When you connect an AI agent to the Get on Board MCP Server, it can search and read — not act. Today an agent can search Talent Database, read privacy-safe candidate profiles, and read your company’s open jobs. It cannot unlock contact details, invite candidates, apply to jobs, post jobs, or see anyone’s email, phone, or CV. Those actions stay in the Get on Board web app, where you decide and where credits are spent.
This article is for recruiters using the MCP server. If you have not connected yet, start with What is the Get on Board MCP Server?
The capability map at a glance
| Task | Through your agent? | Where it happens |
|---|---|---|
| Search candidates in Talent Database | Yes | search_talent tool |
| Read a candidate’s background, skills, and traits | Yes | talent_profile tool |
| List your company’s open hiring processes | Yes | list_jobs tool |
| Read a job’s full description and questionnaire | Yes | job_details tool |
| Confirm your identity, company, and permissions | Yes | whoami tool |
| Unlock a candidate’s contact details | No | Web app, with credits |
| Invite a candidate to a process | No | Web app |
| See emails, phones, CVs, or social links | No | Web app, after unlocking |
| Apply to jobs on a professional’s behalf | No | Not available to agents |
| Post or edit job listings | No | Web app |
| Search public job listings | No | Web app or Jobs API |
What your agent can do
The MCP server gives your agent five read-only tools, always scoped to the company you authorized:
- Search Talent Database with a plain-language brief: role, stack, seniority, country, English level, salary expectations, industry background. Your agent refines the search, compares results, and builds shortlists.
- Read one candidate in depth with the id a search returned: profile description, professional and academic background, skills, tags, and quiz traits. The candidate’s name appears only when your company already unlocked that profile or the person applied to one of your jobs.
- List your open jobs and read a job’s full description and application questionnaire, so it can source for a role you already posted without you re-typing the brief.
- Confirm the connection with
whoami: your identity, active company, and which tools your authorization granted.
Every result includes a first-party Get on Board profile or dashboard link, so the handoff from agent to web app is one click.
What your agent cannot do
- Unlock contact details. No email, phone, WhatsApp, CV file, portfolio, or social link is ever returned through MCP — not in results, profiles, or error messages. Unlocking happens in the web app and spends Talent Database credits, with the usual quota display and confirmation step.
- Invite candidates or move processes forward. Actions like inviting a candidate stay in the web app for now. The agent narrows the list; you make the move.
- Act for professionals. The MCP server is for recruiter team members with accepted company access. There is no professional-side sign-in, and agents cannot apply to jobs on anyone’s behalf — applications on Get on Board come from verified humans.
- Search public job listings. Job search through MCP is not available today. The
list_jobsandjob_detailstools only read your own company’s jobs. - Reach other companies’ data. Every token is bound to one company context you approve at sign-in, and permissions are re-checked on every call.
Why the line is drawn there
The data in Talent Database belongs to the professionals who created their profiles and opted in to be found. That ownership sets the boundary: an agent can read the summaries candidates agreed to show, but the step that reveals someone’s contact information remains a deliberate, human, credit-gated decision in the web app. It also keeps a runaway agent from spending your credits or messaging candidates without you noticing.
These are today’s boundaries, not a fixed ceiling. Read-only came first because it is safe to ship; actions may follow with their own safeguards.
Practical implications
- Give your agent search-and-shortlist work: source from a brief, screen against one of your posted jobs, rank and compare profiles.
- Expect it to end at links. A good agent session finishes with a shortlist of Get on Board profile URLs you open to unlock and contact.
- Profile reads are capped per hour, so point your agent at the candidates worth a closer look instead of every result.
- Access tokens last 2 hours; re-authorizing in your client is expected, not a bug.