# Mapping the Source-Company Universe for a Hard Platform Role

*You can take one hard platform role from a brief to a ranked list of 20 to 30 source companies, each justified or cut on public signals.*

- Canonical URL: https://www.refolk.ai/guides/mapping-source-company-universe
- Pillar: Recruiting and sourcing
- Format: Teardown
- Published: 2026-09-10
- Last reviewed: 2026-09-10
- Reading time: 17 min

You have a hard-to-fill platform role and a hiring manager who wants candidates, not a market-education essay. This guide is for in-house recruiters, sourcers, talent leaders, and founders hiring their own team, and it walks one real decision to the end: which 20 to 30 companies you actually source from, not just the obvious three competitors. I carry a single role - a US Senior Platform Engineer who runs Kubernetes in production - from a role brief to a ranked, evidence-backed universe of source companies, including the non-obvious adjacent ones, with each company justified or cut on public signals.

Most published guides tell you when a target list is ready, how to rate one company's poaching exposure, or what an availability signal means. None walks the company-selection hunt itself. So this is a teardown: the seed list, the adjacent expansion, the companies that looked right but had no depth, the ones cut for freezes, and the intermediate counts you can check your own case against.

## What a finished source-company universe looks like

A finished map is 20 to 40 target companies per role, tiered from direct competitors out to adjacent industries, each marked has-depth or cut with a reason, delivered as a one-page brief. That is the shape published talent-mapping guidance converges on, and it is what a hiring manager can sign off in a twenty-minute kickoff.

The scope numbers are consistent across sources. Focused mapping runs 5 to 10 critical roles at 20 to 40 target companies per role. An initial map takes 5 to 10 business days to produce, yielding a longlist of 20 to 50 named candidates across competitor and adjacent organisations. The calibration deliverable is deliberately light: a one-page brief carrying the target companies, the ICP persona, a pool-size estimate, and five to ten example profiles.

**20-40 - Target companies per role in a focused talent map**

Published TA guidance converges on this range for a single hard role, before cuts.

For a genuinely hard role, you will often start above that range and cut down. A single retained mandate might map and rank 100 or more leaders before anyone gets a call. The point of the tiering and the depth checks below is to spend those cutting decisions where they matter, so the 25 companies you keep are the ones with a real bench and an open door.

#### From raw universe to ranked source companies

| Stage | Figure | Note |
| --- | --- | --- |
| Tiered universe | 40 | competitors, academy, adjacent |
| Passes depth check | 30 | has real bench, not one profile |
| Clears disqualifiers | 25 | no freeze, no off-limits |
| Ranked source list | 25 | delivered on the one-pager |

*A hard role starts wide and narrows through depth and disqualifier checks to a shippable list.*

## Why the skill, not the title, is the binding constraint

The single most expensive mistake in company selection is building the list from a job title. Titles hide rare skills, and a title-based competitor list will map a universe that mostly cannot do the job. Verify depth skill-first, or you will spend a week sourcing the wrong people.

The numbers make this concrete. In Refolk's index of professional profiles, US Senior Platform Engineers who list Kubernetes number 381. Those who list Rust number 6. That is a 63.5x gap inside one title. A team building a "Rust platform" role from a Kubernetes-shaped competitor list will produce a beautiful map of companies that employ platform engineers who cannot do the actual work.

| Skill | Matching people | Top employers (sample) | Kubernetes-to-skill ratio |
|---|---|---|---|
| Kubernetes | 381 | FanDuel, Drata, Qurrent | 1.0x |
| Rust | 6 | Together AI, Veeam, Starbucks | 63.5x |

Read the employer columns, not just the counts. The Kubernetes bench sits at fintech and gaming companies like FanDuel and the compliance-automation firm Drata. The Rust bench sits at AI-infrastructure and backup companies like Together AI and Veeam. Same title, entirely different source-company universe. If you had seeded from "Senior Platform Engineer" alone, you would have missed that the constraint moved the whole map.

