# The Sourced-Candidate Handoff Standard: Accept, Return, or Hold

*You can grade any sourced candidate record as accept, return, or hold, and a second reviewer applying this standard reaches the same verdict.*

- Canonical URL: https://www.refolk.ai/guides/sourced-candidate-handoff-standard
- Pillar: Recruiting and sourcing
- Format: Standard
- Published: 2026-09-20
- Last reviewed: 2026-09-20
- Reading time: 16 min

A sourced candidate record is handed off dozens of times a week, and the argument that follows is always the same: the recruiter says the profiles are wrong, the sourcer says the bar keeps moving. This guide is for in-house recruiters, sourcers, talent leaders, and founders doing their own hiring, and it gives you a gradeable definition of done. After reading it you can grade any sourced record as Accept, Return, or Hold, and a second reviewer applying the same criteria reaches the same verdict.

Most published handoff advice stops at one vague SLA sentence and some profile-writing tips. That is not enough to settle a dispute. What follows is a definition of done you can adopt as team policy, covering both the person and the company as pass or fail checks a reviewer can run in minutes.

## Why the handoff bar keeps moving

The bar moves because the trigger is undefined, not because reviewers disagree on quality. Fix the trigger to one explicit moment and most disputes disappear.

Documented practice places the sourcer-to-recruiter handoff at three different moments. One source says a sourced lead becomes a candidate when they respond positively to outreach and baseline qualification is confirmed. Another says the recruiter takes over once the candidate confirms interest in moving forward. A third describes the common field reality: most sourcers ask the candidate to apply to the job, and once they have, they are in the ATS and the sourcer can hand them off. Three sources, three triggers.

That ambiguity is the root of the fight. When the sourcer assumes handoff happens at "responded" and the recruiter assumes it happens at "applied," each thinks the other owns follow-up, and the candidate falls through the gap. The named failure is concrete: a sourcer identifies strong profiles and sends outreach, but passes candidates without confirming salary expectations or availability, and recruiters then reject them late in the process, citing misalignment. That is not a quality problem. It is a contract problem.

> **Rule:** Name one trigger in the SLA
>
> The handoff SLA must name exactly one moment ownership transfers: responded, confirmed interest, or applied. Any record graded against an unnamed trigger is ungradeable by definition.

The mechanism that fixes this is the same one an SLA already uses: a defined transition point that clarifies when a sourced individual becomes a recruiter-owned candidate. This standard assumes your SLA has picked one. Everything downstream grades against it.

## The three verdicts: Accept, Return, or Hold

Every sourced record resolves to one of three verdicts. Accept means the recruiter takes ownership now. Return means the record is fixable by the sourcer today. Hold means a time-sensitive or unresolvable blocker stops the record from moving.

No public source names a formal three-way accept, return, or hold system for handoffs. This framework is my own contribution, built from the raw material in the research. The distinction that makes it work is where a problem gets fixed:

- **Accept**: all person, company, and compliance criteria pass. Recruiter assumes the record within the SLA window.
- **Return**: a qualification field is missing or an evidence claim is thin, and the sourcer can resolve it. Comp range blank, availability unknown, a reply over-read as interest, no lawful-basis record.
- **Hold**: a blocker exists that the sourcer cannot clear on the spot, or that decays with time. Off-limits clearance pending, identity conflict unresolved, opt-out flag present, evidence older than the compliance window.

The reason to separate Return from Hold is operational. A Return goes straight back to the sourcer with a specific fix. A Hold goes to a queue, and that queue needs an expiry, because some blockers are legal clocks, not to-do items.

#### Routing a flawed record

Horizontal axis runs from Sourcer can fix now to Blocker is external or unresolvable. Vertical axis runs from Time-neutral to Time-sensitive.

| Quadrant | What it means |
| --- | --- |
| Missing comp or availability | Return to sourcer with the specific field to fill |
| Off-limits check not yet run | Hold and route to ops for clearance |
| Reply over-read as interest | Return and ask for explicit willingness to proceed |
| Opt-out flag or aging notice window | Hold with an expiry date, do not sit on it |

*Whether the sourcer can fix it, and whether time is against you, decides Return versus Hold.*

## The person: identity, interest, and contactability

A record passes the person checks when identity is resolved to one human, interest is explicitly confirmed, and there is a lawful way to reach them. Any one of these failing sends the record back or on hold.

### Identity resolved to one person

Two-source identity resolution beats either platform alone, for a documented reason. LinkedIn primarily represents professional identity and career history, while GitHub provides public technical-work evidence. They fail in opposite directions: LinkedIn profiles can overstate scope and underrepresent hands-on work, and GitHub profiles can omit years of private employment. Requiring agreement across both, rather than trusting one canonical field, catches the errors each makes alone.

