Skip to content

Consulting and recruiting

Recruiting firm data inventory: systems and record types to list

By SourceX Editorial · Updated

Short answer

A recruiting firm data inventory lists every system that holds placement work, from the ATS and CRM to VMS portals, payroll, email and call recordings, with a record count, date range, export route and known restrictions for each row. The working rule: one row per system and record family, so candidate-heavy files never hide inside a useful workflow row.

Key takeaways

  • Give each record family inside a system its own row, so workflow history and candidate profiles are never scored together.
  • Record counts and date ranges should come from system reports, and anything unconfirmed is marked unknown.
  • Records held in client VMS portals often sit under client program terms, so flag them before treating them as yours.
  • Onboarding, background check and I-9 files belong on the inventory as named exclusions.
  • Building the inventory requires metadata only; no candidate files leave your systems.

What a recruiting firm data inventory is for#

A recruiting firm data inventory is a single sheet that shows where every record of your desks' work lives, how far back it goes and what limits apply to it. Operations leaders use it to answer questions that otherwise turn into long email chains: what the firm would lose if we turned off the old ATS, what a buyer's diligence team will ask for, and which records could support an AI project or a license.

The inventory describes records; it does not hold them. Each row names a system, a family of records inside it, approximate volume, the first and last dates, how the data could be exported, who owns it internally and what personal data or contract terms touch it. Nobody opens a resume or a pay file to fill it in.

Template rows: the systems most staffing firms should list#

The template rows below cover the systems that hold most of the history at a typical contract and direct-hire firm. Split a system into several rows whenever its record families carry different levels of personal data, because that is how later decisions get made.

Add rows for anything your firm runs that is not listed, such as a separate texting platform, a sourcing tool with saved searches or a reference-checking service. A system you forgot is the one that surfaces late in a migration or a sale.

Template rows: the systems most staffing firms should list
SystemRecord families to listDate range noteFlag
ATS (for example Bullhorn)Job orders, submittals, interviews, placements, activity notesFrom go-live; check for an older ATS before itWorkflow rows, separate from candidate profiles
ATS candidate profilesResumes, contact details, skills, status history, attachmentsSame as the ATSHeavy candidate personal data
Legacy ATS archiveSame families from the prior system, often exported files or a read-only loginEnds at the migration dateField mappings may be lost
CRM or business development toolClient accounts, contacts, opportunities, call and meeting logsOften shorter than ATS historyClient confidentiality
Client VMS portalsRequisitions, submittals, rate cards, timesheet approvalsOnly what each portal lets you exportClient program terms may control use
Payroll and back officeTimesheets, pay and bill rates, invoices, adjustmentsCheck which years are retained; older years may have been purgedCompensation and tax data
Email and calendarRecruiter and account manager mailboxes, interview schedulingSet by mailbox retention policyMixed personal content
Phone, SMS and call recordingsCall logs, text threads, recorded screening callsSet by platform plan and settingsRecording consent and candidate data
Onboarding and complianceBackground checks, I-9s, drug screens, signed policiesGoverned by legal retention rulesList as an exclusion
Shared drives and wikiJob description library, interview guides, desk playbooks, trainingOften the oldest content you holdUsually the least personal data
Slack or TeamsDesk channels, handoffs between recruiters and account managersSet by workspace retentionMixed personal content

Which columns should each row carry?#

Each row should carry the same columns so rows can be compared and sorted. The columns below are the ones that decide later questions about retention, preparation effort and rights, so leave none of them blank; write unknown instead.

Record counts deserve care. A count of candidate records that includes duplicates, parsed job board applicants and never-contacted profiles will overstate what the firm actually worked. Where the ATS allows it, count records with at least one logged activity separately from the total.

Which columns should each row carry?
ColumnWhat to enterWhere it comes from
System and versionProduct name, hosted or on-premise, current or retiredIT or the system admin
Record familyOne family per row, such as submittals or placementsATS entity list or admin console
Approximate record countTotal, plus records with logged activity where possibleBuilt-in reports or list view counts
First and last record dateEarliest created date and most recent updateReport sorted by created date
Export routeNative export, API, vendor-assisted export or backup restoreAdmin and vendor documentation
Internal ownerRole accountable for the systemOperations
Personal data levelLow, medium or highOperations with privacy lead
RestrictionsClient MSA terms, VMS program terms, candidate noticesLegal or contract files
StatusActive, read-only, retired or scheduled for shutdownIT and finance

How do you get record counts and date ranges without exporting data?#

Record counts and date ranges come from reports your systems already run. Most ATS platforms let an admin count records by entity type and filter by created date, which gives both volume and coverage in one pass. Finance can confirm payroll and invoice coverage from the payroll provider, and IT can read mailbox and chat retention settings from the admin console. Do not assume payroll history runs back to the firm's founding: the Department of Labor's Fact Sheet 21 sets minimums, not maximums, of three years for payroll records and two years for time cards and wage-rate tables, so older years may have been purged on schedule.

