Outreach You Can Defend: The Governance Layer AI Sourcing Forgot
AI lets three people contact thousands of candidates. Almost nobody builds the controls that make that safe — and the failure modes aren't gradual, they're single events.

Give a three-person recruiting team an AI sourcing tool and their reach goes up by an order of magnitude overnight. Thousands of profiles evaluated, hundreds of personalised messages sent from the hiring managers' own accounts.
What almost nobody builds at the same time is the set of controls that makes that reach safe to operate. This is the least glamorous part of the category and the one that ends up mattering most, because the failure modes aren't gradual. They're single events with immediate commercial consequences.
Three Ways This Goes Wrong
You contact someone you shouldn't have. A candidate at your biggest client. Three engineers at a portfolio company your investor sits on the board of. A subsidiary of your own group. Nobody on the team knew, because the list of off-limits companies lived in a founder's head and a Slack thread from last year.
Nobody can explain a decision. Six weeks into a search, someone asks why a strong-looking candidate was archived. There's no note, the reviewer has moved on, the reasoning is gone. So the candidate gets re-reviewed from scratch — or worse, re-contacted.
The same person hears from you twice. Two searches running in parallel, both find the same profile, both reach out from different accounts with different pitches. From the candidate's side, this reads as a company that doesn't know what it's doing.
None of these are AI-specific. They existed when everything was manual. What changes is the rate: manual outreach produced these mistakes occasionally, and automation produces them at the same rate as everything else it does.
Blocklists Are the Highest-Leverage Control
The most useful control is also the simplest — an organisation-level list of companies that must never be contacted, applied automatically to every new search.
The requirements are unglamorous and specific. It has to live at organisation level, not per search, or it drifts. It has to apply by default to new searches, because opt-in controls are controls that don't get used. It has to detect existing searches that predate a new entry and offer to bring them in line. And it has to flag candidates already in flight from a newly blocked company.
That last point is where most implementations stop short. Adding a company to a list is easy. Handling the twelve candidates from that company who are already mid-sequence is the part that actually prevents the incident.
Written Reasoning Is an Asset, Not Paperwork
The instinct is to treat notes as compliance overhead. In practice they're the highest-value data a recruiting team produces.
They make decisions reversible: "passed — strong profile but has only worked at 1,000-plus companies, and we've been burned on that twice" saves the next person forty minutes and tells you something about your scorecard. They make handoffs survivable, because searches change owners and candidates move between roles. And they're the feedback signal that improves everything upstream — rejection reasons, logged consistently, are the only reliable way to discover that a criterion in your scorecard is wrong.
The practical requirement is that writing a note has to be nearly free. On the candidate record, in the flow of review, with the ability to pull a colleague in directly. Anything that requires opening a separate tool won't happen.
Human Oversight Has to Be Real
Regulation is converging on one principle. The EU AI Act classifies AI used in recruitment and candidate evaluation as high-risk, with obligations around transparency, record-keeping and human oversight — currently scheduled for August 2026, though a deferral is under negotiation in Brussels as of this writing. New York City already requires bias audits and candidate notification for automated employment decision tools. Other jurisdictions are moving the same way.
The common thread isn't "don't use AI." It's that a human must be able to understand, contest and override what the system produced. That sets a design bar worth meeting wherever you operate. Every score shows its reasoning per criterion, not just a number. Criteria are editable and the effect is visible, so you can see what a criterion was actually doing. Nothing irreversible happens automatically — ranking, drafting and flagging can be automated; contacting and rejecting pass through a person. And every action is attributable.
One detail matters more than it looks. When outreach goes out from a hiring manager's own profile — which is what makes it work — that person's professional reputation is directly exposed. They're entitled to see and control what goes out under their name. An approval queue isn't friction. It's what makes the arrangement acceptable to the person whose name is on it.
Speed without control isn't leverage. It's exposure with better metrics.
Umamy applies organisation-wide do-not-contact rules to every search, keeps the reasoning behind each decision on the candidate record, and never sends anything a human hasn't approved.