Skip to main content
Sign inBook a demo

For enterprises

Enterprise hiring and HR, on your terms

Run every business unit in its own workspace under one organization, with single sign-on and SCIM, custom roles, IP allow-lists, your own encryption key, a dedicated-database tier and data residency. Agents stay behind the approvals you set.
Contact salesVisit the trust center
The Command Center in dark mode
The Command Center in dark mode (sample data).

Identity and access

Your identity provider, your roles, your network

Single sign-on, provisioning and access rules work with the identity provider you already run, once you connect it.
  • Single sign-on

    OIDC and SAML 2.0 per organization on domains you verify, with just-in-time provisioning, an optional “SSO required” rule and a break-glass admin so a broken identity provider cannot lock you out.
  • SCIM 2.0

    Users and groups from your identity provider, with group-to-workspace-role mappings. Setup steps are documented for Microsoft Entra ID and Okta.
  • Custom roles

    Build roles from a catalogue of permissions and assign them per workspace membership.
  • IP allow-lists

    IPv4 and IPv6 ranges per organization with lock-out safeguards, plus a separate list for each agency client portal.
  • Two-factor sign-in

    Optional TOTP two-factor authentication for people who sign in with a password.
  • Every change audited

    Administrative changes are audit events in your organization’s hash-chained audit trail.

Data and keys

Your data, your keys, your region

  • Customer-managed keys

    Stored secrets are sealed with envelope encryption: a data key per organization, wrapped by a key in Azure Key Vault. Bring your own Key Vault key, and revoking it makes your organization’s encrypted values unreadable.
  • Dedicated database

    The dedicated-database tier keeps your workspace data in its own PostgreSQL database with the same schema, set up by our operators. Requests never fall through to the shared database; identity, audit and billing data stay in the shared control plane.
  • Data residency

    Your organization’s region decides where new files are stored and which model endpoint serves you. The EU (Sweden Central) is the default; other regions are available once provisioned. Files are never written to another region, and AI requests fall back to rules instead of leaving it.
  • Business units

    One organization with a workspace per business unit. Organization owners and admins reach every workspace; everyone else reaches only the workspaces they are members of.

Isolation tiers

Pooled or dedicated

Every query is scoped to your workspaces by the application. The dedicated-database tier also keeps your workspace data in a PostgreSQL database of its own.
Isolation tiers compared
What you getPooled (default)Dedicated database
Workspace dataShared PostgreSQL database, separated by workspace with row-level securityYour own PostgreSQL database with the same schema
Application scoping of every queryYesYes
Identity, audit and billing dataShared control planeShared control plane
Candidate-facing flowsShared databaseShared database
Set up byAutomaticHireGenix operators

Open to your agents

Connect your own agents, safely

Nothing external ever changes data without a person: write tools and recommendations from outside become approval requests.
  • OAuth 2.1

    An authorization server for external agents: authorization code with PKCE, client credentials, rotating refresh tokens and short-lived, scoped access tokens.
  • MCP

    Your agents call HireGenix tools over MCP. Tokens are checked on every call, and write tools return a pending approval instead of changing data.
  • A2A

    The AI CHRO is available as an A2A agent. Its recommendations to your agents become approval requests in HireGenix.

Questions

Enterprise questions

Yes. Single sign-on works with OIDC and SAML 2.0 identity providers on domains you verify with a DNS record, and SCIM 2.0 keeps users and groups in sync. Setup steps are documented for Microsoft Entra ID and Okta.

Bring your security and HR teams to the demo

We will go through identity, keys, residency and the approvals model with the people who need to sign off.

Contact salesVisit the trust center
HireGenix for enterprises