Work through the systems in a fixed order so nothing is skipped, and note the source of every figure next to it.

  • Pull the ATS entity list and count each workflow entity by year of creation.
  • Find the earliest record in each family and check whether it predates the current ATS.
  • Locate any legacy archive and confirm whether its files still open and which fields survived.
  • List every client VMS portal the firm logs into and what each one allows you to download.
  • Ask finance which years of timesheets, pay and bill rates and invoices are retained.
  • Ask IT for mailbox, chat, texting and call recording retention settings. In Microsoft Teams, chat messages sit in hidden mailbox folders reached through eDiscovery, and files shared in chats sit in the sharer's OneDrive, so list both.
  • Record who supplied each number and when, so the sheet can be refreshed later.

Which records need a flag before anyone counts them as an asset?#

Records that sit in client VMS portals need the first flag, because the managed service provider or the client often sets the terms for submittals, rate cards and timesheets inside its program. Your firm may hold a copy, yet the program agreement can still limit how that copy is used.

Candidate profiles, call recordings and text threads need a second flag for personal data and recording consent. Voluntary self-identification and EEO data, background check results and immigration documents should be listed as exclusions so nobody mistakes them for usable history. Job orders deserve a third, quieter flag, since the client's identity, its hiring manager and the bill rate usually sit right in the record.

Illustrative: a two-division staffing firm builds its first inventory#

Illustrative: a fictional staffing firm with an IT contract division and a light-industrial division moved from an older ATS to Bullhorn several years ago. The old system survives as exported files on a network drive. Recruiters text candidates through a separate SMS platform, and the IT division submits through several client VMS portals.

The COO splits the ATS into a workflow row and a candidate profile row, lists the legacy archive separately and notes that its interview stage field did not migrate. Each VMS portal gets its own row marked for contract review, and onboarding files are listed as excluded. The decision is to put the IT division's job orders, submittals and placements, plus the job description library, forward for a metadata-only fit check, and to leave texting logs and candidate profiles out of scope for now.

How SourceX uses a recruiting firm inventory#

The inventory feeds Supply, which opens the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery. The fit check reads the system names, record families, counts and date ranges; no files are shared at that stage. The restrictions column then frames the rights review, and the personal data column shapes the preparation plan.

If a package goes ahead, its SourceX Evidence Packet documents where the records came from, the licensing rights and permitted use, the privacy record and the supplier's release authorization. Source system and date coverage from the inventory feed the provenance entry, which lines up with the Source, Provenance and Use metadata groups in the Data & Trust Alliance's Data Provenance Standards.

Frequently asked questions

Should recruiters' personal LinkedIn accounts or phones go on the inventory?

List them as out of scope rather than ignoring them. The firm usually cannot export, control or license records held in personal accounts, and writing that down prevents someone from assuming those messages are part of the firm's history. If your policy requires work on firm systems, note that too.

How should an acquired desk or franchise location be recorded?

Give each legal entity its own rows, even if its records now sit in your ATS. Records created before an acquisition can carry different candidate notices, client contracts and vendor terms, and the rights review needs to see that boundary clearly.

Who should own the recruiting firm data inventory?

The COO or head of operations usually owns it, with the ATS admin supplying counts, finance confirming payroll and invoice coverage, and legal or the privacy lead completing the restrictions column. One owner keeps the sheet current after migrations and vendor changes.

Can the same inventory support a sale of the firm?

Yes. Buyers of staffing firms ask which systems hold candidate and client history, how far back it goes and whether the firm owns and controls it. An inventory that already answers those questions shortens technology diligence and shows where records sit under client or vendor terms.

How often should the inventory be updated?

Revise it each time a system is added, switched off or moved to a new platform, and walk through it on a fixed schedule, such as the annual budget cycle. Retention settings and vendor plans change quietly, and a stale date range can mislead a decision about what history still exists.

Sources

  • The Data & Trust Alliance's Data Provenance Standards (version 1.0.0 specification) define dataset metadata in three groups: Source, Provenance and Use, needed to enable proper dataset selection for AI model training. Source
  • DOL Fact Sheet #21 states each employer shall preserve for at least three years payroll records, and for two years records on which wage computations are based, such as time cards, wage rate tables and work and time schedules. Source
  • Microsoft states that Teams chat data is stored in a hidden folder in the mailbox of each user included in the chat, and these folders are searched with eDiscovery, not accessed directly. Source
  • Microsoft states that files shared in Teams chats are stored in the OneDrive account of the user who shared them, while files uploaded to channels are stored in the team's SharePoint site. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify