Refolk
TeardownRecruiting and sourcing

Draining One Competitor's Public Org Into a Hiring Shortlist

You can take one named competitor and produce a defensible, prioritized shortlist of its team to approach, with funnel counts and the legal checks that pause each name.

17 min readLast reviewed August 12, 2026Read as Markdown

Key takeaways

  • In Refolk's index there are roughly 47 Kubernetes individual contributors for every engineering director (13,656 versus 290), so one competitor rarely yields more than one or two credible leads at the top.
  • Enumeration is the binding constraint, not outreach: manual GitHub and Stack Overflow sourcing reaches only the 18 to 25% of engineers publicly active there, while strong personalization can still lift replies to 30 to 50%.
  • The GitHub-to-LinkedIn cross-match is both the dedupe engine and the freshness check, because an org member is likely still employed even with a LinkedIn that is two years stale.
  • The legal risk inverts as you succeed: a one-off hire is low risk, but volume from one employer converts an ordinary draw into anti-raiding exposure over a mass exodus.
  • With the FTC noncompete ban vacated and enforceability back under state law, a name's cleared or paused status now depends on the candidate's jurisdiction, so the red-line screen runs per person, not once per company.
  • The US Kubernetes pool is about 6.5x the UK's (13,656 versus 2,093), so a UK-anchored competitor draw exhausts faster and pushes you cross-border sooner.

You have chosen the company. A hiring manager points at one competitor and says, "their platform team is the best in the market, get me three of them." This guide is for the in-house recruiter, sourcer, or founder who now has to turn that single name into a ranked, deduped, reachable shortlist you can actually send, without stepping on a criminal antitrust line. It carries one worked example - a Kubernetes-heavy platform team - all the way through, with the real intermediate counts, the dedupe and reachability checks, and the contract red lines that pause a name.

This is the opposite of building a target-company list. The company is fixed. The job is to drain it end to end.

Why draining one org is a different job than mapping a market

Most talent-mapping work starts wide and narrows: which companies, then which people. Here the company is already chosen, so the whole funnel inverts. You are not deciding where to look; you are extracting everyone credible from one place and turning them into an ordered send list.

That inversion changes what breaks. When you map a market, thin coverage at any one company barely matters because you can move to the next. When you drain a single org, coverage at that org is the whole game, and its ceiling is low. Manual sourcing on GitHub or Stack Overflow gives visibility into only the 18 to 25% of engineers publicly active on those platforms. So before you filter anything, accept that you are seeing a fraction of the team and that your job is to see as much of it as possible, confirm who is real and current, and rank what remains.

The other thing that changes is legal weight. A one-off hire from a competitor is ordinary. Pulling several people from the same employer is not - it looks like a raid, and it invites anti-raiding and non-solicit challenges. The cap and the sequencing at the end of this procedure exist because success, not failure, is what triggers litigation.

When you drain a single org, coverage at that org is the whole game, and its ceiling is low.

What public sources actually expose about a team

Two sources carry this work: LinkedIn for the org shape, and the public GitHub graph for engineers. LinkedIn is the primary org-reconstruction source, and specialist mapping produces lists of virtually every executive at a target company and develops reporting relationships, determining who reports to whom. GitHub is the second layer: if a developer has set organization memberships to public, you can see which companies they belong to, and a member of a well-known company's GitHub org is likely a current or recent employee even if their LinkedIn is two years stale.

Coverage and confidence differ sharply by level. Treat reporting lines as confirmed only at VP and above; below that they are inferred, not established.

SourceWhat it reliably exposesConfidence
LinkedInNames, titles, VP+ reporting structureHigh at the top, inferred below
Public GitHub orgEngineer membership, language stack, commit recencyConfirms current employment, misses the quiet majority
Stack Overflow / public activityThe 18 to 25% publicly active engineersPartial, skews toward visible ICs

The underused move is GitHub org membership. Only 31% of tech recruiters use GitHub regularly, and only 31% of tech recruiters touch it, so an active platform team's public org is often unworked ground. TypeScript overtook Python as the number one contributor language in the 2025 Octoverse report, growing 66.63% year over year, which tells you the language signals you filter on drift and need re-checking against the current stack, not last year's.

The funnel, and where it is actually throttled

The binding constraint is enumeration at the top of the funnel, not response rate at the bottom. Because you can only see the 18 to 25% of engineers publicly active on GitHub and Stack Overflow, the widest stage of your funnel is already narrow before a single filter runs. Personalization can still lift replies to 30 to 50%, so effort belongs at discovery, not at blasting a big list.

Exact stage-by-stage drop-off is not established publicly; guides give pool sizes rather than a standardized funnel. What follows is the shape, using the visibility ceiling as the honest top.

