Re-Engaging Past Finalists When a Matching Role Reopens
You will take a reopened req, pull the right past finalists, re-verify each from public signals, and ship a ranked, lawfully-contactable list before any fresh search.
Key takeaways
- Rediscovered candidates now account for 46% of sourced hires, up from 26% in 2021, yet at a 200-hire firm under 5% of the 400 to 1,200 past finalists ever get re-engaged.
- The re-engagement edge is a timing arbitrage, not a quality one: finalists were already vetted, so the only stale variable is whether they are still reachable and open.
- LinkedIn's Open to Work signal is the single most predictive re-verification check, lifting recruiter reply rates from about 5% to about 15%.
- Legal exposure scales with record age, and the cliff is roughly 24 months; a warm bench older than two years is a liability, not an asset.
- California's CPRA requires keeping applicant records four years, but that retention duty is not a license to contact, and reading it as one violates the outreach basis.
- In Refolk's index the US Python-engineer pool is about 13x the UK's (55,206 versus 4,229), so in thin markets re-engaging finalists is a materially larger share of reachable talent.
A role you filled or paused just reopened. The fastest, cheapest candidates are not in a fresh search - they are your past finalists and silver medalists, already vetted, sitting in the ATS. This guide is for in-house recruiters, sourcers, and founders doing their own hiring, and it gives you an end-to-end method to pull the right past finalists, re-verify each one's current public status, gate the list for lawfulness, and ship a ranked re-engagement list before you touch a new external source.
The problem is not finding these people. It is knowing which stale records are still worth a message and whether it is lawful to send it. Every vendor page sells you a rediscovery button; none of them tell you the record from eight months ago is now a promotion at a new employer, or that a warm bench older than two years may be illegal to contact. This is that procedure.
Why past finalists beat a fresh search
Past finalists are the highest-yield pool most teams have and the one they mine least. Rediscovered candidates - people already in your CRM or ATS - now make up 46% of sourced hires, up from 26% in 2021, while a separate vendor figure puts it at 44% of great hires already sitting in your applicant tracking system. That is roughly half of sourced hiring coming from records you already own.
The gap between that share and how little the pool gets worked is the whole opportunity. At a company making 200 hires, final-round candidates accumulated over 24 months typically number 400 to 1,200 people, and under 5% ever get re-engaged. The pool exists, it is vetted, and it is almost untouched.
The reason this works is worth being precise about. Re-engagement is a timing arbitrage, not a quality one. A silver medalist was already assessed against your bar; the only variable that changed since you rejected them is availability. That is why re-verification, not re-sourcing, is the core of this job. You are not asking "is this person good" again. You are asking "is this person still there, still relevant, and now open."
Finalists were already vetted. The only thing that went stale is whether they are still reachable and open.
Geography sharpens the case. In Refolk's index, the US pool of software engineers with Python is 55,206, while the equivalent UK pool is 4,229 - the US pool is about 13 times larger. In a thin market like the UK, re-engaging past finalists is not a marginal efficiency; it is a materially larger fraction of all reachable talent for the skill.
What qualifies as a silver medalist
A silver medalist is a candidate who was not hired but reached the final rounds, where usually minor details separated them from the person hired. That is the concept. The operational definition, the one that lets two recruiters build the same list, lives in three checkable ATS fields.
- Stage reached. Final round or equivalent. Someone who did a single screen is not a finalist.
- Rejection reason. Must be in the set of position filled or timing, not failed assessment. This is the field that separates "we hired someone else" from "we said no."
- Scorecard signal. Interview feedback that placed them near the top. As one head of talent acquisition put it, being able to filter on scorecard responses is "literally the definition of a silver medalist."
Rediscovery tools expose exactly these fields: you can search across ATS and CRM profiles filtering by stage reached, rejection reason, source, DEI attributes, and interview feedback. If your eligibility rule cannot be written as a filter on those fields, it is a gut call, and gut calls do not produce a list two people would agree on.
The lawfulness gate you cannot skip
Before you re-verify or contact anyone, every record must have a documented lawful basis, and any record older than your defensible retention window either gets re-consented or dropped. Vendors skip this step; it is non-negotiable. Legal exposure scales directly with record age, and the cliff is roughly 24 months.
