systems together stops existing.

What the security review asks about

Control that does not depend on people behaving

Access is defined once and enforced everywhere. Retention runs on a schedule. Attribution is automatic. None of it relies on a consultant remembering the policy, which is the only kind of control that survives a thousand users.

Role → modules → data privileges, managed centrally
Anonymise and un-anonymise for erasure requests
CV expiry triggers with renewal reminders
Audit log on every record type, with attribution

Questions this desk asks

Can several brands run in one instance?

Yes. Brand Kit carries logos, CV templates, watermarks, portals and advert themes, and data privileges keep the desks apart. Where brands must be fully separate, separate tenants remain the cleaner answer.

What does migration look like at our scale?

A structured project rather than an import button: mapping, staged loads with per-run status and error logs, a parallel period, then cutover. There is a dedicated migration guide covering exactly this.

Is there single sign-on?

Yes — SSO is supported and documented separately, alongside the infrastructure and security detail your review will ask for.

How is AI usage controlled?

Metered AI and data features carry per-feature spending caps and kill switches, plus a visible per-use price and monthly free allowances. Finance sets the ceiling centrally rather than discovering the number later.

One platform your security review can actually finish

Access control, retention, audit and integration are how the product behaves, not a statement of work. Talk to us with your requirements list open.