🤫husshhussh
🤫husshhusshOnePuppy
🤫 Talent 1.0 · July 2026

The hiring handbook, in full.

Every stage, every scorecard, every message we send, and the rules we hold ourselves to. This is the operating manual, not the invitation. If you are deciding whether to apply, start with the short version.

The short versionSee open roles

Published in full, including the parts most companies keep internal.

Take it with you. Version 1.0, July 2026.

Download the document

Contents

  1. 01A note from Manish
  2. 02What this document is
  3. 03The human is the principal
  4. 04What we are building
  5. 05Seven people, one standard
  6. 06How we build
  7. 07The kind of builder this asks for
  8. 08The candidate promise
  9. 09The candidate journey
  10. 10The build session
  11. 11The interview standard
  12. 12How AI is used in hiring
  13. 13The operating model
  14. 14The recommended launch stack
  15. 15The website experience
  16. 16The state machine
  17. 17Data model and privacy
  18. 18Automation rules
  19. 19The weekly operating review
  20. 20Accepted offer to Day 0
  21. 21Day 1, Week 1, Day 30
  22. 22The 30/60/90 compact
  23. 23Interns, contractors, and international teammates
  24. 24Access is a lifecycle
  25. 25The 30-day launch plan
  26. 26Build versus buy
  27. 27Definition of done
  28. 28Appendix A: the one-page role brief
  29. 29Appendix B: interviewer scorecard
  30. 30Appendix C: work-sample cover sheet
  31. 31Appendix D: candidate communications
  32. 32Appendix E: counsel and compliance review triggers
  33. 33Appendix F: source notes
  34. 34The invitation

A note from Manish

Most technology companies begin with the company.

What data can we collect? What can we predict? What can we automate? What can we sell?

We begin with the human.

The most important information in a person's life is already digital. It is scattered across devices, accounts, institutions, and relationships. Companies can use it. AI can learn from it. Yet the person it describes often cannot put it to work.

hussh exists to change that.

We believe every person will have an AI agent. The question that matters is not whether the agent is intelligent. The question is who it serves.

We are building Agent One to answer to one human. We are building Puppy One so that human can own the computing power behind it. We are building consent, memory, identity, and trusted connections so personal information can become useful without becoming someone else's inventory. We are exploring Tag One and an owner-operated compute network so intelligence can move into the physical world without moving control away from the person.

HushOne, Inc. is seven people today. That is not a footnote. It means every person changes the product, the company, and the standard. There is nowhere for the work - or the credit - to hide.

We are not offering the comfort of a finished map. We are offering the chance to help draw it, and the obligation to make it useful. Some systems are unfinished. Priorities will sharpen as reality teaches us. Candor, judgment, and the ability to ship matter more here than ceremony.

Mission alone is not enough. We measure ourselves in useful products shipped, trust earned, customers served, commitments kept, and capital used with care. We want to build a company that lasts because the work deserves to last.

If that feels like responsibility you have been looking for, welcome.

Manish Sainani

Founder and CEO

The short versionWe are building private intelligence that works for its owner. We hire people who can turn that belief into a product, a customer outcome, or an operating system that is simple, trustworthy, and complete.

What this document is

Talent 1.0 is both an invitation and an operating standard.

The first half is written for every person considering hussh. It explains the problem we see, what we are building, how we work, the standard we hold, and the experience a candidate should expect.

The second half is the system the team will use to make that promise real. It defines ownership, stages, automation, privacy, assessment, onboarding, metrics, and the website experience. It is deliberately transparent. A company that asks people to trust its products should be willing to explain how it makes decisions about people.

This version supersedes the legacy Hushh Talent Acquisition Project, also known as hushhproto v0.3. It preserves the original conviction while retiring dated goals, obsolete links, repetitive instructions, the universal unpaid assignment, and any request for candidates to expose their private personal data.

One company, one clear identity

HushOne, Inc. is the legal corporation. hussh is the lowercase brand, pronounced "hush." hushh.ai is the current public site. The primary mark is the hush emoji when the medium supports it cleanly.

The current public source of truth for products, roles, and company information is hushh.ai. Product status changes quickly; the published roadmap and each role page govern when this document and a live page differ.

Contents

  • The invitation - the human, the mission, and the product system
  • The working agreement - how seven people build and what we expect from one another
  • How we hire - the candidate promise, process, work sample, and decision standard
  • Talent OS - the website, systems, automation, privacy, and accountability model
  • Onboarding - accepted offer through Day 90
  • Launch plan - the 30-day path from document to working product
  • Templates and safeguards - role briefs, scorecards, communications, and counsel review

PART I

The invitation

Build for the human.

The human is the principal

AI should not merely know more. It should answer to someone.

Today, personal information creates value for almost everyone except the person it describes. It improves advertising, risk models, recommendations, pricing, and automated decisions. Meanwhile, the individual is left with fragments: an email here, a statement there, a photo library, a medical portal, a tax folder, a family chat, a browser history, and a hundred accounts that do not work together.

This is more than an organization problem. It is an ownership problem.

Information becomes an asset to a person when it helps that person make a decision, complete an action, protect something important, earn or save money, or work better with someone they trust. That value depends on control. The owner must be able to understand what exists, decide what is used, approve who receives it, see what happened, and revoke access.

Our mission is simple:

Make personal information generally accessible and valuable to its owner - and available to the people, businesses, and agents the owner chooses - without surrendering control.

We call the category Personal Supercomputing: private intelligence, owned compute, useful context, and consent that a human can understand.

The five tests

Every important product decision should pass five tests.

  • The owner is clear. The human or business knows whose agent, data, and compute it is.
  • Consent is specific. Access has a purpose, a scope, a duration, and a way to say no.
  • The action is legible. The owner can see what happened and why.
  • Control is reversible. Permission can be changed or revoked without begging a platform.
  • Value returns to the owner. The outcome saves time, improves a decision, protects a relationship, creates income, or makes life meaningfully easier.

If a feature is impressive but fails those tests, it is not a hussh feature.

What we are building

One promise connects the product system: private intelligence that serves the owner.

