Refolk
October 5, 2026·8 min read

Greenhouse Named hireEZ. Your $12,960 LinkedIn Seat Is the Fuse.

Greenhouse's 2026 AI roundup flagged hireEZ for LinkedIn restriction risk. Here is the dollar math, the ToS mechanism, and how to vet safe tools.

hireEZ LinkedIn restrictionAI sourcing tool LinkedIn banLinkedIn Recruiter account restrictedsafe AI sourcing toolsLinkedIn automation ToS
Greenhouse Named hireEZ. Your $12,960 LinkedIn Seat Is the Fuse.

Greenhouse's updated "Best AI recruiting software in 2026" roundup did something unusual: it named a direct competitor, hireEZ, and tagged it in the comparison table with "Documented LinkedIn account restriction risk." That is the only tool out of thirteen flagged for platform-ToS exposure, and it landed the same quarter most TA teams are approving 2026 Recruiter renewals that now run up to $12,960 per seat.

If you are the person signing those renewals, that one phrase in a competitor's roundup is the most expensive sentence of your quarter. Here is what it actually means, who absorbs the blast radius, and how to pick an automation layer that does not route through the account your pipeline depends on.

What Greenhouse actually said about hireEZ

Greenhouse's 2026 roundup compared thirteen AI recruiting tools and put a single warning under hireEZ: "Documented LinkedIn account restriction risk." No other tool in the table (not SeekOut, not Findem, not Gem) carried a ToS flag.

That is a competitive signal, not a neutral review. ATS vendors almost never name a competitor by name in a public comparison; the standard move is a feature grid with the vendor's own product gently on top. Greenhouse breaking that convention tells you two things:

  • Greenhouse thinks the restriction risk is concrete enough to put in writing with legal reviewing it.
  • Greenhouse's own governance pitch (its MCP layer, its API-side integrations) is partly a shot at vendors whose automation routes through the recruiter's live LinkedIn session.

hireEZ's own marketing describes EZ Agent as an agentic AI that searches 800M+ profiles across 45+ external platforms, ranks candidates, and runs multichannel outreach. The breadth is real. The question Greenhouse is forcing recruiters to ask is where the LinkedIn portion of that breadth comes from and whose account is on the hook when LinkedIn notices.

The ban falls on you, not on hireEZ

The hireEZ Chrome extension inherits your LinkedIn session. When LinkedIn's behavioral detection fires, your seat gets restricted, not the vendor's.

That is the whole story in one sentence, and it is the piece most buying committees miss. Here is how it works in practice:

  • hireEZ's InMail flow runs via a Chrome extension inside the recruiter's own browser, authenticated with the recruiter's own LinkedIn license (pin.com).
  • The extension inherits whatever InMail caps and permissions that seat carries. The seat is the fuse.
  • LinkedIn actively detects automation through behavioral analysis, browser fingerprinting, and rate-limit monitoring (connectsafely.ai).
  • Third-party reviewers (everyats.com) document users getting permanent bans with no warning after the extension's activity gets flagged as "unauthorized."
  • LinkedIn's User Agreement Section 8.2 explicitly bans "manual or automated software, devices, scripts, robots, other means or processes to access, 'scrape,' 'crawl' or 'spider' the Services," and binds the account holder, not the SaaS vendor.

So when a vendor says "we are compliant," read it carefully. Compliant with what? If the integration is Chrome-extension-based and simulates a human clicking inside LinkedIn.com, the compliance claim is about the vendor's own corporate posture. The enforcement action, when it comes, lands on your login.

$12,960
LinkedIn Recruiter Corporate seat, 2026 high end
A roughly 15% jump over 2025. Multiply by headcount, then multiply by the probability any one seat gets flagged.

The dollar math on a 10-seat team

A ten-recruiter team losing two seats to restriction is a $21.6K to $25.9K sunk license cost before you count pipeline downtime. That is the number worth putting in the renewal memo.