Under GDPR the two relevant bases are legitimate interest under Article 6(1)(f) or consent under Article 6(1)(a). For core recruitment, legitimate interest is typically appropriate - you do not need consent to read a CV - but it cannot be asserted informally. It requires a documented Legitimate Interest Assessment recording what the interest is, whether processing is necessary, and whether the candidate's rights outweigh it.
Here the sources genuinely disagree, and you should know it. Some argue legitimate interest covers re-contact for a new role; others argue that keeping someone in a talent pool for future roles needs active consent that you renew periodically. This is not a question you resolve by reading a blog. Get your data protection officer to make the call for your organisation and record it.
Retention windows differ by regime, and mixing them up is where teams get hurt.
| Regime / record | Retention window |
|---|---|
| GDPR unsuccessful applicant | ~6 months |
| GDPR consented talent pool | 12 to 24 months |
| GDPR, no re-contact | Indefensible beyond 24 months |
| California (CPRA) applicant records | 4 years |
These windows are not equivalent, and that is the trap. The GDPR rows are maximum-defensible windows that push toward deletion. The California row is a statutory minimum that requires retention: since January 2023 the CCPA exemptions expired and full privacy rights extend to job applicants, and employers must retain applicant personnel records for four years from creation. A US-EU team running one blanket policy will violate one regime or the other.
The upshot inverts the vendor pitch. A "warm bench" older than two years is usually a liability, not an asset. Run the gate first so you never spend re-verification time on a record you cannot lawfully message.
Re-verifying current status from public signals
Re-verification means comparing every stored field against the person's live public profile and tagging what changed. This is the step that turns a stale list into a current one, and it is where the message either lands or embarrasses you.
There is no single magic check beyond a field-by-field comparison of the stored ATS record against the current LinkedIn, GitHub, or open-web profile. Read four things and tag the record:
- Employer. Still there, or moved. A candidate flagged "at Company X" may have left months ago.
- Title. Same, or promoted. Referencing an old title in outreach signals you did not look.
- Location. Same, or relocated - which can change eligibility for an onsite or in-region role.
- Openness. LinkedIn's Open to Work spotlight, read directly on the profile.
Open to Work is the most predictive of the four because it measures the exact variable that went stale: availability. Once a candidate privately shares their goals, LinkedIn Recruiter users see Open to Work on the profile, and you can filter for it under Spotlights at the top of the search results. A public badge is the everyone-visible variant, adding an #OpenToWork frame to the profile photo. Over 200 million members have activated the signal, and about 40 million showed the public badge in a single month in mid-2024.
But read it carefully. The signal can be recruiter-only or public, and it can be stale: LinkedIn prompts a user to turn it off when they start a new position, but not everyone does. An active badge is a strong prior, not proof. Confirm the current employer and title before you rely on it.
Re-verifying one stale record
- EmployerCompare stored company to the live profile; tag still-there or moved
- TitleCompare stored title; tag same or promoted
- LocationCompare stored location; tag same or relocated
- OpennessRead the Open to Work spotlight; tag open or unknown
The payoff for reading openness is measurable. When recruiters approach candidates on LinkedIn the response rate is about 5%, but for people with Open to Work activated it is about 15% - three times higher. That single tag is the difference between a cold list and a warm one.
This is the step Refolk was built to compress. Instead of opening each stale record and hunting across profiles for who moved and who is open, you can describe the current state you want and let the index resolve it against live public signals.
Refolk turns "who on this list is still there and now open" from an afternoon of tab-switching into a single query, which matters most in thin markets where the finalist pool is a large share of everyone reachable.
The end-to-end procedure
Run these seven steps in order. The whole pass for a typical reopened req takes a focused half-day, and the lawfulness gate at step three is the one people cut and the one that creates liability.
Reopened req to ranked re-engagement list
- Scope the req and define eligibilityWrite down the required stage, acceptable rejection reasons, and must-have scorecard signals before pulling. Done is a written filter two recruiters would apply identically.
- Pull the matching pool from the ATS or CRMFilter stored records by stage reached, rejection reason, source, and interview feedback, then deduplicate. Done is a clean list of comparable-role finalists.
- Apply the retention and lawfulness gateDrop or re-consent records older than your defensible window and confirm a lawful basis for each survivor. Done is every record carrying an LIA on file or fresh consent.
- Re-verify current public status one by oneCompare each stored employer, title, and location against the live profile and check Open to Work. Done is every record tagged still-there, moved, promoted, relocated, or open.