> **Rule:** Define the binding skill before you name a single company
>
> Every company on the list must be justified against the specific skill at the required seniority, not the title. A title filter buries the real constraint.

This is why step 1 of the procedure is the role brief and not the competitor list. The biggest payoff of the brief is alignment with the hiring manager. When you walk into kickoff with real example profiles instead of a job-description wishlist, the conversation about what "qualified" means is concrete, fast, and over in twenty minutes. That conversation is where you lock the binding skill.

## Seeding the competitor list, then expanding in tiers

Start with direct competitors, then expand outward in two more tiers: academy companies that reliably develop the skill, and adjacent-industry firms plus recent IPOs and late-stage startups. This tiered method is the documented approach retained search firms use, and it is the difference between a list of three obvious names and a real universe.

The first tier is competitor and adjacent company analysis: map every company in the target market that employs the equivalent role at the required seniority. Treat this as industry intelligence work, not a LinkedIn search. For the Kubernetes role, the seed tier is other fintech and gaming platform teams - the companies whose engineers already run the same stack under the same load.

The second tier adds competitors in other industries plus academy companies that consistently develop great talent, such as the top technology companies. The third tier reaches into adjacent industries, high-profile firms that IPO'd, and late-stage startups with delayed IPOs. The tiering is explicit in the documented method, and the art is in the third tier: identifying which adjacent industries actually overlap.

#### The three tiers of a source-company universe

1. **Adjacent industries** - recent IPOs, late-stage startups, sectors with real skill overlap
2. **Academy companies** - firms that reliably develop the target skill, top tech orgs
3. **Direct competitors** - same market, same role, same seniority

*Each outer layer is added only after the skill is confirmed to exist there at the required seniority.*

Here is the fork that matters, and where I made a wrong turn worth showing. My first instinct for the Kubernetes role was to expand into three speculative adjacent industries - logistics, ad-tech, and travel - on the theory that they run large infrastructure. That is an adjacent add on vibe, not overlap. Before committing sourcer hours, I checked whether the target skill actually appeared at the required seniority in those sectors. It thinly did. Then I checked geography.

The same role returns 381 people in the US and 156 in Germany. That is a 2.44x factor from a single country, and for a remote-friendly role, adding Germany expanded the pool more than all three speculative adjacent industries combined. Supply is concentrated by market maturity, not just sector.

| Country | Matching people | Top employers (sample) | US-to-country ratio |
|---|---|---|---|
| United States | 381 | FanDuel, Drata, Starbucks | 1.0x |
| Germany | 156 | SAP, Tradebyte, AMBOSS, Celonis | 2.44x |

So the corrected expansion was: competitors in fintech and gaming, academy tech companies, one confirmed-overlap adjacent industry, and Germany for the remote-eligible portion. The lesson generalises. Before you add a tier, look at where the skill actually lives.

I ran this search: `Senior platform engineers who run Kubernetes in production at fintech and gaming companies in the US, not just my direct competitors.` - [see the full result list](https://www.refolk.ai/s/7nq6khw7q4).

*Returns named engineers across the competitor and adjacent tiers with the production skill confirmed, so you seed and expand in one pass instead of two.*

This expansion is exactly the friction [Refolk](/) removes: instead of hand-building a tier and then hand-checking whether the skill exists there, you ask for the people at the intersection of skill, seniority, and industry and get the source companies back with them. You still make the tiering judgment; you stop doing the intelligence gathering by hand.

## Confirming a company holds the skill in depth

A company earns a place on the map only when it holds the skill in depth, meaning a real team, not one loud profile. The strongest public depth-and-seniority signal for engineering is GitHub org membership breadth, backed by team-size evidence.

If an engineer is a member of a recognisable company's GitHub org - Vercel, Facebook, Google, Stripe - that confirms employment and suggests they contribute to production-grade code. Org membership is especially useful as a seniority signal: engineers trusted to contribute to a company's public repos are typically mid-level or above. When several engineers at a company show org membership on infrastructure repos, that is a bench.