SystemThe jobThe principle
Agent OneA private personal agent that works from the owner's trusted context, memory, permissions, and intent. It works alongside the assistants and models a person already uses.One agent. One loyalty. The human remains in control.
Puppy OneA personally owned supercomputer, from the phone in a pocket through laptops, desktops, workstations, and servers, configured to run Agent One and reach outside compute when the owner chooses.Own the intelligence and the machine that runs it.
PCHP and the consent fabricOpen, agent-native rails for scoped access, consent, revocation, and a receipt the owner can read.Privacy is not a setting. It is the architecture.
Kai, Nav, Counsel, and specialist agentsPurposeful agents that help with money, coordination, consent, identity, contracts, and other real work.Specialization without divided loyalty.
Tag OneA safety and wellness companion intended for people and animals an owner loves. It is a developing product direction, not a medical device.Tenderness, not tracking.
The owner-operated AI FactoryA future network in which qualified Puppy and Warehouse hosts do their own work first and can serve trusted demand with measured idle capacity.Compute should create value for the people who own and host it.

The product order

We work in an intentional order:

  • Start with the human need.
  • Define the trust boundary.
  • Design the smallest complete experience.
  • Choose the technology.
  • Make first value possible on Day 0.
  • Measure whether a real person is better off.
  • Scale only what earns repeated trust.

This protects us from building a collection of clever demonstrations. A product is not complete because a model can do something. It is complete when the right person can use it safely, understand it, and rely on it.

Where we begin

We begin where trust, sensitive information, and follow-through matter: individuals and the professionals they already trust, including registered investment advisors, financial planners, private wealth teams, family offices, insurance professionals, founders, and business owners.

These users do not need another empty chat box. They need context that stays accurate, permissions that stay clear, work that gets completed, and a record that can be explained.

Our ambition is much larger than one profession. Agent One is for every human. Focus is how we earn the right to reach that future.

What we refuse to become

We will not build a surveillance business and call it personalization.

We will not train another product on a person's private life without clear authorization.

We will not trade trust for a growth chart.

We will not hide a complicated business model behind the word "free."

We will not make a human prove ownership of their own information to a platform that extracted it.

We will not pretend that a legal consent screen is the same as informed choice.

Our financing and investment work, where applicable, is governed separately from product trust. Agent One should never need to sell the user to fund the product.

Seven people, one standard

Seven people is a design constraint.

It means we do not have a department for every problem. We do not maintain a traditional internal HR organization today. That does not remove responsibility; it makes responsibility visible. Every candidate, customer, system, and commitment has a named human owner. Specialized legal, payroll, benefits, security, and employment work belongs with qualified partners and accountable company leaders.

It also means:

  • You will speak directly with the people making the product and the decisions.
  • You may own a number, a product, a customer, and the system around it.
  • Your judgment will be visible.
  • Documentation matters because coordination cannot live in one person's head.
  • Automation is expected, but accountability remains human.
  • Priorities can change when evidence changes.
  • Everyone helps close the gap between promise and reality.

Your title describes your craft. Your responsibility is the human outcome.

If you want a finished playbook, this may feel early. If you want to help write the standard, this may be your moment.

PART II

The working agreement

Clarity is kindness. Craft is respect. Ownership closes the loop.

How we build

Work backward from the human

We begin with a person, a moment, and an outcome. We ask what the person is trying to protect or accomplish, what context is truly necessary, and what could go wrong. Only then do we choose an interface, model, database, or workflow.

Technology is a means. The human outcome is the product.

Trust before convenience

The fastest path is not always the right path. We prefer minimum necessary access, explicit permission, strong defaults, and a readable record. We explain tradeoffs in ordinary language.

Trust must be earned in the product, not requested in the marketing.

Consent must be visible and reversible

Consent has a person, purpose, scope, duration, and receipt. The owner should know what is being shared and be able to stop it. If revocation is technically impossible or operationally ignored, consent is theater.

Simplicity is earned

Simple does not mean shallow. It means the team did the hard work before asking the user to do anything.

We prefer one clear idea per surface, fewer words with higher meaning, progressive disclosure, and a complete first-value path. Beautiful products make difficult things feel obvious.

Ship whole outcomes

Small teams should own end-to-end results, not fragments tossed across functions. A feature without onboarding, permissions, instrumentation, support, and a clear customer outcome is unfinished work.

We celebrate demos. We promote durable outcomes.

Tell the truth early

Bad news does not improve with age. Raise risks while choices still exist. Separate facts, assumptions, decisions, and hopes. Be precise about what works, what is in development, and what is still a theory.

Candor is not license for cruelty. The best truth is specific, timely, and useful.

Use AI as leverage, never as an alibi

We expect every teammate to use modern AI tools where they improve speed, depth, or quality. We also expect the teammate to understand, verify, secure, and own the result.

AI can draft, search, summarize, test, schedule, and automate. It cannot absorb accountability.

Spend like an owner

Capital is stored human effort. We use it with respect. We automate repeatable coordination, buy mature systems where compliance matters, and build only where the experience is strategically different.

Low cost is not the same as low quality. The standard is highest useful value per dollar, hour, watt, and unit of attention.

The kind of builder this asks for

We hire for slope, evidence, judgment, and craft - not familiarity, charisma, or pedigree alone.

SignalWhat good looks likeWhat it is not
Human judgmentYou can identify the real need, the trust boundary, and the consequence of being wrong.Reciting frameworks after the decision has already been made.
Product craftYou make complicated things clear, coherent, and pleasant to use. You care about the last ten percent.Decorative polish on an experience that does not work.
Ability to shipYou turn ambiguity into a small complete plan, deliver it, measure it, and close the loop.Motion, activity, or perpetual prototype theater.
Clear communicationYou write and speak so decisions, owners, and next actions are obvious.Jargon, performance, or hiding uncertainty.
Learning velocityYou update quickly when evidence disagrees with your plan.Changing direction with every opinion.
Privacy and security judgmentYou minimize data, design permissions, anticipate misuse, and know when to stop and escalate.Treating compliance as a final review.
Low-ego collaborationYou challenge the work directly, share credit, ask for help, and make teammates better.Agreeableness without standards, or brilliance used as permission to diminish others.
Customer and commercial instinctYou can connect the product to a real user, distribution path, willingness to pay, and durable value.Growth detached from trust or unit economics.

We look for people who can move from first principle to working product, explain why it matters, and remain close to the person they serve.

The honest trade

What you may gain here:

  • Founding-level surface area and ownership
  • Direct access to the founder, product, customers, and decisions
  • The chance to define a category rather than optimize a mature one
  • Meaningful equity when approved and documented for the role
  • An AI-first operating environment designed to multiply individual output
  • Work whose privacy and ownership principles are easy to explain to someone you love

What the stage will demand:

  • Comfort with incomplete systems and changing evidence
  • High-quality written decisions
  • Willingness to move between strategy and execution
  • Care with sensitive information
  • A bias toward showing the working thing
  • Resilience without drama
  • The maturity to disagree clearly and commit after a decision

We work hard because the problem deserves it. Intensity is not an excuse for chaos, disrespect, or avoidable burnout.

The candidate promise

The way we hire should be proof of the company we are building.

Every candidate should receive:

  • A role page with the mission, outcomes, location model, compensation range, equity approach, benefits, and interview stages
  • A short application that collects only information needed for the decision
  • A named human owner
  • A confirmation immediately and a human review target within three business days
  • Structured interviews tied to published evidence, not improvised "culture fit"
  • A work sample that is relevant, time-bounded, and paid when it asks for substantial original work
  • Respect for pre-existing intellectual property and candidate-created work
  • A clear explanation of how AI is and is not used
  • A way to request accommodation, correct information, withdraw, or ask for deletion
  • A status update at least every three business days while active
  • A decision target within two business days of the final interview
  • A candid view of the role, the company, and the risks

We may say no. We will not treat a person's time or information as free inventory.

Our five non-negotiablesNo ghosting. No hidden work. No personal-data assignment. No AI-only decision. No confidential disclosure without a clear agreement and purpose.

PART III

How we hire

Fast enough to respect momentum. Deliberate enough to protect the decision.

The candidate journey

The standard path targets fourteen calendar days from completed application to verbal decision. Senior, regulated, immigration-dependent, or unusually complex roles may take longer; the candidate should always know why.

StageCandidate experienceEvidence soughtAutomation and human ownershipTarget
0Read the public role page. Compensation, location, outcomes, and the process are visible before applying.Self-selection and informed interest.Role Owner writes; founder approves; Talent Steward publishes.Before opening
1Complete a five-to-ten-minute application. Resume or profile plus three evidence questions; no cover letter required.Relevant outcomes, motivation, location and work authorization facts.Receipt is automatic. A named human reviews every advance and every final decline.Human review in 3 business days
2Receive the Candidate Confidentiality Agreement before any substantive interview or non-public material. A public introductory conversation may occur first if it contains no confidential information and is not used as a hidden evaluation.Willingness to protect actual non-public information under clear, mutual rules.Agreement is generated and signed electronically. The confidential stage stays locked until complete.Same day
3Meet the Role Owner for a 25-minute mission and evidence screen.Why this problem, one comparable outcome, constraints, and mutual fit.Candidate self-schedules. The Role Owner completes a structured scorecard.Within 2 business days
4Join a 45-minute craft and judgment interview.Depth in the role, quality bar, decisions, failures, privacy and security judgment.Interview kit and questions are fixed before the interview. Notes require candidate consent if recorded.Within 3 business days
5Complete a representative build session or paid work sample.Ability to turn a first principle into a useful, clear, and complete outcome.The rubric is shared in advance. Synthetic or company-provided data only.2-4 hours maximum
6Discuss the work with two future collaborators in a 60-minute working session.Reasoning, response to feedback, collaboration, and ability to improve the artifact.Interviewers submit independent scorecards before the debrief.Within 2 business days
7Meet the founder for mutual conviction, company truth, role scope, and closing questions.Shared ambition, judgment, ownership, and an honest decision by both sides.Founder records a clear yes/no and unresolved risks.30-45 minutes
8References and role-specific checks occur with consent. Background checks, if needed, follow a conditional offer and applicable law.Verification proportionate to the role.Separate disclosures and authorizations; no bundled waivers.1-3 business days
9Receive a written offer that states role, manager, location, compensation, equity terms subject to approval, benefits, start date, contingencies, and at-will status where applicable.A complete mutual commitment.Founder, finance/operations, and counsel-approved workflow.Within 2 business days of final decision
10Enter a secure preboarding portal with one owner, one checklist, and a written 30/60/90 plan.Readiness for first value on Day 0.Employment system, identity, device, access, payroll, and onboarding tasks are orchestrated.Start-ready 2 business days before Day 1

The confidentiality gate

The request to protect research and development before substantive interviews is reasonable only if the agreement is narrow, clear, and lawful.

The Candidate Confidentiality Agreement should:

  • Protect specifically defined non-public product, security, customer, financial, and technical information
  • Apply before confidential materials or evaluated substantive interviews are unlocked
  • Be mutual where the candidate may share confidential work or employer information
  • Exclude public information, prior knowledge, independently developed information, and information rightfully received from another source
  • Permit disclosure to legal counsel and government agencies and preserve protected reporting, whistleblower, labor, wage-discussion, discrimination, harassment, and other non-waivable rights
  • Include the federal trade-secret immunity notice where required
  • Avoid ownership of a candidate's general skills, ideas, pre-existing work, or lawful future work
  • State a reasonable term and a longer obligation only for information that legally remains a trade secret
  • Give the candidate a downloadable signed copy
  • Be reviewed for the candidate's jurisdiction before launch

An NDA is not permission to disclose everything. Information staging still matters. Public context comes first. Role-specific non-public context comes only when needed.

The background-check disclosure and authorization must remain a separate document. The confidentiality agreement must never include a release of claims or a promise not to discuss wages or working conditions.

The build session

The old hushhproto assignment asked every technical candidate to spend up to a week connecting personal data to a search or chat experience. That standard is retired.

It contradicted the privacy thesis, created unnecessary security risk, consumed too much candidate time, and could produce commercially useful work without clear payment or ownership.

Talent 1.0 replaces it with a representative build session.

The rules

  • Only the final two or three candidates complete a work sample.
  • The default is two hours. Four hours is the hard maximum without a separate paid trial agreement.
  • The default stipend is the greater of $300 or the role's reasonable hourly equivalent for the stated maximum time, adjusted when local law or the work requires more. A short live working session may be unpaid when it is clearly evaluative, uses no production work, and stays within ordinary interview time.
  • The prompt uses synthetic, public, or company-provided data. Candidates are never asked to upload personal takeouts, customer data, credentials, or another employer's confidential information.
  • The rubric, time box, allowed tools, deliverables, and ownership terms are visible before the candidate accepts.
  • AI tools are allowed. The candidate explains material use and remains responsible for the result.
  • The candidate owns pre-existing intellectual property. hussh receives only the limited right to evaluate the submission.
  • hussh does not ship, sell, or otherwise use rejected candidate work. If the company wants production rights, it enters a separate paid agreement.
  • Accommodations and an equivalent alternative format are available.

Role-specific prompts

TrackRepresentative challengeEvidence
Product and engineeringBuild the smallest consent-first experience that helps a fictional user share one piece of trusted context with one advisor and revoke it. Use synthetic data.Architecture, working path, security judgment, tests, usability, and explanation of tradeoffs.
DesignRedesign one first-value flow so a human can understand what Agent One will use, why, and how to stop it.Information hierarchy, interaction craft, accessibility, states, and clarity under constraint.
GTM and partnershipsCreate a 30-day design-partner plan for one defined advisor or insurance ICP, with ten target accounts, a customer story, outreach sequence, and learning goals.Customer insight, specificity, commercial judgment, measurement, and follow-through.
Marketing and PLGDesign one launch loop that takes a person from a true story to trying Agent One and reaching first value, with a small budget and explicit trust claims.Authentic story, channel fit, conversion logic, instrumentation, and brand judgment.
OperationsMap and automate one candidate or customer workflow with states, owners, exception handling, auditability, and a simple dashboard.Systems thinking, completeness, reliability, privacy, and operational taste.

Shared rubric

DimensionWeightThe question
Human usefulness25%Does the work solve a meaningful problem for the intended person?
Craft and simplicity20%Is the result coherent, clear, and pleasant without hiding complexity?
Role depth20%Does the candidate demonstrate the technical, design, commercial, or operating judgment the role requires?
Privacy and security15%Is data minimized, consent explicit, misuse anticipated, and control reversible?
Execution10%Is the work complete enough to test, learn from, and improve?
Communication and learning10%Can the candidate explain choices, identify limitations, and update after feedback?

The interview standard

Every interview evaluates a defined question. Every interviewer receives a kit. Every scorecard is completed independently before the debrief.

The evidence scale

ScoreMeaningEvidence standard
1Clear concernThe example is absent, contradictory, unsafe, or materially below the role requirement.
2Below the barSome relevant evidence exists, but important depth, ownership, or judgment is missing.
3Meets the barSpecific evidence shows the candidate can perform the role at the expected level.
4Raises the barRepeated evidence shows unusual depth, judgment, craft, learning, or leverage.

Interviewers score evidence, not personality similarity. "I liked them" is not a hiring argument. "They owned X, chose Y because of Z, measured Q, and learned R" is.

Decision rules

  • The Role Owner recommends hire or no hire.
  • The founder approves every full-time hire while the company remains this small.
  • Security, integrity, discrimination, retaliation, or material-trust concerns cannot be averaged away.
  • A no based on a remediable information gap can trigger one targeted follow-up, not an entire repeated loop.
  • References verify a decision; they do not replace structured evidence.
  • The final debrief records strengths, risks, conditions, dissent, and the owner of each unresolved question.
  • AI may organize evidence. It may not cast a vote or make the final decision.

How AI is used in hiring

AI is useful for coordination. It is dangerous when convenience quietly becomes authority.

Allowed

  • Answering public process questions
  • Scheduling and reminders
  • Drafting role descriptions and candidate communications for human approval
  • Checking whether required fields, scorecards, and approvals are complete
  • Summarizing consented interview notes without adding unsupported claims
  • Generating structured interview-question suggestions from an approved rubric
  • Alerting owners when a candidate is waiting
  • Producing aggregate operational metrics

Not allowed

  • Making the final hire or decline decision
  • Ranking people through an opaque model
  • Inferring protected traits, health, emotion, personality, honesty, or "culture fit" from a face, voice, name, address, or writing style
  • Scraping non-public personal information
  • Running an undisclosed social-media investigation
  • Recording an interview without explicit notice and consent
  • Using candidate data to train a general model without specific permission
  • Auto-rejecting from an AI score
  • Hiding the identity of the accountable human decision-maker

Every candidate can ask how AI affected the process and request an accommodation or human alternative where required.

PART IV

Talent OS

Automate coordination. Preserve care. Make accountability impossible to lose.

The operating model

hussh does not need a large recruiting department. It does need a real system.

The first principle is one candidate record, one current state, one accountable owner, and one next action.

Human roles

RoleAccountable forCannot delegate
Founder and CEOHeadcount approval, leadership bar, final full-time approval, company truth, closing.The final decision and the accuracy of material company claims.
Role OwnerRole brief, sourcing strategy, candidate relationship, assessment quality, recommendation, and 30/60/90 outcomes.Candidate care and the hiring recommendation.
Talent StewardPipeline integrity, SLAs, templates, scheduling exceptions, audit readiness, and weekly operating review. This can be a rotating six-month operating role.Ensuring no candidate becomes ownerless.
InterviewerEvidence for a defined competency and an independent scorecard.The accuracy of observations and conflicts of interest.
Finance and People OperationsCompensation mechanics, approvals, payroll, benefits, worker classification workflow, and employment-system completeness.Correct pay and a complete employee record.
Security and IT OwnerDevice, identity, least-privilege access, training, monitoring, and timely revocation.Security approval for privileged roles and systems.
External employment counsel or qualified partnerJurisdiction-specific templates, NDA carve-outs, worker classification, pay transparency, immigration, checks, and policy review.Legal advice; software must not invent it.

Automation can remind, route, lock, unlock, summarize, and verify completion. It cannot own a human relationship.

The recommended launch stack

Build the experience. Buy the regulated recordkeeping.