- Score and rank the survivorsRank on interview recency, scorecard strength, and openness signal. Done is a ranked list whose top tier is strong scorecard plus active openness plus continued relevance.
- Draft segmented, specific outreachReference the prior process and name the specific role and comp per segment. Done is messages that avoid generic openers and name why you are back.
- Send, sequence, and measureRun a multi-touch sequence and track reply rate against a cold baseline. Done is a measured reply rate you can compare to the 5 to 8% recruiting benchmark.
Some practitioners add a step zero: check the silver-medalist list before you even write the new job post. Mark strong candidates the day you reject them, note the role, the reason, and their status, and make checking that list the first move on every new req. That discipline turns this reactive playbook into a standing habit.
How to score and rank the survivors
Rank on three signals, in this order of weight: openness, scorecard strength, and interview recency. The top tier is a candidate with a strong scorecard who shows an active openness signal and remains relevant to the reopened role. There is no published authoritative threshold set for this, so the rubric below is built from the documented signals rather than borrowed from a vendor.
OPENNESS (0-3) 3 = Open to Work active and confirmed current 2 = Recently changed jobs or updated profile 1 = No signal, employer unchanged 0 = Just started a new role (deprioritise, revisit later) SCORECARD (0-3) 3 = Top of the final-round slate, lost on minor details 2 = Strong finalist, one soft area 1 = Made final round, mixed feedback RECENCY (0-2) 2 = Interviewed within 6 months 1 = Interviewed 6-18 months ago 0 = Interviewed over 18 months ago (recheck lawful basis) TIER: sum >= 7 = message first; 4-6 = second wave; <4 = hold or drop
Adjust weights to your market; in thin markets, weight openness lower because reachable options are scarce.
The matrix below is the fast version of the same judgement when you are triaging quickly.
Which finalist to message first
How this goes wrong
The failure modes below are where re-engagement lists produce embarrassment, wasted effort, or legal exposure. Each has a false positive that looks like success and a specific check that catches it.
| Failure mode | What it looks like | The check |
|---|---|---|
| Silver medalist defined by gut | Anyone who "interviewed once" gets added | Require stage=final AND reason in {position filled, timing} |
| Stale record treated as current | Outreach references an old title or employer | Field-by-field compare to the live profile before sending |
| Open to Work misread | A stale or recruiter-only badge read as active looking | Confirm current employer; badge may survive a job start |
| Retention breach | A "warm" 3-year-old record contacted anyway | Apply the 6/24-month gate; confirm an LIA or consent exists |
| Legitimate interest assumed | New-role re-contact justified without review | Get DPO sign-off; sources disagree, do not assume |
| Generic re-engagement copy | High open rate, near-zero replies | Never "I came across your profile"; name role and comp |
| CCPA retention read as permission | A California record contacted because it is "on file" | Separate the 4-year retention duty from the outreach basis |
Two of these deserve extra weight. The first is the stale-record trap: the whole value of re-engagement is that you already know these people, and referencing an outdated title tells them you did not check, which erases the advantage. The second is the retention-as-permission trap, which crosses from wasted effort into legal risk. Keeping a record because a statute requires it says nothing about whether you may market to it.
Writing outreach that gets a reply
Re-engagement copy fails in one predictable way: it reads like cold outreach to someone who is not cold. The candidate remembers your process, so a generic "I came across your profile" opener signals you have forgotten them. Reference the prior process and name the specific role and comp.
The reply-rate stakes are why specificity matters. The table below sets the baselines you are measuring against.
| Outreach type | Reply / response rate |
|---|---|
| LinkedIn recruiter cold approach | ~5% |
| LinkedIn candidate with Open to Work | ~15% |
| Recruiting cold email (benchmark) | 5 to 8% |
| Personalized cold email (secondhand cite) | 40 to 50% |
Treat the 40 to 50% figure with caution - it is a secondhand marketing cite, not a peer-reviewed result. The load-bearing numbers are the recruiter cold baseline of about 5% and the Open to Work lift to about 15%. Your re-engagement list should beat the cold baseline handily, because you are combining a warm relationship with a live openness signal. If it does not, your copy is generic or your re-verification was sloppy.
Hi [first name], We spoke last [month/quarter] when you reached the final round for [prior role] here. That decision came down to fine margins, and you stayed on my shortlist. The [reopened role] just opened again - [one line on scope], [comp or band]. Given how close last time was, you were the first person I wanted to tell. Are you open to a short call this week to see if the timing works now? [Your name]
Fill the four bracketed fields from the ATS and the reopened req; keep it under 90 words.