Team-structure benchmarks let you sanity-check the size. Google's DORA program found that by 2025, 76% of organisations had a dedicated platform team, drawn from a survey of nearly 5,000 technology professionals. Span-of-control gives a rough headcount: average engineering span rose about 34%, from roughly 11 to about 15 engineers per manager. So one platform manager implies a team of a dozen or more - a check you can run against the org chart you are reverse-engineering.

**76% - Organisations with a dedicated platform team by 2025**

From Google's DORA survey of nearly 5,000 technology professionals. Use it to judge whether a company's platform bench is plausibly deep.

Depth is confirmable but cheap to fake, which is the trap. Public signals are gameable individually, so a depth judgment must aggregate across a team. One staff engineer with an impressive profile is a false positive for depth. The mechanism that makes aggregation necessary is exactly why the 76% platform-team benchmark matters more than any single hero profile: you are looking for the shape of a team, not the brightness of one person.

## How this goes wrong: the failure modes

The most valuable part of a source-company map is knowing where it lies to you. These are the documented failure modes for company selection, each with what the false positive looks like and how to clear it.

**Thin bench mistaken for depth.** A company shows a few senior titles but no team behind them. The false positive is one loud staff engineer with a big GitHub profile. Check org membership breadth and team size, not one profile. Thousands of repos with no stars, no forks, and no README files often indicate auto-generated or tutorial-following activity, not production depth.

**Title matching over skill matching.** "Platform Engineer" spans wildly different stacks. The 63.5x Kubernetes-to-Rust gap in the table above shows that a title filter alone will bury the real constraint. Match on the confirmed skill at the required seniority, always.

**Adjacent add with no evidence.** An adjacent industry gets added on a hunch, not on overlap. Before committing sourcer hours, confirm the target skill actually appears there at the required seniority. This is the wrong turn I took above; the fix is a single-query check before you commit the tier.

**Stale map read as current.** With median US tenure at 3.9 years, a six-month-old longlist has moved. Check the last-verified date against a six-month talent-flow window before outreach. Fortune 500 CHRO churn runs about 6% every six months, the closest documented proxy for how fast a senior map decays.

**Freeze mistaken for opportunity.** A company still shows open reqs but sourcing is paused. The false positive is stale ATS postings: many ATS systems keep stale postings live even during slowdowns. Verify on the official careers page and cross-check WARN Act filings and public layoff trackers.

**Freeze over-read as decline.** A freeze is not a layoff. The company may still hold deep talent worth mapping for a later window. Cut it from the active list, but flag it for a trigger-based refresh rather than deleting it.

**Off-limits ignored.** Sourcing from a firm your client has a client or partner relationship with. Off-limits lists are a documented artifact - in the tech no-poach case, HR departments maintained written lists of hires that were off-limits. Confirm whether such constraints exist and clear them with the hiring manager first.

**GitHub absence read as absence of skill.** Many strong engineers work in private repos. No public activity for six months or more could mean a career change or a shift to private work; either way it requires investigation, not an automatic cut.

> **Watch out:** A live posting is not proof a company is sourcing
>
> Stale ATS postings stay up during slowdowns. If a company lost people recently and none of those roles reappeared on the careers page, that silence is the signal, not the postings.

## The disqualifier screen: freeze, off-limits, and thin bench

Three disqualifiers cut a company from the active map: a hiring freeze, an off-limits or no-poach constraint, and a bench too thin to justify sourcer hours. Screen for all three, and log every cut with its reason so the decision is auditable.

On freezes: during a freeze, open requisitions are typically put on hold, budget approvals are suspended, and recruiting teams are instructed to pause sourcing entirely. Even backfills and roles opened because someone left may be blocked. Freeze trackers compile from earnings calls, public layoff trackers, careers pages, workforce insights, and WARN Act filings. Read the absence of new postings, not the presence of old ones.