One competitor's platform team, drained

  1. Real team (unknown)
    100%

    You never see all of it

  2. Publicly visible
    18-25%

    The GitHub/Stack Overflow-active slice

  3. Right level + tenure
    subset

    After leveling and trajectory

  4. Skill-matched + current
    subset

    After GitHub-to-LinkedIn confirm

  5. Cleared to send
    subset

    After the legal red-line screen

The funnel is throttled at enumeration, so the widest stage is already a fraction of the real team.

Two numbers from Refolk's index make the scarcity concrete before you start filtering. They tell you how many credible names a single competitor can plausibly hold at each level.

TierCountICs per role (derived)
Software Engineer (IC)13,656-
Director of Engineering290~47 ICs per director

Counts from Refolk's index of professional profiles; the ratio is derived (13,656 / 290). A Senior-band query returned zero rows and is excluded as a data limitation, not a real absence of senior engineers.

~47x
Kubernetes ICs per engineering director in Refolk's index
13,656 individual contributors against 290 directors, so seniority scarcity is exponential and a single competitor rarely yields more than one or two credible leads at the top.

The practical read: plan for an IC-heavy draw. If the hiring manager wants three directors from one competitor, the math says that team probably does not contain three, and the ones it does contain are the hardest to move.

Geography compounds the scarcity

Where the competitor is anchored changes how fast the well runs dry. The US Kubernetes pool is roughly 6.5 times the UK's, so a UK-anchored competitor draw exhausts far faster and pushes you cross-border sooner than a US one would.

MarketSWE + KubernetesIndex vs UK (derived)
United States13,6566.5x
United Kingdom2,0931.0x

Columns one and two are from Refolk's index; the third is derived (US count divided by UK count).

This matters at scoping, not at the end. If your competitor's platform team is in London, a two-thousand-strong national skill pool means the visible fraction of that one org is a meaningful share of the entire local market, so exhausting it early is realistic and your fallback (adjacent companies, cross-border, or a different skill graph) needs to be ready before you start.

The procedure

The job runs in eight steps. The first five build and rank the list, the sixth confirms each person is real and reachable, and the last two are the legal and concentration screen that makes the shortlist safe to send. A comprehensive talent-mapping project typically spans 6 to 12 weeks, but a single-org drain is faster because the company is fixed - budget days per step, not weeks.

One competitor to a send-ready shortlist

  1. Scope the target team
    Name one competitor and the exact department, then pull the public org from LinkedIn plus GitHub organization membership. Done when you hold a raw enumerated list of names with titles, tagged by skill rather than assumed reporting line.
  2. Confirm reporting lines where possible
    Separate confirmed structure (public VP and above) from inferred lines below that level. Done when each name carries a confirmed-line or inferred-line tag.
  3. Level and tenure filter
    Drop the wrong levels and flag tenure trajectory and recent movers - someone on their third job in five years is priced differently from their second in fifteen. Done when you have a leveled list with tenure notes.
  4. Skill match
    Verify each remaining name against GitHub activity, language stack, and listed profile skills. Done when the skill claim is evidenced, not assumed from the title.
  5. Activity and receptiveness pass
    Layer 60-day profile updates and Open-to-Work nuance on top of tenure, treating activity as the weaker signal. Done when the qualified list is prioritized by receptiveness.
  6. Dedupe and reachability
    Cross-match GitHub to LinkedIn to confirm one distinct, currently employed person, then verify a live contact channel. Done when you have a deduped shortlist with checked channels.
  7. Legal red-line screen
    For each name check no-poach exposure, your recruiter's or hire's carried non-solicit, and trade-secret risk, then pause or remove. Done when you hold a cleared shortlist with every paused name logged.
  8. Cap and sequence
    Apply a concentration cap and stagger outreach over time. Done when you have a send-ready, ordered shortlist that no longer looks like a raid.

The wrong turns in the worked example

Carrying the platform team through, here is where I actually went sideways.

At step one I mapped by org chart alone and nearly missed two strong Kubernetes ICs who sat in a "developer experience" group, not "platform." Several practitioners argue you should map by skill graph, not org chart, because a company's business competitors are not always its talent competitors. The employer is fixed here, so I enumerate the org, but I tag by skill and re-run the skill query across adjacent teams rather than trusting the department boundary.

At step three I initially dropped a candidate for a two-year tenure that read as junior-hopping. Trajectory rescued them: it was their second role in fifteen years, not their third in five. Tenure is a trajectory read, not a threshold.

At step five I over-weighted a profile refresh and ranked someone as job-seeking who had simply updated a headline. Activity signals are the second layer and weaker than tenure signals in isolation, so I paired the refresh with tenure before promoting anyone.

Dedupe and reachability: the same step does two jobs

The GitHub-to-LinkedIn cross-match is both your dedupe engine and your freshness check. Because a public org member is likely current even with a two-year-stale LinkedIn, the step that confirms one distinct human also rescues names a LinkedIn-only pass would have written off as departed.