Sequence the send. A five-stage multi-touch sequence gets roughly twice the replies and about a 68% higher interested rate than a one-off message. Space the touches, vary the angle, and track reply rate per segment so you can tell whether the openness tag or the scorecard tier is driving results.
Before you call the list done
Run this checklist on the finished list before the first message goes out. It catches the failures above and confirms the list is both worth sending and lawful to send.
Re-engagement list readiness
- Every name qualifies on stage=final AND rejection reason in {position filled, timing}
- The pull is deduplicated and matched to the reopened req, not a loosely similar role
- Every record has a documented lawful basis - an LIA on file or fresh consent
- No record exceeds your defensible retention window without re-consent
- Each record is tagged still-there / moved / promoted / relocated / open after live re-verification
- California records are handled for retention without treating four-year storage as a contact license
- The list is ranked, with a top tier of strong scorecard plus active openness plus relevance
- Each message names the specific role and comp and references the prior process, no generic openers
- A multi-touch sequence is set up with reply rate tracked against the 5 to 8% cold baseline
Keeping the habit current
The reactive version of this playbook works, but the durable win is making it a standing motion. Tag finalists the day you reject them - role, reason, status - so that the pull at step two is a filter, not an archaeology dig. Make "check the silver-medalist list" the first step on every reopened or new req, before the job post is written.
Two things go stale and need re-checking on a cadence rather than once. First, lawful basis: retention windows and the legitimate-interest-versus-consent question shift, so review your policy with your DPO periodically rather than treating one sign-off as permanent. Second, openness signals decay fast - a badge that was live a quarter ago may be gone - so re-verify at the moment you decide to send, not the moment you build the list. Do those two things and the reopened-req scramble becomes a fifteen-minute pull from a pool you already trust.
Questions practitioners ask
Can I contact a past finalist about a new role under legitimate interest, or do I need fresh consent?
Sources disagree, so get your data protection officer to sign off rather than assuming. For core recruitment, legitimate interest under GDPR Article 6(1)(f) is often the appropriate basis and does not require consent to read a CV, but it must be backed by a documented Legitimate Interest Assessment. Some sources argue that keeping someone in a talent pool for future roles needs active, periodically renewed consent. Do not treat this as settled.
How old is too old for a past-finalist record?
For unsuccessful applicants, roughly six months aligns with discrimination-claim windows. For consented talent pools, 12 to 24 months is the widely accepted range, and beyond 24 months without re-contact or renewed consent, retention is very hard to defend. Apply the gate before you re-verify anyone, because re-verifying a record you cannot lawfully contact wastes time and creates exposure.
Does California's four-year retention rule mean I can keep contacting those candidates?
No. California requires employers to retain applicant personnel records for four years from creation, but that retention obligation is separate from any license to send outreach. Reading the four-year rule as permission to market is a common trap. Keep the record as required, but qualify contact against your outreach basis exactly as you would any other candidate.
Is the Open to Work badge a reliable sign someone is still looking?
It is the clearest documented signal but not proof. It can be set to recruiter-only or public, and it can be stale: LinkedIn prompts users to turn it off when they start a new position, but not everyone does. Treat an active signal as a strong prior that raises reply rate from about 5% to about 15%, then still confirm the person's current employer and title before referencing them.
Why re-engage past finalists before running a fresh external search?
Because the pool is already vetted and almost untouched. Rediscovered candidates make up 46% of sourced hires, yet under 5% of a firm's past final-round candidates get re-engaged. The only variable that went stale is availability, which you can re-verify from public signals in minutes. In thin markets the case is even stronger: in Refolk's index the UK Python-engineer pool is 4,229 versus 55,206 in the US.
What separates a silver medalist from anyone who interviewed once?
Fields, not gut feel. Require stage equal to final round AND a rejection reason in the set of position filled or timing, not failed assessment. A silver medalist is someone minor details separated from the person hired, which shows up in scorecards. If you cannot point to the ATS field that qualifies them, they do not belong on the list.
Try it on your own search
Stop building boolean strings. Just describe the person.
Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.
- One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
- Read live at search time, not from a database that went stale last quarter.
- Watch every step as it runs, and see why each name made the list.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
500 free credits on sign-up. No card, no demo call. See real searches.