On off-limits and no-poach: in October 2016 the DOJ and FTC issued joint antitrust guidance for HR professionals identifying employment practices that violate antitrust law. A no-poach agreement is where two or more employers agree not to hire or solicit each other's employees. These are real, documented artifacts, and you clear them with the hiring manager before sourcing, not after.

| Disqualifier | Public signal to check | Verdict when it fires |
|---|---|---|
| Hiring freeze | Careers page, WARN filings, layoff tracker | Cut from active list, flag for later |
| Off-limits / no-poach | Client and partner relationships, written lists | Cut and confirm with hiring manager |
| Thin bench | GitHub org breadth, team size, DORA benchmark | Cut, keep only if depth reappears |

One nuance from the sources: they disagree on whether the disqualifier screen happens before or after you name candidates. One documented method frames it as continuous, with the list evolving as interviews begin and feedback arrives, some companies added on fresh insight and others removed for low-quality leads or disinterest. So treat the depth check and the disqualifier screen as a loop, not a clean one-time gate.

## The procedure, end to end

Here is the full method as a repeatable sequence, matched to the timeline the sources document. It runs about one to two working weeks for a single hard role.

#### From role brief to ranked source-company universe

1. **Write the role brief and ICP** - Turn the job description into an ideal-candidate persona with target companies, and confirm it with the hiring manager. Done when they sign off on real example profiles, not a wishlist.
2. **Seed the direct-competitor list** - List every company employing the equivalent role at the required seniority in the target market. This is industry intelligence work, not a LinkedIn search. Done when you have a first-tier list.
3. **Expand into academy and adjacent tiers** - Add talent-factory companies, then adjacent-industry firms, recent IPOs, and late-stage startups. Done when you have a three-tier universe, each tier's skill overlap confirmed.
4. **Reverse-engineer org charts and confirm depth** - Verify each company holds the skill in depth using GitHub org membership breadth, team size, and public work. Done when every company is marked has-depth or thin.
5. **Screen for disqualifiers** - Cut companies under freeze, off-limits or no-poach constraints, or with too thin a bench. Treat this as a loop, not a gate. Done when every cut is logged with a reason.
6. **Name the longlist** - Name every individual in a target role across the surviving companies, recording current company, estimated tenure from public signals, and reporting level. Done when you have 20 to 50 raw names.
7. **Rank and deliver the one-pager** - Ship the calibration brief with target companies, the ICP persona, a pool-size estimate, and five to ten example profiles. Done when the hiring manager signs off.

> A title-based competitor list maps a universe that mostly cannot do the job you are hiring for.

## Ranking the survivors and reading the seniority tier

Rank the surviving companies by bench depth, door status, and skill match, then read whether your role sits at a tier the pool can supply. The seniority band changes the whole search, not just the count.

Refolk's index shows 381 US Senior Kubernetes platform people versus 36 at Director level - a 10.6x gap. A Director search is a different animal: a far smaller, mostly-passive set, mapped from different companies.

| Band | Matching people | Top employers (sample) | Senior-to-band ratio |
|---|---|---|---|
| Senior | 381 | FanDuel, Drata | 1.0x |
| Director | 36 | Zocdoc, athenahealth, Platform9, Fiserv | 10.6x |

Notice the employer shift again: the Director bench surfaces healthtech and payments names like Zocdoc, athenahealth, and Fiserv that barely appear at Senior. If your role is a Director, your source companies are not the same 25 you found for the Senior version, and the query that finds them looks for people who previously led SRE or platform teams in those sectors. This is why leadership maps decay differently and get an annual refresh, while engineering maps get a quarterly one.

#### Ranking a source company for a hard role

Horizontal axis runs from Thin bench to Deep bench. Vertical axis runs from Door closed (freeze/off-limits) to Door open.

| Quadrant | What it means |
| --- | --- |
| Deep bench, door closed | Flag for a trigger-based refresh when the freeze lifts |
| Deep bench, door open | Source here first; this is your core universe |
| Thin bench, door closed | Cut and do not revisit |
| Thin bench, door open | Deprioritise; verify before spending hours |

*Plot each survivor on bench depth against door status to decide where to spend sourcer hours.*

## Keeping the map current

A source-company map is a living document, not a one-time deliverable. Refresh high-velocity functions like engineering quarterly, run executive and specialist roles annually, and add a light pass whenever a req opens or a talent-supply event fires.