Public pricing data (herohunt.ai, feeds.obra.co) puts the 2026 Corporate seat at $10,800 to $12,960, with the YoY increase around 15%. A ten-seat shop is looking at $108K to $129.6K per year on Recruiter alone. The restriction scenarios compound badly:

Seats restrictedSunk license costRecovery timelinePipeline hit
1 of 10$10.8K to $13KOften permanent, no warning10% of outbound capacity
2 of 10$21.6K to $25.9KAppeals rarely reinstate20% plus rebuild time
3 of 10$32.4K to $38.9KReplace seats under new identity30% plus trust loss with LinkedIn

Third-party reviewer sites document a consistent pattern: restrictions arrive without warning, appeals rarely restore access, and the "fix" is standing up new seats, which LinkedIn's fraud team scrutinizes harder because of the prior flag.

For context, LinkedIn Recruiter has 421 G2 reviews at 4.5 stars. hireEZ has 264 reviews at 4.6 stars, skewing 40.8% small-business. That skew matters: small-business buyers are the ones most dependent on a single seat holder, with the least internal capacity to vet ToS exposure before renewal.

Why the hiQ ruling does not protect you

The hiQ v. LinkedIn case is routinely cited as "scraping is legal." It isn't, and the misread is costing recruiters money.

What the Ninth Circuit actually said: scraping publicly available data does not violate the Computer Fraud and Abuse Act. What happened next: the district court found hiQ had breached LinkedIn's User Agreement, and in December 2022 hiQ paid LinkedIn $500,000, accepted a permanent injunction against scraping LinkedIn, and agreed to destroy everything it had collected.

The practical takeaway for a recruiting-ops lead:

  • CFAA (criminal law) is off the table for public-data scraping. Nobody is going to jail.
  • Contract law (the LinkedIn User Agreement you clicked) is the active enforcement surface. LinkedIn can and does act unilaterally on contract grounds, which means account restriction without going near a courtroom.
  • Every post-2022 LinkedIn restriction documented in public reviewer threads has been on contract grounds, which is a much lower bar for LinkedIn to pull the trigger on.

So the vendor pitch of "the hiQ ruling protects this" is either misinformed or dishonest. The ruling that actually matters is the settlement that followed it, and it says: LinkedIn gets to decide what counts as "unauthorized activity," and the account holder bears the cost.

The 37-to-1 problem nobody is budgeting for

In Refolk's index of U.S. professionals, there are 5,220 people with "Sourcer," "Technical Sourcer," or "Sourcing Specialist" in their title, and only 141 with "Recruiting Operations" or "TA Operations" titles. That is roughly 37 sourcers per every one ops professional qualified to vet tool risk.

That ratio is the quiet reason this keeps happening. The person with their hands on hireEZ (or any session-side automation) is almost never the person reading the User Agreement before signup. The small population that is actually tasked with that review clusters in a handful of places: Sierra, Plaid, Harvey, Honeycomb, Hudson River Trading. Those are the teams quietly de-risking tool stacks ahead of 2026 renewal.

Among the 2,414 U.S. Director+ TA leaders in Refolk's index (the renewal decision-makers), concentration is heaviest in NYC and Denver. If you are one of them and your recruiting-ops headcount is zero or one, your 2026 vendor review is a one-person job competing with everything else that person owns.

37:1
U.S. sourcers per recruiting-ops professional
Derived from Refolk's index. The population qualified to vet ToS exposure before signing is tiny relative to the population using the tools.

How to classify any sourcing tool in under 60 seconds

The bright line is simple: tools that use an official API with rate limits are survivable; tools that simulate human behavior inside LinkedIn.com are not (connectsafely.ai).

Walk through this with any vendor on your 2026 shortlist:

  1. Where does the LinkedIn data come from? Official partner API (safe), publicly cached and indexed off-platform (gray but defensible), live scrape via extension on recruiter's session (dangerous).
  2. Whose session executes the outreach? The vendor's server using its own partner credentials (safer), the recruiter's live LinkedIn session (your seat is the fuse).
  3. Does the vendor install a Chrome extension that reads or writes inside linkedin.com? If yes, assume behavioral detection will eventually fire.
  4. Does the vendor claim "fully compliant" without naming the API or partner program? Treat as a session-side tool.
  5. If LinkedIn restricts a user's account tomorrow, what is the vendor's SLA? Most contracts carry no remedy for this. Read the MSA.

