Philippines staffing research ·

Can Candidate Sourcing Stay Tied to an Authorized Requisition?

A controlled study of requisition versions, sourcing instructions, channel limits, approvals, pauses, and candidate routing.

Illustration for Can Candidate Sourcing Stay Tied to an Authorized Requisition?

Research question. This study asks whether sourcing stays attached to a current authorized requisition without letting a coordinator decide who should be hired. It creates a buyer-side evaluation method, not a claim about Outsourced Employment or another provider.

Evidence basis. The Philippine Data Privacy Act says personal information should serve declared purposes, remain accurate and relevant, not be excessive, and receive reasonable organizational, physical, and technical protection. Its implementing rules address accountable roles, access duties, processing records, processor arrangements, and review. NIST CSF 2.0 supplies a general vocabulary for governance, identity, data security, detection, response, and recovery. CISA guidance supports least privilege. These are design inputs; owners and qualified advisers interpret them for a real organization.

Unit of analysis. Examine one fictional requisition version, approved instruction, channel, and candidate-routing event. This narrow unit prevents favorable totals from hiding unsupported transitions. Every conclusion identifies its source event, version, observed time, and accountable next decision.

Test population. Create 110 events covering draft and approved openings, replacements, confidential searches, location and qualification changes, pauses, closures, duplicates, agencies, referrals, and reopened searches. Use invented organizations, people, documents, amounts, accounts, and identifiers. Keep the seeded answer key separate through independent review. Record exclusions and reasons rather than silently replacing difficult cases.

Required evidence. Capture requisition token, owner, approval, version, effective time, scope, location, channel, candidate source, action, stop event, acknowledgment, exception owner, and recruiter disposition. Define purpose and allowed values before testing. Blank, unknown, not applicable, not received, restricted, and cannot determine remain different. Reviewers cannot turn absence into an answer.

Failure hypothesis. A title is not authorization. Accurate copying of a stale request can cause unauthorized outreach, duplicate agency work, or disclosure of a confidential replacement. Include positive controls that should proceed, negative controls that should stop, and ambiguous controls that should reach an owner. A workflow that never stops is uncontrolled; one that stops every case is unusable.

Decision boundary. Coordinators may verify approvals, use current instructions, record source events, stop on declared triggers, and escalate. Hiring, finance, recruiting, privacy, legal, and business owners approve openings, channels, requirements, and selection. Count an unauthorized substantive decision as a serious error even if the guess proves correct. Coordination does not transfer accountability.

Controlled comparison. Randomize case order and compare an inbox queue with a versioned register that blocks action after a pause, closure, or superseding instruction. Give both workflows equal information and time. Evaluate correctness, access, serious errors, unresolved work, and duration; speed alone is not success.

Scenario design. Seed approval at 09:00, a location change at 11:20, a pause at 14:10, and agency acknowledgment at 16:00. Add a confidential replacement, duplicate requisition number, scheduled message after closure, and one referral shared across two valid openings. Require evidence for each transition and preserve late or conflicting signals. The correct response to ambiguity is the named route, not the researcher’s preferred answer.