The underlying mobility justifies the cadence. Median US tenure is 3.9 years and Fortune 500 CHRO churn runs about 6% every six months, so named senior talent moves quietly under a static list. Trigger-based refreshes matter too: when compensation benchmarks shift or a competitor's layoff creates a talent-supply event, re-run the map before the window closes. View talent-flow data over 6, 12, or 24-month windows, and never send outreach against a company whose last-verified date is older than your flow window.

#### Before you call the source-company map done

- [ ] The binding skill is defined at the required seniority, and every company is justified against it, not the title.
- [ ] The universe is tiered: direct competitors, academy companies, and confirmed-overlap adjacent industries.
- [ ] Each adjacent industry and country was added only after confirming the skill exists there at the required seniority.
- [ ] Every company is marked has-depth from aggregated signals, or cut as thin, never kept on one hero profile.
- [ ] Freeze, off-limits, and thin-bench cuts are each logged with a reason and a verification source.
- [ ] Frozen-but-deep companies are flagged for a trigger-based refresh, not deleted.
- [ ] Last-verified dates are inside your 6-month talent-flow window before any outreach.
- [ ] The one-pager carries target companies, the ICP persona, a pool-size estimate, and five to ten example profiles.

The end state is not a static list you hand off and forget. It is a ranked universe you can defend company by company, refresh on a cadence tied to how fast the function moves, and re-open the moment a freeze lifts or a competitor sheds people. That is the difference between a source-company map that gets you candidates and one that just gets you a meeting.

## Frequently asked questions

### How many companies should be on a source-company list for one hard role?

Aim for 20 to 40 target companies per role, which is where published talent-mapping guidance converges for a focused scope. For a genuinely hard role you will often land at 20 to 30 after cutting for thin bench and freezes. Fewer than that and you starve the longlist; many more and you spread sourcer hours too thin to verify depth on any of them.

### How do I find adjacent industries to source from instead of just direct competitors?

Work in tiers: direct competitors first, then academy companies that reliably develop the skill, then adjacent-industry firms, recent IPOs, and late-stage startups. The discipline is to add an adjacent industry only after confirming the target skill actually appears there at the required seniority, not on a hunch. Check that public depth exists before you commit sourcer hours to the tier.

### How can I tell a company really employs the skill in depth versus one loud engineer?

Look for breadth of GitHub org membership and team size, not a single profile. Org membership confirms someone contributes to production code and signals mid-level or above, but one staff engineer with a big profile is not a bench. Thousands of repos with no stars, forks, or READMEs often indicate auto-generated or tutorial activity, so aggregate signals across several people before marking a company has-depth.

### How often does a source-company map go stale?

Refresh high-velocity functions like engineering quarterly and lower-velocity executive or specialist roles annually, with a light pass when a req opens. Median US job tenure is 3.9 years and Fortune 500 CHRO churn runs about 6% every six months, so a six-month-old longlist has already moved. Re-verify last-checked dates against a six-month talent-flow window before any outreach.

### How do I avoid sourcing from a company that is secretly frozen?

Read the absence of new postings, not the presence of old ones. Many ATS systems keep stale postings live during slowdowns, so confirm on the official careers page and cross-check WARN Act filings and public layoff trackers. If a company lost people recently and none of those roles reappeared, that silence is the signal that sourcing is effectively paused.

### Is a hiring freeze a reason to permanently cut a company from the map?

No. A freeze is not a layoff, and a frozen company may still hold deep talent worth mapping for a later window. Cut it from the active longlist so you do not waste sourcer hours, but keep it flagged for a trigger-based refresh when the freeze lifts. A freeze on its own is not a reliable signal in either direction, so watch what else is happening around it.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/mapping-source-company-universe*