LayerRecommended systemJobFirst-principles reason
Experiencehushh.ai careers and candidate portalPublic story, role pages, application handoff, status, confidentiality, scheduling, work sample, privacy controls, and onboarding view. Agent One can power the concierge.This is the differentiated human experience and should feel like hussh.
Recruiting system of recordAshbyJobs, applications, stages, scheduling, interview kits, scorecards, approvals, analytics, and webhooks.Do not build an ATS. Ashby is designed for structured recruiting and currently offers a startup plan up to 100 employees.
Agreement systemDocuSign, integrated through the planned Paperwork AgentCandidate Confidentiality Agreement, offer and supporting signatures, status, copies, and an audit trail. Ashby's built-in e-signature can be the fallback if it meets counsel and integration requirements.One counsel-approved template source and one authoritative signature record.
U.S. employment and benefitsJustworks PEO, subject to final quote and benefits reviewPayroll, benefits, workers' compensation, required onboarding, and employer administration.With seven people and no internal HR department, a PEO converts recurring compliance operations into a managed service.
Interim employee recordQuickBooks only until PEO cutoverExisting I-9 and onboarding records that must be completed and preserved.Avoid disrupting current obligations, then retire duplicate ownership.
Identity and productivityGoogle Workspace and Cloud IdentityEmail, calendar, groups, identity, multi-factor authentication, and access lifecycle.A familiar identity spine already in use.
Background screeningA reputable FCRA-compliant provider integrated with the ATS, such as Checkr, after approvalRole-proportionate checks after a conditional offer, with disclosures, authorization, dispute, and adverse-action workflows.Never improvise sensitive checks or store reports in the website database.
Exceptional international hiringRemote EOR after role, country, tax, IP, security, and cost approvalEmployer-of-record for selected hires outside the United States.International hiring should be possible, not accidental.

The launch should not implement both a PEO and a second new HRIS. Select one employer system of record. Keep QuickBooks only through a controlled migration, with explicit record ownership and retention.

Ashby's public pricing listed its Foundations plan at $400 per month for up to 100 employees in July 2026, with a stated annual discount. Vendor pricing and feature availability must be reconfirmed before purchase.

If the Justworks quote or benefits network does not meet the company's needs, the clean one-platform alternative is Rippling PEO with Recruiting and IT. Do not buy both recruiting stacks. Choose Ashby plus the selected PEO when a deeper candidate experience is the priority; choose Rippling's integrated path when one-vendor employee, identity, and device administration is more valuable.

The website experience

The current careers page has the right opening idea: "Build the future people actually own." Talent 1.0 turns it into a complete product.

Public surfaces

RoutePurposeMinimum content
/careersBelief and orientationFounder invitation, mission, product system, working principles, open roles, how we hire, and contact path.
/careers/roles/[slug]The role contractWhy now, three to five outcomes, manager, location, approved work states or countries, compensation and equity approach, benefits, evidence required, interview map, work sample, and start target.
/careers/how-we-hireProcess transparencyStages, timing, candidate promise, confidentiality timing, work-sample rules, AI-use policy, accommodations, and FAQs.
/careers/candidate-privacyCandidate data controlData collected, purposes, providers, access, AI use, recording policy, retention, correction, deletion, legal exceptions, and contact.
/careers/accessibilityAn equal pathHow to request an accommodation or alternate application/interview format without explaining more than necessary.
/careers/talent-communityConsent-based future contactExplicit opt-in, interests, update frequency, unsubscribe, and retention. No automatic marketing enrollment.

Secure candidate portal

The portal opens through a short-lived magic link or passkey and shows only the candidate's own record.

Creating a commercial hussh or Agent One account is never required to apply. The portal identity is limited to the recruiting relationship, and an equally complete email-based accommodation is available when needed.

It should provide:

  • Current stage in plain language
  • Named Role Owner and next expected update
  • One primary next action
  • Confidentiality agreement and signed-copy download
  • Self-scheduling and rescheduling
  • Interview agenda and interviewer names
  • Work-sample prompt, rubric, timer expectation, payment terms, and submission
  • Accommodation request
  • Correction, withdrawal, and deletion request
  • Offer documents and preboarding checklist when applicable
  • A Candidate Concierge powered by Agent One for process questions

The concierge receives only public content before authentication and only the minimum candidate-specific status after authentication. It cannot access hidden interview notes, other candidates, references, background reports, compensation approvals, or final deliberations.

Internal hiring console

The team needs one small view:

  • Open roles and approved headcount
  • Candidates waiting by stage
  • Owner, next action, and SLA clock
  • Missing scorecards, signatures, approvals, and documents
  • Conflicts and accommodations requiring human attention
  • Offer status
  • Accepted hires and Day 0 readiness
  • Weekly funnel and candidate-experience metrics

This console can be an Ashby dashboard at launch. Build a custom internal surface only where it materially improves the hussh workflow.

The state machine

The workflow engine should treat stage transitions as explicit events, not free-form labels.

StateEntry conditionAutomatic actionHuman gate
ROLE_DRAFTRole Owner submits a one-page brief.Validate required fields and create approval tasks.Founder and finance approve headcount and range.
PUBLISHEDApproved role is live.Publish or sync the role, structured data, application, and interview plan.Talent Steward checks the public experience.
APPLIEDCandidate submits.Confirm receipt, create the record, set privacy version, assign owner, start review SLA.Role Owner reviews.
CONFIDENTIALITY_REQUIREDCandidate is selected for substantive evaluation.Generate and send the jurisdiction-appropriate agreement; lock non-public materials and evaluated interviews.Candidate signs; exceptions go to counsel.
CONFIDENTIALITY_COMPLETEValid signed agreement is stored.Release scheduling link and approved context.Role Owner conducts screen.
SCREENScreen scheduled or completed.Reminders, agenda, scorecard task, and next-step SLA.Role Owner advances or declines with evidence.
CRAFTCraft interview scheduled or completed.Interview kit and scorecard task.Interviewer submits independent evidence.
WORK_SAMPLECandidate agrees to prompt and payment terms.Release prompt, rubric, submission path, payment task, and deadline.Reviewers score independently.
WORKING_SESSIONWork is submitted and meets basic completeness.Schedule collaborators and prepare artifact.Panel evaluates reasoning and collaboration.
FINALFounder meeting is scheduled or complete.Assemble evidence summary with no AI recommendation.Founder and Role Owner decide.
CONDITIONAL_OFFERHire decision and compensation approval are complete.Send offer and separate role-specific authorizations.Candidate accepts; checks resolve.
ACCEPTEDOffer accepted and contingencies cleared.Create employment-system record, Day 0 plan, device and access tasks.Finance, Security, and Role Owner confirm readiness.
ACTIVEStart date arrives and required employment verification is complete.Start onboarding milestones and feedback cadence.Role Owner owns performance and experience.
DECLINEDHuman records a job-related reason.Send respectful message, retention choice, and optional feedback survey.Role Owner verifies decision and message.
WITHDRAWNCandidate withdraws.Confirm, stop reminders, close access, and apply retention/deletion rule.Talent Steward resolves any open payment or document duty.

