# Integration with your ATS — Criterio Talent

> Your ATS stays the system in charge: Criterio Talent receives the role and the candidate, interviews, and returns the report by API, with no exporting or retyping.

URL: https://criteriotalent.com/en/integraciones/

---

**Integrations**

# The process does not stop to interview.

The ATS your team already runs stays the system in charge. Criterio Talent receives the role and the candidate, runs the interview, and returns the report where you expect it — with nobody exporting, pasting or retyping anything.

Here is exactly what travels, in which direction, and what happens when the other side does not answer. Each company’s integration lives inside its own perimeter.

## The operations that exist today

There are five, and they cover the whole path of an application: sync the role, request the interview, check on it, retrieve its report, and read the catalogue of available interviewer profiles.

The request that creates an interview accepts an idempotency key, so a retry after a network that dropped halfway does not produce two interviews for the same person.

All five live under a versioned path: the version is in the address, not in a header someone forgets.

| Operation | What it does | Sync a role | Mirrors the role from the client system into the instance, with its associated script. | Request an interview | Issues the individual link for a person against an already-synced role. | Check an interview | Returns where it stands: issued, opened, running, finished or declined. | Retrieve the report | Returns the assessment per competency with the evidence supporting it. | Profile catalogue | Lists the interviewer profiles available in that instance.

## The events that go out, and how you check they are ours

The integration should not have to keep asking. Eight events run through the life of an interview: the link was issued, the person opened it, it started, it finished, they declined, it failed, the report is ready, and a connection test to verify the receiver before anything real happens.

Each event travels signed with HMAC-SHA256 over the exact body, with the timestamp inside the signed message. The receiver must compare in constant time and reject a timestamp more than five minutes away from its clock: with the timestamp outside the signature, an old event can be replayed by changing the hour.

The events and their signature header are declared in the specification itself, not just described on a page. An event that lives only in documentation falls behind the moment the code changes.

## Authentication and keys

- Keys are issued and revoked from the instance’s own console, inside the client’s domain.
- An invalid key gets a response carrying its request identifier, so an integration problem can be traced without guesswork.
- Keys belong to the instance, so they never cross from one company to another.

## ATS and HRIS

The API is the mechanism; connecting to a specific ATS or HRIS is a project, and it is defined as one: which fields travel, in which direction, how often, and what happens when the other side does not answer.

It is defined in writing before starting, because an integration discovered along the way is the most expensive way to find out that two systems understood the same word differently.

## Corporate identity

The platform’s identity is its own and carries a mandatory second factor for authorised staff. That is what operates today.

Signing in against the client’s corporate directory is part of the scope defined per project.

## What gets defined with you

There is no catalogue connector you install and forget: each integration is designed around the ATS your team actually runs, with its fields and its states. That costs a conversation up front and saves the worst surprise there is — finding out in the third week that two systems understood the same word differently.

Signing in against the corporate directory is part of that same scope and is agreed per project. Today the platform’s identity is its own, with a mandatory second factor for authorised staff.

**Next step**

## See it with a role of yours on the table.

Thirty minutes: an interview is defined from your job post, walked through the way the candidate sees it, and a report is read with its evidence.