By this classification, LinkedIn Hiring Assistant and Greenhouse's MCP layer sit on the API side. hireEZ's EZ Agent, and most "agentic" tools that promise to run outreach for you across LinkedIn, sit on the session side. Refolk sits off-platform entirely: the discovery layer runs on public web and GitHub signal, so the LinkedIn seat you pay $12,960 for is used only when you choose to log in and send a message yourself.

Greenhouse did not flag hireEZ for being bad at sourcing. It flagged it for making your seat the collateral.

What to put in the 2026 renewal memo

One paragraph, three bullets, and a classification table. That is the memo that gets signed.

The paragraph: "Our 2026 Recruiter renewal is $X across Y seats. One competitor ATS has now publicly flagged tool-induced LinkedIn restriction risk by name. The attached table classifies every automation tool touching our Recruiter seats as API-side (safe) or session-side (risk). Any session-side tool is paused pending vendor-level remediation."

The three bullets:

  • Inventory every Chrome extension installed on recruiter machines. Anything that reads or writes inside linkedin.com is in scope.
  • Require vendors to answer the five classification questions above in writing. "Compliant" without an API name is a no.
  • Reclassify any tool whose outreach runs through the recruiter's own LinkedIn session as a Tier-1 risk and apply the same vendor review you apply to anything touching candidate PII.

FAQ

Is hireEZ going to get my LinkedIn account banned?

Not every user, and not predictably. The documented pattern is that LinkedIn's behavioral detection fires on a subset of accounts using session-side automation, and when it does, restrictions arrive without warning and appeals rarely restore access. The exposure is real, the timing is not predictable, and the cost per flagged seat in 2026 is $10,800 to $12,960 plus pipeline downtime. If you cannot absorb that outcome on any single seat, treat session-side tools as a Tier-1 risk.

Does the hiQ ruling protect my team if LinkedIn restricts a seat?

No. The Ninth Circuit's hiQ ruling said scraping public data is not a federal crime under the CFAA, but the same case ended with hiQ paying LinkedIn $500,000 and accepting a permanent injunction on contract grounds. LinkedIn enforces its User Agreement via account restriction, not litigation, and the contract binds the account holder (you), not the SaaS vendor.

What makes a sourcing tool "safe" by LinkedIn's standards?

Tools built on official LinkedIn APIs with documented rate limits (LinkedIn Hiring Assistant is the clearest example) sit inside LinkedIn's permission layer and will not trigger restrictions. Tools that run as Chrome extensions inside linkedin.com, simulate human clicks, or scrape profiles via the recruiter's authenticated session can and do trigger restrictions. Off-platform discovery tools that index public web and GitHub signal avoid the question entirely because they do not touch your LinkedIn session.

How do I vet a vendor before signing in 2026?

Ask five questions in writing: where the LinkedIn data comes from, whose session executes the outreach, whether a Chrome extension reads or writes inside linkedin.com, which specific API or partner program backs the "compliant" claim, and what the vendor's SLA is if a user's account gets restricted. Any vendor that will not answer in writing fails the review. Any vendor whose honest answer puts your Recruiter seat on the critical path is a Tier-1 risk at 2026 pricing.

Try it on the search you came here for

Stop building boolean strings. Just describe the person.

Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.

  1. 01Describe them

    One plain sentence. Role, city, stack, stage, whatever matters to you.

  2. 02I read the web live

    GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.

  3. 03You read the shortlist

    Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.

  • No boolean, no filters, no seat to buy. One box.
  • Read at search time, so a profile updated yesterday counts today.
  • Every step visible as it runs, every name with its reason.

500 free credits on sign-up. No card, no demo call. See real searches.

Read next