Every transition writes an immutable audit event with timestamp, actor, source, previous state, new state, and reason. Failed webhooks retry safely and do not create duplicate messages, documents, or hires.

Data model and privacy

Minimum core records

  • Role: mission, outcomes, location, range, level, manager, approvals, interview plan
  • Candidate: identity and contact fields the person provides
  • Application: source, role, evidence answers, resume/profile, consent version
  • Process: current state, owner, next action, SLA, accommodations restricted to need-to-know users
  • Agreement: template version, jurisdiction, envelope identifier, status, signed artifact hash
  • Interview: purpose, schedule, attendees, consent status, scorecard, evidence
  • Work sample: prompt version, payment terms, submission, evaluation, IP acknowledgment
  • Decision: recommendation, evidence, dissent, final human approver, reason
  • Offer: approved terms, documents, conditions, signature status
  • Onboarding case: employment-system identifier, checklist, device, accounts, training, 30/60/90 outcomes
  • Audit event: actor, action, object, time, before, after, and source

Privacy rules

  • The public web application never stores resumes, signed agreements, background reports, tax forms, identity documents, or medical/accommodation details in general application logs.
  • Sensitive records live in the system designed for them.
  • Access is role-based and reviewed quarterly.
  • Interview recording is off by default. When used, notice and explicit consent precede recording, and a non-recorded path remains available.
  • Candidate data does not train a general-purpose model without separate, specific permission.
  • No interviewer copies candidate material into an unapproved personal AI account.
  • Retention is published, jurisdiction-aware, record-specific, and approved by counsel. It is not hard-coded to one universal period. A separately consented talent-community profile may use a 24-month default, while required recruiting records may need shorter or longer treatment based on location, employer coverage, pending claims, or legal holds.
  • Candidates can correct factual data, withdraw, or request deletion. Legal retention exceptions are explained.
  • Background reports and work-authorization documents are separated from interview evidence and limited to authorized users.
  • Logs never contain passwords, tokens, government ID images, or complete background-report content.
  • Voluntary demographic information, when collected lawfully, is segregated from the candidate record and hidden from decision-makers.
  • Every AI feature used in the process has an owner, purpose, approved inputs, vendor and model version, evaluation date, known limitations, and a disable switch.

Automation rules

The workflow should be boring in the best way: deterministic, observable, idempotent, and easy to recover.

  • A candidate never waits without an owner and due date.
  • A stage cannot advance when a required agreement, scorecard, approval, or disclosure is missing.
  • A confidential link cannot open before the agreement state is valid.
  • A scorecard becomes read-only when the interviewer sees the debrief, preventing consensus from rewriting independent evidence.
  • A final decline requires a human actor and job-related reason.
  • A final hire requires founder approval while the team remains small.
  • An offer cannot send until compensation, location, worker classification, and counsel-approved template checks pass.
  • A background check cannot start before a conditional offer and separate authorization unless counsel approves a different lawful sequence.
  • An employee account cannot activate before a valid start state; privileged access requires an additional security approval.
  • A separation or rescinded start automatically opens immediate access-revocation and property-return tasks.
  • Every candidate-facing automation has a reply path to a human.
  • Every failure appears in an exception queue; silence is never treated as success.

The weekly operating review

Thirty minutes, once a week, with the founder, active Role Owners, and Talent Steward.

Agenda:

  • Candidates waiting past SLA
  • Roles without enough qualified evidence
  • Missing scorecards or approvals
  • Candidate experience concerns
  • Offers, acceptance risk, and start readiness
  • Funnel quality by source
  • Automation failures and one process improvement

No meeting should become a tour of every candidate. Discuss exceptions, decisions, and system improvement.

The scoreboard

MetricInitial standardWhy it matters
Application confirmationImmediateRemoves uncertainty.
Human review90% within 3 business daysAutomation cannot substitute for accountable review.
Active-candidate updateAt least every 3 business daysNo ghosting.
Interview scheduling waitMedian under 2 business daysRespects momentum.
Scorecard completion100% before debriefProtects independent judgment.
Final decisionWithin 2 business days of final interviewDemonstrates clarity.
Median application-to-decision14 calendar days or lessFast enough for a small company.
Work-sample payment100% within 5 business days of accepted submissionCandidate time is not free inventory.
Candidate experience70+ candidate NPS, with response themes reviewedMeasures whether the process earns trust.
Offer acceptance80% or better, interpreted with sample sizeTests role clarity and closing quality.
Day 0 readiness100% two business days before startFirst value should not begin with missing access.
30/60/90 plan100% before Day 1Hiring is incomplete without success definition.
90-day outcome review100%Connects selection evidence to actual performance.

Small samples can mislead. Use numbers to ask better questions, not to manufacture certainty.

PART V

Onboarding

An accepted offer is not the finish line. It is the first product promise to a teammate.