The check: the employer or domain and the saved evidence URL reconcile across sources. The false positive is the wrong-person match, where the same name at a different employer gets merged into one record. When identity lies, it looks like a clean profile with a subtle mismatch: the LinkedIn employer and the GitHub bio employer point to different companies with no explanation. Reject same-name, conflicting-domain matches. That is a Hold until resolved, never an Accept.

### Interest that is real, not polite

Grade interest against the channel it came through, not gut feel. A warm-sounding reply on a low-yield channel is weaker evidence than the same reply on a high-yield one.

| Channel | Average reply | Recruiting / HR vertical |
| --- | --- | --- |
| Cold email (all sectors) | 3.43% | recruiting among strongest |
| Cold email "good" bar | 5%+ | - |
| LinkedIn InMail | 10 to 25% | 18 to 25% (highest) |
| Email sequence, 5 touches | 21.3% cumulative | recruiting |

Recruiting InMail replies at roughly five times the all-sector cold email average of 3.43 percent. That context changes how you read a "yes." The other trap is the over-read reply: a polite "not now" logged as interest. The check is textual. The reply must show explicit willingness to proceed, not mere acknowledgement. If it does not, that is a Return, and the fix is a follow-up that asks the direct question.

**18 to 25% - Recruiting InMail response rate, the highest of any vertical**

All-sector cold email averages 3.43%, so the channel a reply arrived on is part of the evidence.

### Contactability and comp

Interest without comp range and availability is the single most common thin handoff. High-performing teams confirm baseline qualification before handoff: right experience level, open to the role type, within compensation range. When those fields are blank, the record is a Return. The whole point is to stop the late-stage rejection where a recruiter discovers the misalignment the sourcer never checked.

## The company: current employer and source-company clearance

A record passes the company checks when the current employer is confirmed from dated evidence and that employer is cleared against the off-limits list. This is the half of the handoff most guides skip entirely, and it is where the expensive mistakes live.

### Current employer, from the most recent dated evidence

The stale-employer failure is quiet. A GitHub bio or an old LinkedIn entry shows a role the person left two years ago. Because GitHub profiles can omit years of private employment, the absence of a recent employer is not proof of anything. The check is to anchor on the most recent dated evidence across sources, not the most prominent field. If the latest dated signal is old or ambiguous, Hold and re-verify rather than Accept on a guess.

### Source-company clearance

Off-limits is the highest-leverage pass or fail check because scale makes it invisible. An off-limits agreement prevents a recruiter from targeting people at one client for a role at another. The AESC standard stipulates a firm will not approach a company it has worked for during the previous two years.

| Clearance type | Duration |
| --- | --- |
| AESC standard off-limits | 2 years from last engagement |
| Common off-limits floor | 1 year from last placement |
| Open-ended (supplier agreement) | duration of contract |
| Large-firm list scale | tens of thousands of companies per year |

A single large firm's list can reach tens of thousands of companies in a year, and healthcare firms doing 50 to 100 engagements can hold 50 to 250 or more organizations on a no-contact list. At that scale an uncleared employer is statistically likely, not rare. ATS systems encode this: when an account is off-limits, by extension all candidates associated with it become off-limits.

The check must run before further contact, not after. An employer surfaced against the no-contact list after the opener already went out is a breach you cannot take back. Uncleared employer means Hold or drop, never Accept.

> **Watch out:** Clearance is a pre-send gate, not a post-hoc audit
>
> Running off-limits after outreach protects nobody. The employer must be checked against the no-contact list before the record advances, and a pending check is a Hold on its own.

This is where a plain-English search removes real friction. Instead of pulling a list and manually diffing it against a no-contact roster, you can exclude off-limits companies at the query stage.

I ran this search: `Data scientists in the US who list a current employer on LinkedIn and have a matching GitHub profile, excluding anyone at off-limits companies.` - [see the full result list](https://www.refolk.ai/s/77f2ecxyme).

*Returns candidates whose current employer is confirmed across LinkedIn and GitHub, with off-limits employers filtered out before they reach your review queue.*

[Refolk](/) does the cross-source employer confirmation and the exclusion in one pass, so the record arrives at review with two of the hardest company checks already satisfied.

## The compliance metadata every record carries

A record cannot be Accept without lawful basis, a date of collection, the channel, and any opt-out flag attached. Missing metadata is a Return; an aging notice window or a live opt-out is a Hold.

| Gate | Requirement |
| --- | --- |
| Notify sourced candidate | within ~30 days of collection |
| Lawful basis (outreach) | legitimate interest + documented LIA |
| Talent-pool retention | explicit consent required |
| Opt-out propagation | spread across org, honor request |

Under legitimate interest, sourced candidates who did not actively apply require particular care: you must inform them you hold their data typically within 30 days of collecting it, and before you use it for any purpose. That clock is why Hold is a decaying asset. A record parked past 30 days is not just stale, it becomes non-compliant to action. So a Hold needs an expiry, not an open queue.