Run it in one pass per name:

  • Match the GitHub handle to a current LinkedIn role at the competitor.
  • Confirm commit activity inside the last 60 days.
  • Confirm this is one person, not two records or a shared handle.
  • Verify a live contact channel before the name enters the send list.

That last check is where reachable shortlists quietly rot. One 2026 compilation cites roughly 70% annual contact-data decay on accuracy, so a name you confirmed as employed can still have a channel that bounces. Verify the channel is live at the moment you build the list, not from a record captured months ago.

This confirmation, freshness, and channel-check across the GitHub graph, LinkedIn, and the open web is exactly the friction Refolk is built to remove - you describe the person in plain English and get back candidates already resolved across sources.

Once the list is deduped and every channel checked, response benchmarks tell you what confirmation traffic to expect.

Channel / conditionResponse rate
Average LinkedIn InMail10-25%
Recruiting-specific InMail18-25%
Strong personalization30-50%
Open-to-Work (recruiters-only) uplift+~37%

All rows from public passive-sourcing benchmarks. The lesson embedded here: since enumeration is the ceiling, put the effort into personalization on a smaller confirmed list to reach the 30 to 50% band, rather than sending average InMail to a larger, shakier one. Passive candidates reward the patience - it takes about 4.5 months on average to close a passive candidate from first contact to hire, and they are 17% less likely to drop out of the funnel than active ones.

How this goes wrong

Every failure mode below produces a name that looks good and is not. For each, I give the false positive and the check that catches it.

GitHub org membership read as employment proof. The false positive is an alumnus still listed in a public org after leaving. Cross-match to a current LinkedIn role and recent commit activity before counting anyone as employed.

Stale contact data. The false positive is a "reachable" name whose email bounces. With roughly 70% annual contact-data decay, verify the channel is live before sending.

Coverage illusion. You see only the 18 to 25% publicly active on GitHub and Stack Overflow; the quiet majority is invisible. Compare your enumerated list against the LinkedIn org headcount to size the gap you are not seeing.

Activity-signal over-weighting. The false positive is a profile refresh read as job-seeking. Activity signals are weaker than tenure signals in isolation, so pair every refresh with tenure trajectory.

No-poach self-inflicted wound. The false positive is a "friendly" understanding with the competitor not to cold-call each other's staff. That agreement is itself the violation, and an illegal agreement can be oral - it need not be written down. Confirm no reciprocal hands-off understanding exists.

Your recruiter's carried non-solicit. If your sourcer recently left the target company, their own non-solicit covenant can taint the draw. Check whether solicitation, direct or indirect, can be shown, and instruct any hire not to recruit their former colleagues.

Trade-secret contamination. The false positive is a strong candidate volunteering their employer's roadmap in the interview. Candidates should never be asked to disclose proprietary details, and both the departing employee and the new employer can face liability under the Defend Trade Secrets Act. Give clear instructions that you do not want the former employer's property, and document that you gave them.

Concentration and anti-raiding. Drawing many people at once triggers anti-raiding exposure over a mass exodus, and challenges are amplified when recruiting multiple employees from a single employer with non-solicitation provisions. Cap the number and stagger outreach.

Three lines pause or kill a name, and one dead rule changed how you run the whole screen. Run the red-line screen per person, not once per company, because with the FTC's blanket ban vacated, enforceability is back under state law and depends on the candidate's jurisdiction.

The three lines, sharpest first:

  1. Horizontal no-poach between employers. Wage-fixing or no-poach agreements between employers may expose companies and executives to criminal liability under the antitrust laws. Any agreement not to cold-call another company's workers, or to require the current employer's permission before hiring, may be an unlawful no-poach agreement. The DOJ intends to proceed criminally against naked no-poaching agreements, and the agreement can be oral. This one is on you, not the candidate.
  2. A carried non-solicit covenant. There isn't much a company can do to stop employees leaving to join a former colleague, as long as the departing employee hasn't improperly solicited them and isn't subject to an enforceable noncompete. The risk lives in your recruiter or your new hire, not the target.
  3. Trade-secret solicitation. Exercise particular caution to avoid soliciting confidential information; candidates should never be asked to disclose proprietary details, and you must understand any restrictive covenants binding a prospective employee.

On the FTC rule: the noncompete rule is not in effect and is not enforceable, after a district court issued an order on August 20, 2024 stopping the FTC from enforcing it, and the FTC took steps to dismiss its appeal on September 5, 2025. Do not read that as "noncompetes are dead." An estimated 30 million workers, nearly one in five Americans, are subject to a noncompete, and enforceability remains governed by state law. In late 2025 the FTC still forced a pet-cremation company to release 1,800 employees from noncompetes deemed anti-competitive, so state and case-by-case enforcement continues. New York non-solicit enforceability, for instance, is still governed by BDO Seidman v. Hirshberg, 93 N.Y.2d 382 (1999).