Evidence drill 1 focuses on requisition token. Compare requisition token against version at the declared event time, then test whether location supports or contradicts that relationship. Preserve action before asking the accountable owner to resolve any conflict involving exception owner. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 2 focuses on owner. Compare owner against effective time at the declared event time, then test whether channel supports or contradicts that relationship. Preserve stop event before asking the accountable owner to resolve any conflict involving and recruiter disposition. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 3 focuses on approval. Compare approval against scope at the declared event time, then test whether candidate source supports or contradicts that relationship. Preserve acknowledgment before asking the accountable owner to resolve any conflict involving requisition token. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 4 focuses on version. Compare version against location at the declared event time, then test whether action supports or contradicts that relationship. Preserve exception owner before asking the accountable owner to resolve any conflict involving owner. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 5 focuses on effective time. Compare effective time against channel at the declared event time, then test whether stop event supports or contradicts that relationship. Preserve and recruiter disposition before asking the accountable owner to resolve any conflict involving approval. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 6 focuses on scope. Compare scope against candidate source at the declared event time, then test whether acknowledgment supports or contradicts that relationship. Preserve requisition token before asking the accountable owner to resolve any conflict involving version. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 7 focuses on location. Compare location against action at the declared event time, then test whether exception owner supports or contradicts that relationship. Preserve owner before asking the accountable owner to resolve any conflict involving effective time. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 8 focuses on channel. Compare channel against stop event at the declared event time, then test whether and recruiter disposition supports or contradicts that relationship. Preserve approval before asking the accountable owner to resolve any conflict involving scope. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 9 focuses on candidate source. Compare candidate source against acknowledgment at the declared event time, then test whether requisition token supports or contradicts that relationship. Preserve version before asking the accountable owner to resolve any conflict involving location. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 10 focuses on action. Compare action against exception owner at the declared event time, then test whether owner supports or contradicts that relationship. Preserve effective time before asking the accountable owner to resolve any conflict involving channel. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 11 focuses on stop event. Compare stop event against and recruiter disposition at the declared event time, then test whether approval supports or contradicts that relationship. Preserve scope before asking the accountable owner to resolve any conflict involving candidate source. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 12 focuses on acknowledgment. Compare acknowledgment against requisition token at the declared event time, then test whether version supports or contradicts that relationship. Preserve location before asking the accountable owner to resolve any conflict involving action. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 13 focuses on exception owner. Compare exception owner against owner at the declared event time, then test whether effective time supports or contradicts that relationship. Preserve channel before asking the accountable owner to resolve any conflict involving stop event. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Evidence drill 14 focuses on and recruiter disposition. Compare and recruiter disposition against approval at the declared event time, then test whether scope supports or contradicts that relationship. Preserve candidate source before asking the accountable owner to resolve any conflict involving acknowledgment. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.

Case construction detail. Translate this scenario into individual test cards: Seed approval at 09:00, a location change at 11:20, a pause at 14:10, and agency acknowledgment at 16:00. Add a confidential replacement, duplicate requisition number, scheduled message after closure, and one referral shared across two valid openings. On each card, show only the information that the real role would possess at that moment. Withhold later events until their timestamp arrives. This prevents hindsight from improving a classification and reveals whether the operating record can support the decision when it is actually needed. Keep the hidden expected route, serious-error class, and permitted evidence beside the answer key, not in the reviewer interface.

Causal review. For every incorrect or delayed result, trace the chain through these required elements: requisition token, owner, approval, version, effective time, scope, location, channel, candidate source, action, stop event, acknowledgment, exception owner, and recruiter disposition. Identify the earliest unsupported transition instead of blaming the final user. Classify whether the cause was an unavailable source, ambiguous definition, stale version, excessive permission, missing acknowledgment, incorrect mapping, or action outside the written boundary. Re-run only the affected cases after a versioned correction and retain the first result so improvement is measurable rather than reconstructed.

Decision usefulness. The buyer should receive evidence about authorization coverage, stale-version use, stop latency, duplicates, channel compliance, misrouting, agreement, and owner-response time. Convert those measures into a decision table that shows the observed fact, denominator, uncertainty, consequence, accountable owner, and proposed next test. Do not roll serious boundary violations into one average score. A fast median can coexist with a small number of unacceptable disclosures or decisions, while a slower result may reflect appropriate stops on ambiguous cases. State both the operational benefit and the control cost.

Boundary challenge. Apply adversarial examples to this division of responsibility: Coordinators may verify approvals, use current instructions, record source events, stop on declared triggers, and escalate. Hiring, finance, recruiting, privacy, legal, and business owners approve openings, channels, requirements, and selection. Ask reviewers what they can prepare, what they may observe, what requires approval, what must stop, and what should never enter the routine record. Score the evidence trail as well as the answer. A correct escalation with no preserved source or recipient acknowledgment is incomplete; a perfectly documented action outside the permitted lane is still a failure.