Accepted offer to Day 0

Within one business day of acceptance, the new teammate receives:

  • A welcome from the founder
  • A named Onboarding Owner, normally the Role Owner
  • A secure portal with one checklist and due dates
  • Employment, payroll, benefits, policy, and work-authorization tasks
  • A clear equipment and approved-work-location plan
  • The first-week calendar
  • The role scorecard and written 30/60/90 outcomes
  • A short company and product reading path
  • A way to ask private questions of the PEO or appropriate owner

Company readiness

The team completes:

  • Worker classification, approved state or country, compensation, manager, start date, and payroll record
  • Required forms and role-specific agreements
  • Background and reference conditions, if any
  • Device assignment, shipping, inventory, full-disk encryption, update policy, endpoint controls, and recovery plan
  • Google Workspace and Cloud Identity account with phishing-resistant multi-factor authentication
  • Least-privilege groups for calendar, documents, GitHub, cloud, CRM, support, and other role systems
  • Named data-access owner and privileged-access expiration where appropriate
  • Security, privacy, acceptable-use, confidential-information, and incident-reporting training
  • A first customer or user story
  • A first meaningful deliverable sized for Week 1

Where practical, a hussh-configured Puppy One or company device arrives with Agent One ready on Day 0. The experience should reflect the same promise made to a customer: open the box, meet your agent, know what it can access, and begin useful work.

Work-authorization verification begins only after offer acceptance. The employee completes Form I-9 Section 1 no later than the first paid workday; the company completes Section 2 within three business days of starting. The employee chooses which acceptable documents to present. I-9 records remain separate and restricted, and are retained for three years after hire or one year after employment ends, whichever is later.

Day 1, Week 1, Day 30

Day 1: understand the promise

  • Founder story: why the human is the principal
  • Product map: Agent One, Puppy One, consent fabric, specialist agents, Tag direction, and compute network
  • One real customer or user journey
  • Company economics, current priorities, and the difference between shipped, building, and exploring
  • Privacy and security model
  • Role outcomes, decision rights, and escalation paths
  • Every teammate, in one day, because seven people should know one another

The new teammate uses the product, not just the slides.

Week 1: touch reality

  • Observe or review one real user problem
  • Complete security and employment setup
  • Reproduce the current first-value experience
  • Make one small improvement to the product, customer experience, story, or operating system
  • Document what was confusing and what should change
  • Hold a Friday review with the Role Owner

Days 8-30: own and ship

The teammate owns one meaningful, measurable improvement end to end. It should be small enough to finish and real enough to matter.

Examples:

  • Engineering ships a consented user flow with tests, telemetry, and rollback.
  • Product or design improves first value and validates it with users.
  • GTM recruits and learns from a defined set of design partners.
  • Marketing launches one authentic story-to-activation loop.
  • Operations removes a repeated manual workflow and documents the exception path.

Day 30 ends with evidence: what changed for the user, what the team learned, what remains uncertain, and what the teammate will own next.

The 30/60/90 compact

HorizonHuman outcomeBusiness or product outcomeEvidence
Day 30Understand the user, trust model, team, and operating rhythm.Ship one useful improvement and close the loop.Working artifact, customer or user signal, written learning review.
Day 60Operate independently within clear decision rights.Own a repeatable metric, product surface, customer segment, or operating system.Trend, quality, reliability, or pipeline evidence; risks and next decisions.
Day 90Increase the output and judgment of the team around you.Deliver the role's first major outcome and a credible next-quarter plan.Measured result, stakeholder review, self-assessment, manager assessment, and updated role plan.

The Role Owner and teammate review progress at Days 15, 30, 60, and 90. No one should discover at Day 90 that the definition of success changed silently.

Interns, contractors, and international teammates

The human standard is the same; the legal and access path is not.

Interns

  • A real learning plan, named mentor, paid status unless a counsel-approved exception applies, time records where required, and work appropriate to the program
  • For STEM OPT or similar programs, designated officials, training plans, supervision, compensation, and worksite requirements are handled as a compliance workflow, not an email afterthought
  • No intern owns a production-critical system without supervision

Contractors and consultants

  • Classification is based on the real relationship, not the title of the agreement
  • Scope, deliverables, independence, payment, IP, confidentiality, security, and access expiration are explicit
  • Contractors receive only the systems and data necessary for the engagement
  • A recurring employee-like relationship triggers reclassification review

International hires

  • Country availability, EOR cost, IP assignment, data transfer, export controls, security, benefits, payroll, time-zone expectations, and permanent-establishment risk are approved before the offer
  • Remote EOR is the default partner path for exceptional international employees unless a local entity or another approved structure is more appropriate

Access is a lifecycle

Onboarding and offboarding are one system.

When a role changes or employment ends:

  • The human decision and effective time are recorded
  • Identity, sessions, credentials, keys, groups, and privileged access are revoked by policy
  • Devices and company information are returned or securely handled
  • Personal data is separated from company data
  • Payroll, benefits, legal notices, and final pay follow the applicable jurisdiction
  • The owner confirms completion
  • The audit trail is preserved

The goal is not suspicion. It is responsible stewardship of people, customers, and information.

PART VI

From document to product

Thirty days to a working Talent OS.

The 30-day launch plan

Week 1: decide and protect

Owner: Founder with Talent Steward, finance/operations, security, and employment counsel.

  • Approve Talent 1.0 and name the Talent Steward
  • Confirm the public legal line, brand line, recruiting email, company locations, and role-location policy
  • Decide the U.S. employer system of record: complete the Justworks PEO quote and benefits review, or document the chosen alternative
  • Approve the Candidate Confidentiality Agreement, offer templates, IP/inventions agreement, contractor template, privacy notice, accommodation path, recording notice, background-check workflow, and retention schedule
  • Approve the paid work-sample policy and expense/payment workflow
  • Select one live role as the pilot
  • Write its one-page role brief and 30/60/90 outcomes

Exit test: no open question remains that would make the public role page materially misleading.

Week 2: configure the systems

Owner: Talent Steward with one engineer.

  • Configure Ashby organization, roles, states, scorecards, templates, scheduling, approvals, permissions, privacy, analytics, and webhooks
  • Configure DocuSign templates and the Paperwork Agent integration
  • Connect Google Calendar and approved mail delivery
  • Configure the employer-system new-hire workflow
  • Select and configure the background-screening integration only for roles that require it
  • Define canonical identifiers and prevent duplicate candidate and employee records
  • Build the exception queue, retries, and audit events
  • Test access with least-privilege roles

Exit test: a synthetic candidate can move from application through signed confidentiality, interviews, work sample, offer, and accepted state without a spreadsheet or private inbox becoming the system of record.

