Consolidated matrix

The Harbor procurement view.

Scores are invented for this demonstration, but the control categories reflect the diligence questions HR teams ask when community platforms touch candidates, employees, and recruiting workflows.

ControlEnterprise GraphAnonymous ForumRegional GuildPortfolio Circle
Composite score82687672
Best buyer useBroad sourcing and market mapsSentiment and compensation signalRegional hiring and licensed rolesSkills validation and early-career roles
Primary riskExcess candidate profilingRe-identification pressureLimited market coverageVendor maturity
DPA readinessComplete packetNeeds architecture letterComplete packetAudit pending
Admin controlsSeat logs, exports, rolesLimited dashboardsRole controls and event logsBasic role model
Candidate noticeClear but broadNeeds anti-retaliation framingSpecific and localizedVisible contact controls
Retention posture36 months standard18 months standard24 months standard12 months standard
Invented annual price band$148,000 to $410,000$42,000 to $96,000$28,000 to $74,000$18,000 to $61,000

Harbor shortlist rules

Greenlight

Use when DPA, admin logs, candidate notice, and deletion routes are complete before launch.

Conditional

Use for a limited pilot with a written risk owner and a 90-day evidence checkpoint.

Hold

Pause procurement when identity, moderation, or subprocessor evidence is unavailable.

Retire

Exit when a community cannot meet breach notice, deletion, or non-retaliation commitments.

Detailed control matrix

Evidence itemWhy HR caresMinimum acceptable responseOwner
Subprocessor registerCandidate and employee data may move through analytics, hosting, enrichment, and support vendors.Named vendors, country, purpose, and 30-day change notice.Legal
Recruiter activity logHR must investigate inappropriate searches and contact patterns.Search, export, message, and admin events retained for 18 months.Recruiting operations
Deletion workflowCandidate rights requests need operational proof, not promises.Self-service deletion plus enterprise request queue under 30 days.Privacy
Moderation reportCommunity harm can become employer risk when programs are sponsored.Quarterly volume, severity, median response time, and appeal outcomes.Employee relations
Accessibility reviewHiring channels must not exclude candidates.WCAG 2.2 AA statement and remediation owner.Talent programs