There is no public benchmark that sets a safe cap on how many you draw from one employer. Treat sequencing - independent inbound applications, spaced over time - as risk mitigation, not a bright-line safe harbor. The point of the cap is to keep a legitimate draw from reading as a coordinated mass exodus.

When a name is cleared, paused, or dropped

High concentration so farLow concentration so far
Cleared, send now
Proceed with normal personalized outreach
Paused pending check
Confirm non-solicit and trade-secret posture before contact
Sequence and space
Cleared but stagger to avoid a raid pattern
Hold or drop
High concentration plus unclear covenants; pause and reconsider
Covenants cleanCovenants unclear
Two axes decide each name: how clean the covenants are, and how concentrated your draw from this employer already is.

Before you call the shortlist done

Run this checklist against the final list. If any item fails, the name goes back a step or gets logged as paused, not sent.

Send-ready shortlist verification

  • Each name is confirmed current by a live LinkedIn role and commits inside the last 60 days, not org membership alone.
  • Every name is a single, deduped human, cross-matched between GitHub and LinkedIn.
  • Each contact channel was verified live at build time, accounting for ~70% annual data decay.
  • Level and tenure are recorded, with trajectory noted rather than a raw tenure threshold.
  • Activity signals are paired with tenure, so no name is ranked on a profile refresh alone.
  • No reciprocal no-poach understanding exists with the competitor, written or oral.
  • Your recruiter's or hire's carried non-solicit has been checked and cannot taint the draw.
  • Candidates carry documented instructions not to disclose their employer's confidential information.
  • The noncompete check was run per person against the candidate's own state, not once for the company.
  • A concentration cap is set and outreach is staggered so the draw does not read as a mass exodus.

Keeping the map current

This shortlist decays the moment you build it. People leave, org charts shift, and language stacks move - TypeScript overtook Python in the 2025 Octoverse rankings, and next year's leader may differ again. Re-run the GitHub-to-LinkedIn cross-match on any name you did not immediately contact, because a person confirmed current three weeks ago may already be gone, and a departed name may now sit at exactly the Series B startup you also want to source from.

Keep the paused-names log alive too. A name paused today for an unclear non-solicit can clear once that covenant expires, and a name cleared today can become a concentration problem once you have hired two of their colleagues. The legal screen is not a gate you pass once; it is a state you re-check as your own draw from that employer grows. Success is what moves a name across the line from ordinary to risky, so the last thing you do before every send is ask whether this hire, on top of the ones before it, still looks like recruiting rather than a raid.

Questions practitioners ask

Is it legal to recruit a whole team from one competitor?

Recruiting from a competitor is legal in itself. What creates liability is a no-poach agreement between the two employers, which can be criminal under antitrust law and can be oral, plus your recruiter's or hire's carried non-solicit covenant and any trade-secret solicitation. Drawing many people at once also raises anti-raiding exposure over a mass exodus, so cap the number and stagger outreach rather than approaching everyone simultaneously.

How do I confirm someone in a competitor's GitHub org still works there?

Cross-match their GitHub organization membership to a current LinkedIn role and recent commit activity. A public org member is likely a current or recent employee even if their LinkedIn is two years stale, but the false positive is an alumnus still listed in the org. Check both a live LinkedIn role and commits inside the last 60 days before you count that person as employed.

Does the FTC noncompete ban mean I can ignore noncompetes now?

No. A district court stopped FTC enforcement of the noncompete rule on August 20, 2024, and the rule is not in effect, but enforceability is back under state law. That means a candidate's cleared or paused status depends on their jurisdiction, so you run the noncompete check per person rather than once per company. New York non-solicits, for example, are still governed by BDO Seidman v. Hirshberg.

How many credible senior candidates can one competitor realistically yield?

Usually one or two at the top. In Refolk's index there are about 47 Kubernetes individual contributors for every engineering director (13,656 versus 290), so seniority scarcity is exponential, not linear. A single competitor's org almost never holds a deep bench of director-level leads, which is why a whole-team draw ends up individual-contributor heavy and why you should not build a plan that assumes several senior hires from one company.

What reply rate should I expect when confirming these names are live?

Average LinkedIn InMail response runs 10 to 25%, recruiting-specific InMail lands closer to 18 to 25%, and skilled sourcers using strong personalization reach 30 to 50%. Open-to-Work candidates in the recruiters-only setting respond about 37% higher. Because enumeration is the binding constraint, the leverage is in getting personalization high on a smaller, well-confirmed list rather than blasting a large one.

Try it on your own search

Stop building boolean strings. Just describe the person.

Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.

  • One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
  • Read live at search time, not from a database that went stale last quarter.
  • Watch every step as it runs, and see why each name made the list.

500 free credits on sign-up. No card, no demo call. See real searches.

Read next