Skip to main content

Can I add a consulting firm or an outside person to manage assessment processes?

Yes, you can. Many companies outsource part of their recruiting operation by hiring specialized consulting firms or freelance recruiters. Coodesh lets you invite these people to collaborate directly on the platform — with a few security layers designed to protect your company's data and your candidates' data.

This article covers three things: which email to use for the invite, what access an outside person gets by default, and how to use workspaces to limit their access to a specific need.


Which email should the outside person use?

Before inviting someone, ask: is this a personal email or a corporate email? Ideally, the person should access the platform with a corporate email — either your company's own domain or the consulting firm's domain (e.g. person@consultingfirm.com). This makes it easier to track who did what on the platform and reduces the risk of improper access.

If the person is from an external consulting firm, you can register the firm's domain as an authorized domain for your workspace:

  1. Go to Workspace > Security.

  2. Under Authorized domains, enter the full domain (e.g. consultingfirm.com).

  3. Click Add domain.

From then on, email login also works for anyone using that domain, just as it already does for your internal team. Learn more in Security Settings.

If the person doesn't have a corporate email (for example, a freelance recruiter using Gmail), the platform also accepts sign-up with a personal email — but only through an invite link sent by someone already registered at your company. Whenever possible, prioritize a corporate email or an authorized domain: they give you more control over who has access to the account.


What access does an outside person get by default?

When you invite someone, you choose an access profile: Admin, Manager, or User. See what each one allows in Manage users in the workspace.

Recommendation: for people outside your company, the Manager profile is the best fit — combined only with the specific permissions needed for the role that person will play, and restricted to a workspace created specifically for that role, not your company's main workspace (see the next section). Avoid granting the Admin profile to anyone who isn't part of your team.

Even with a management profile, some areas stay restricted for outside users by default, for security reasons — to prevent data leaks and to keep someone outside your company from having unrestricted access to everything in the account:

  • Coodesh Library — viewing, editing, or cloning questions in the general test library.

  • Integration keys (API) — generating and managing keys used for integrations with other systems.

  • Talent pool — the pool of candidates your company has already evaluated in other processes.

  • Other company-wide settings, such as registration data, authorized domains, billing, and integrations.

These restrictions exist so that collaborating with an external partner doesn't mean giving up control over your company's and your candidates' sensitive data.


Use workspaces to isolate access

The permission restrictions above protect settings and sensitive data, but if the outside person is added directly to your main workspace, they may still see jobs and candidates from processes unrelated to their assignment — including evaluations already completed for other jobs.

To avoid this, the best approach is to create a separate workspace for the specific need (for example, an internship hiring process run by the consulting firm) and add only your company's decision-makers for that need, plus the outside person, to it. That way, they'll only have access to the jobs and candidates in that workspace — not to candidates already evaluated in the rest of the account.

See the step-by-step guide in How to Create and Manage Workspaces and Workspace Settings.


In summary

  • Ask whether the outside person's email is personal or corporate before inviting them.

  • If they're from a consulting firm, register their domain under Workspace > Security > Authorized domains.

  • Use the Manager profile with specific permissions for the role, avoiding the Admin profile.

  • Remember that the library, integration keys, talent pool, and company-wide settings stay restricted for outside users.

  • Restrict that access to a workspace created specifically for the outside person's role, and add only the people who need to be part of it.

Not sure which profile or permissions to use in a specific case? Reach out to our support team via chat or email.

Did this answer your question?