Alternative explanation. Before accepting the primary conclusion, test whether the same result could arise from A title is not authorization. Accurate copying of a stale request can cause unauthorized outreach, duplicate agency work, or disclosure of a confidential replacement. Compare that explanation with source timestamps, versions, permissions, and acknowledgments. Mark inference as inference and preserve competing explanations when the evidence cannot choose between them. This discipline matters because a plausible operational narrative can otherwise harden into an unsupported fact that later reviewers, systems, or employee communications repeat.

System-path review. Replay every scenario through the primary record, email, calendar, notification, download, integration, audit log, and backup path that might carry the same information. Record propagation time, mismatched identifiers, stale copies, recipient scope, and acknowledgments. A clean main screen cannot compensate for an uncontrolled export or dependent system still acting on an old state.

Temporal review. Repeat selected cases when a cutoff passes, an owner changes, a source is corrected, or acknowledgment arrives late. State changes only when declared evidence exists. Record the observer, applicable rule version, and dependent-system result. This separates an overdue item from a superseded one and a corrected source from a correction actually received.

Recovery review. Remove a required source, delay an owner, add a duplicate, and interrupt an integration. A controlled workflow preserves last-known state, says what cannot be determined, avoids reconstructing facts from memory, and uses the approved contingency. Work resumes without double action, silent closure, or broader disclosure.

Measurement. Report authorization coverage, stale-version use, stop latency, duplicates, channel compliance, misrouting, agreement, and owner-response time. Give counts with denominators. Separate observed facts, rule classifications, owner decisions, and researcher inference. Preserve disagreement and missing evidence rather than averaging them into a confident-looking score.

Privacy and security. Use invented candidates and requisitions; exclude resumes, demographics, identifiers, compensation, and confidential replacement details. Record who can view, change, export, and delete each artifact. Check whether revoked access survives elsewhere. Stop on unexpected sensitive information and use the approved incident path.

Repeatability. Give a second reviewer written rules and clean cases without coaching. Low agreement indicates unclear definitions, missing evidence, or inconsistent access. Version clarifications and rerun affected cases; do not label every disagreement a training problem.

Acceptance. Set minimum accuracy, maximum unresolved age, acceptable agreement, and zero-tolerance events before opening the answer key. Report each independently. Strong averages cannot offset an unauthorized decision, exposure, or false closure hidden in a total.

Procurement use. Ask a provider to demonstrate a sanitized register, permission view, version history, exception path, acknowledgment, and audit export for this workflow. Every artifact has a date and scope. A policy, demo, or marketing statement is point-in-time evidence, not proof of continuous operation.

Limitations. This cannot prove an opening is lawful, funded, correctly classified, or well designed, and it does not assess merit. Synthetic cases simplify behavior, platforms, contracts, and cross-border operations. Begin a live pilot with a small approved queue, least-privilege access, named reviewers, monitored exceptions, and a stop rule. The defensible conclusion is whether evidence remains reviewable and uncertainty reaches the correct owner—not whether the workflow guarantees a legal, security, payroll, privacy, employment, or business result.

Sources checked September 28, 2026: National Privacy Commission, “Republic Act 10173 — Data Privacy Act of 2012,” https://privacy.gov.ph/data-privacy-act/; National Privacy Commission, “Implementing Rules and Regulations of the Data Privacy Act of 2012,” https://privacy.gov.ph/implementing-rules-regulations-data-privacy-act-2012/; National Institute of Standards and Technology, “The NIST Cybersecurity Framework (CSF) 2.0,” https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20; Cybersecurity and Infrastructure Security Agency, “Identity and Access Management: Recommended Best Practices for Administrators,” https://www.cisa.gov/sites/default/files/2023-12/ESF%20IDENTITY%20AND%20ACCESS%20MANAGEMENT%20RECOMMENDED%20BEST%20PRACTICES%20FOR%20ADMINISTRATORS%20PP-23-0248_508C.pdf. These sources provide principles, not a finding that a provider complies.

Philippines staffing intake

Define the role before hiring begins.

Share the tasks, tools, schedule, and approval limits for your Filipino team member. The intake turns those details into a practical staffing brief.

Contact Us