When you connect an agent to the Get on Board MCP Server, it can search Talent Database and read candidate profiles — but it never receives contact data. No emails, no phone numbers, no CV files, no social or portfolio links. The server returns public, privacy-preserving summaries plus a link to the profile in Get on Board, where you decide whether to unlock contact details with credits. This article explains those boundaries, for recruiters connecting an agent and for professionals wondering what an agent can see.
What an agent never sees
Every MCP tool applies a strict allowlist: only the fields on the list leave the server, and everything else is dropped. The following data is never returned through MCP, in any tool, in any response:
- Email addresses and phone numbers (including WhatsApp).
- CV and resume files.
- Social profile links: LinkedIn, GitHub, GitLab, Stack Overflow, X/Twitter.
- Portfolio and personal website URLs.
- Private profile text beyond the candidate’s public summary.
Candidate-written text is also cleaned before it leaves the server: HTML is stripped, contact details embedded in the text are redacted, and length is clamped. What an agent does receive is enough to evaluate fit — country, seniority, years of experience, skills, English level, a public summary — without ever exposing a way to reach the person outside Get on Board.
The data belongs to the professionals who published it
Every profile an agent can find through MCP belongs to a professional who created it on Get on Board and chose to be discoverable by companies. This is the opposite of the enrichment stack — tools like Apollo, Lusha, or ZoomInfo — where contact data is scraped or bought from third parties and the person never agreed to be in the database.
Because professionals own their data on Get on Board:
- They decide what appears on their profile and can edit or remove it at any time.
- They chose to be visible to hiring companies — nobody harvested them from the open web.
- Their contact channels are only revealed under the platform’s rules, which the MCP server cannot bypass.
Connecting an agent does not change any of this. The agent works within the same visibility rules you already have as a recruiter in the web app — it just can’t see the contact layer at all.
Why unlocking stays human and credit-gated
Reaching out to a candidate is the moment that matters most for their privacy, so it stays a deliberate, human decision. To get contact details, you open the candidate’s profile_url in Get on Board and unlock the profile using your Talent Database credits, with the same quota display and confirmation step as always.
An agent cannot unlock candidates, spend credits, send invitations, or apply to jobs on anyone’s behalf. All MCP tools are read-only. That means a misconfigured or overeager agent cannot drain your credits or mass-contact professionals — the worst it can do is search and read.
Is this scraping? No — it’s the opposite
A fair question when “AI” and “candidate data” appear in the same sentence. Scraping means extracting personal data at scale without consent. The MCP server is built to prevent exactly that:
- Recruiter-only access. Only recruiter team members with an accepted company membership can authorize a connection. There is no anonymous or public access, and no professional-side access either.
- OAuth with short-lived tokens. You authorize from the browser at
https://www.getonbrd.com/mcp; access tokens expire after 2 hours and can be revoked at any time. - Permissions re-checked on every call. Your role, company access, and Talent Database permission are verified on each search and each profile read — not just once when you connect.
- Read budgets and rate limits. Searches and profile reads have hourly caps per company, so no connection can vacuum the database.
- No contact data, ever. Even if someone tried to misuse a connection, there are no emails or phones in the responses to extract.
Bulk extraction of profiles is against Get on Board’s terms, and the MCP server’s design makes it impractical anyway.
What this means for you as a professional
If you have a Get on Board profile, agents used by recruiters can find you through the same search that recruiters already use, and read the public side of your profile: your summary, skills, experience, and preferences. They cannot see your email, phone, CV, or social links. Your name appears only to companies that already unlocked your profile or received an application from you. If a company wants to contact you, a person at that company has to open your profile in Get on Board and unlock it — the same flow as before agents existed.
Related articles
- What is the Get on Board MCP Server?
- What can an AI agent do (and not do) on Get on Board?
- What profile information is visible in Talent Database?
- Can I directly access the contact data in Talent Database?
- How can I use Get on Board for agentic recruitment?
- What is Talent Database?
- Tools to reach tech candidates in Latin America: enrichment, scraping or marketplace?