The opt-out is the other live wire. If a candidate said "not interested" and asked you not to store their data, that request must be spread across the organisation and honored. The practical fix is a documented opt-out: because deletion is hard to guarantee, ask for consent to keep the contact information so you can document the opt-out. A record with an unqueried preference flag risks duplicate outreach to someone who already said no, which is a Hold every time.

> A held record is a legal clock, not a to-do item, so give every Hold an expiry the day you set it.

The stakes are not theoretical. The Irish DPC fined LinkedIn EUR 310 million in October 2024 over invalid consent and legitimate-interest grounds for profiling. Metadata is the cheapest insurance you will ever attach to a record.

## The handoff procedure, end to end

Run these eight steps in order. Steps one through six are the sourcer and ops building the record; step seven is the reviewer grading it; step eight is the recruiter taking ownership.

#### From role brief to reassigned ownership

1. **Set the handoff contract** - Before sourcing, the talent lead and hiring manager agree profile, screening criteria, decision owner, interview blocks, and start-date target in a written SLA that names one handoff trigger.
2. **Source and make first contact** - The sourcer builds the shortlist, sends the opener, and confirms basic fit against the brief. Done when the candidate responds through a recorded channel.
3. **Qualify against baseline criteria** - Confirm positive interest plus experience level, openness to the role type, and compensation range. Done when interest, comp range, and availability fields are non-empty.
4. **Verify identity and current employer** - Cross-check LinkedIn career history against GitHub or open-web evidence and resolve conflicts. Done when a single identity is resolved, current employer confirmed, and a dated evidence URL saved.
5. **Run source-company clearance** - Check the current employer against the off-limits and no-contact list before further contact. Done when the employer is marked cleared or flagged with reason and window.
6. **Attach compliance metadata** - Record lawful basis, date of collection, channel, and any opt-out or preference flag. Done when metadata is present and the 30-day notice clock is logged with its due date.
7. **Grade the record** - A reviewer applies the accept, return, or hold checklist and logs the verdict with a reason. Done when the verdict is recorded and, for Hold, an expiry date is set.
8. **Transfer ownership** - On Accept, the recruiter assumes the record within the SLA window, using 24 hours as a default. Done when ownership is reassigned in the ATS and the sourcer released.

#### Where the verdict happens

1. **Build** - Sourcer sources, contacts, qualifies, verifies, clears, and attaches metadata
2. **Grade** - Reviewer runs the checklist and logs Accept, Return, or Hold
3. **Route** - Accept moves forward, Return goes back with a fix, Hold goes to a dated queue
4. **Own** - Recruiter assumes the accepted record within the SLA window

*Grading sits between the sourcer's build and the recruiter's ownership, so the transfer is never a judgement call made under time pressure.*

The transfer window itself is a documented example: once interest, salary expectations, and role alignment are confirmed, the recruiter takes ownership within 24 hours, which protects the candidate experience and ensures timely follow-up. Use that as your default and tighten it if your process can absorb it. The cost of a slow transfer is real: 42 percent of candidates withdraw when scheduling takes too long.

## How this goes wrong: the failure modes

The failure modes below are where handoffs break in practice. Each has a false positive that looks like a pass, a check that catches it, and a verdict. This is the load-bearing section, because a standard that misses these is just a nicer-looking SLA sentence.

- **Interest confirmed but comp and availability skipped.** Looks like a warm reply. Check: comp-range and availability fields non-empty. Verdict: Return.
- **Positive reply over-read.** A polite "not now" logged as interest. Check: reply text shows explicit willingness to proceed, not acknowledgement. Verdict: Return.
- **Wrong-person identity match.** Same name, different employer, merged into one record. Check: employer or domain and evidence URL reconcile across sources; reject same-name, conflicting-domain matches. Verdict: Hold until resolved.
- **Stale employer.** GitHub bio or LinkedIn shows a past role. Check: anchor on the most recent dated evidence. Verdict: Hold.
- **Off-limits employer not checked.** Candidate is at a client the firm cannot approach. Check: employer run against the no-contact list before send, not after. Verdict: Hold or drop.
- **No lawful-basis or notice record.** Outreach sent, but no LIA or 30-day notice logged. Check: metadata present. Verdict: Return.
- **Opt-out ignored, duplicate outreach.** A prior "not interested" not propagated triggers re-contact. Check: preference flag queried before handoff. Verdict: Hold.
- **Handoff-trigger ambiguity.** Sources disagree whether the trigger is responds, confirms interest, or applies. False positive: sourcer and recruiter each assume the other owns follow-up. Check: the SLA names one trigger explicitly.

> **Tip:** Grade the reply text, not the reply's tone
>
> The single cheapest reviewer habit is reading the actual words. "Happy to chat" is acknowledgement; "I'd move for the right senior role above X salary" is interest. The second is Accept-grade; the first is a Return.

Note the pattern: every Hold is either an external blocker you cannot fix at your desk or a clock that is running. Every Return is a field a sourcer can complete before lunch. If you find yourself wanting to Return something that is really an off-limits or opt-out problem, you have miscategorised it, and it will sit in the wrong queue.

## The reviewer's checklist

Run this checklist against every record before logging a verdict. All items pass means Accept. A fixable gap means Return. A time-sensitive or unresolvable blocker means Hold with an expiry.

#### Handoff grading checklist

- [ ] Interest is confirmed in the reply text as explicit willingness to proceed, not acknowledgement
- [ ] Compensation range is captured and reconciles with the brief
- [ ] Availability or start-date expectation is recorded
- [ ] Experience level and openness to the role type match the brief
- [ ] Identity resolves to one person, with employer or domain agreeing across LinkedIn and GitHub or open web
- [ ] Current employer is confirmed from the most recent dated evidence, with the URL saved
- [ ] Current employer has been run against the off-limits and no-contact list and is cleared
- [ ] Lawful basis is recorded and the LIA is documented
- [ ] Date of collection and channel are logged, and the 30-day notice clock has a due date
- [ ] Any opt-out or preference flag has been queried and honored
- [ ] The SLA handoff trigger for this role is met and named

## Keeping the standard current and making it stick

Team-authored standards are the only ones that change behavior, so the last step is to ratify this as your own, not to import it. Only 45 percent of teams have a definition of done their own team created, and only team-created definitions correlate with high performance, while externally imposed ones show no correlation. Copy the structure, but hold a session where sourcers and recruiters argue the exact fields and the one trigger, then sign it.

A few things in this standard are time-sensitive by mechanism, so re-check them rather than trusting a fixed value. Off-limits durations vary by firm and contract, from a one-year floor to open-ended, so verify the window per client rather than assuming two years. Notice periods and lawful-basis requirements follow the regulation in force where your candidates live; the 30-day figure is the common European reading, and the specific test comes from the ICO's three-part legitimate-interest assessment. Channel response benchmarks drift, so re-pull them before you use them to weight interest evidence.

I should flag one limit honestly. There is no single published, cross-platform standard for identity resolution, and no established public field list for a sourced record. This standard fills that gap with a defensible two-source rule and a checklist, but it is a considered construction, not a citation. Where your ATS or your regulator gives you a stricter rule, theirs wins.

Finally, set a Hold expiry policy on day one. Because the notice clock runs from collection and a held record can quietly cross the compliance line, decide now what happens to a Hold that ages out: re-verify, notify, or purge. A queue without an expiry is how a decaying asset becomes a liability. Grading the record is only half the job; the other half is knowing when a verdict expires.

## Frequently asked questions

### What is a sourced candidate definition of done?

It is the set of pass or fail criteria a record must meet before a recruiter takes ownership, stated so two reviewers grade the same case the same way. In this standard it covers the person (identity resolved, interest evidence, contactability) and the company (current employer confirmed, source-company clearance), plus compliance metadata. Records that pass all criteria are Accept; missing qualification fields are Return; time-sensitive or unresolvable blockers are Hold.

### When is a candidate ready for recruiter review?

When interest is explicitly confirmed, baseline criteria including compensation range and availability are captured, identity and current employer are verified, the employer is cleared against the off-limits list, and compliance metadata is present. Published sources disagree on the exact trigger, placing it at positive reply, confirmed interest, or application, so the readiness point is whatever single trigger your SLA names. The point of the standard is to fix that trigger once.

### What is a reasonable sourcing handoff SLA?

A common documented example is that once interest, salary expectations, and role alignment are confirmed, the recruiter takes ownership within 24 hours to protect candidate experience. The number matters less than naming one trigger and one owner. Set the window your process can actually meet, given that 42 percent of candidates withdraw when scheduling takes too long, and hold the handoff to it.

### What is the difference between a Return and a Hold?

Return means the record is fixable by the sourcer now: a missing comp range, absent availability, an over-read reply, or no lawful-basis record. Hold means a blocker exists that the sourcer cannot resolve on the spot or that is time-sensitive: off-limits clearance pending, an unresolved identity conflict, an opt-out flag, or evidence older than the 30-day compliance window. Return goes back for completion; Hold goes to a queue with an expiry date.

### Why check the candidate's current employer against an off-limits list?

Because approaching someone at a client you are contractually barred from soliciting can breach an off-limits agreement, and the risk is not rare. A single large search firm's no-contact list can reach tens of thousands of companies in a year, and the AESC standard bars approaching a firm worked for in the previous two years. Run the employer against the list before further contact, not after, and treat an uncleared employer as Hold or drop.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/sourced-candidate-handoff-standard*