Week 3: make it feel like hussh

Owner: Product/design with one engineer.

  • Publish the manifesto and how-we-hire page
  • Publish the candidate privacy and accessibility pages
  • Build the role template and pilot role
  • Embed or API-connect the application
  • Build the secure candidate status surface
  • Add Candidate Concierge answers from approved public content
  • Add scheduling, signature, work-sample, withdrawal, correction, deletion, and accommodation actions
  • Verify mobile, keyboard, screen-reader, contrast, empty, error, expired-link, and retry states

Exit test: a candidate can understand the company, the role, the process, and their next step on a phone without emailing for basic coordination.

Week 4: rehearse, measure, launch

Owner: Talent Steward.

  • Run three synthetic candidates: advance, decline, and accommodation/exception
  • Run a lost-webhook, duplicate-webhook, expired-link, no-show, signer-name mismatch, and offer-change test
  • Conduct a security and privacy review
  • Train interviewers and require a sample scorecard
  • Verify every template in plain language
  • Confirm Day 0 device, account, PEO, payroll, and I-9 readiness
  • Publish the pilot role
  • Review the first ten candidate journeys daily
  • Hold a Week 1 retrospective and fix the highest-friction point

Exit test: the team can run the process with less than two hours of Talent Steward coordination per active role per week, excluding interviews and candidate conversations.

Build versus buy

Phase 1 should take one product-minded engineer and one operating owner roughly two to four weeks using embedded ATS experiences and webhooks. A richer custom portal can follow after the process has handled real candidates.

Build now:

  • hussh story and role experience
  • Candidate status and next-action surface
  • Agent One concierge with strict data boundaries
  • Workflow orchestration where cross-system state must be visible
  • Metrics and exception view unique to the seven-person operating model

Buy now:

  • Applicant tracking and scheduling
  • Legally reliable e-signature and agreement retention
  • PEO/payroll/benefits/workers' compensation
  • Background screening
  • Identity, email, calendar, and device management foundations

Do not build payroll, I-9 verification, background-report storage, benefits administration, or a generic ATS. These systems create risk without creating product differentiation.

Definition of done

Talent 1.0 is live when:

  • One current public document replaces the legacy v0.3 material
  • Every open role uses the role-brief template and publishes compensation, location, outcomes, and stages
  • Every candidate has a human owner, state, next action, and SLA
  • Confidential material stays locked until the correct agreement is signed
  • No work sample uses personal data or uncompensated production work
  • Every interview has a defined question and completed scorecard
  • AI performs no final ranking, hire, or decline
  • Candidate privacy, accessibility, AI use, recording, retention, and deletion are published
  • An accepted candidate reaches Day 0 with device, identity, payroll, benefits, access, and 30/60/90 plan ready
  • The weekly dashboard works without a spreadsheet
  • Counsel, security, finance/operations, and the founder have approved their parts
  • The team has completed one end-to-end rehearsal and fixed the exceptions found

APPENDICES

Reusable templates

One standard, repeated well.

Appendix A: the one-page role brief

Every role begins here. If this page is not clear, the company is not ready to recruit.

Identity

  • Role title and level
  • Role Owner and manager
  • Employment type
  • Approved location, work states or countries, time-zone expectations, and travel
  • Compensation range, variable compensation mechanics, equity approach, benefits, and any material conditions
  • Target start date

Why now

One paragraph: what human or business problem cannot be solved without this hire, why it matters now, and what happens if the company does not hire.

Mission

One sentence beginning with an action verb.

Example: "Make Agent One's first consented advisor workflow obvious, trustworthy, and useful in under ten minutes."

Outcomes

Three to five measurable outcomes, each with a horizon.

  • Day 30
  • Day 60
  • Day 90
  • Month 6
  • Month 12 when appropriate

Evidence required

  • Must-have craft or domain depth
  • Comparable outcomes
  • Security, privacy, regulatory, or customer requirements
  • Helpful but non-essential experience
  • Explicitly unnecessary pedigree or credentials

Decision rights and constraints

  • What this role owns
  • What requires founder, security, legal, or finance approval
  • Budget, people, data, customer, and system access
  • Known tradeoffs and risks

Interview map

For each stage: purpose, interviewer, evidence, scorecard, candidate time, and decision SLA.

Work sample

Prompt summary, expected time, stipend, allowed tools, synthetic data source, rubric, IP terms, and alternative/accommodation path.

Appendix B: interviewer scorecard

Candidate:

Role:

Interview:

Interviewer:

Date:

Question this interview was designed to answer:

Evidence observed:

Candidate's specific action:

Outcome and measurement:

Tradeoff or constraint:

What the candidate learned:

Score, 1-4:

Confidence: low / medium / high

Material concern:

Follow-up question, if any:

Conflict of interest or prior relationship:

Recommendation for this competency only: below / meets / raises

Interviewers should not include protected information, medical details, family status, irrelevant appearance comments, speculation about personality, or unsupported AI inferences.

Appendix C: work-sample cover sheet

Purpose:

This exercise helps both sides experience the work. It is not production work.

Time:

Expected two hours; stop at four. Note where you would go next rather than exceeding the limit.

Payment:

The greater of $300 or the role's reasonable hourly equivalent for the stated maximum time after a good-faith completed submission, subject to the written invitation and lawful payment setup.

Data:

Use only the provided synthetic/public data. Do not include personal, customer, employer, credential, or confidential information.

Tools:

Use any lawful tool you would use on the job, including AI. Briefly explain material AI assistance and how you verified the result.

Deliverable:

A working artifact or concrete plan, a short explanation, assumptions, risks, and the next test.

Ownership:

You keep your pre-existing IP. hussh may review the submission for hiring and will not put rejected candidate work into production. Any broader use requires a separate written, paid agreement.

Rubric:

Human usefulness 25%; craft and simplicity 20%; role depth 20%; privacy and security 15%; execution 10%; communication and learning 10%.

Appendix D: candidate communications

Application receipt

Subject: We received your application for [role]

Thank you for considering hussh. Your application is with [Role Owner], the human accountable for this role. We aim to complete a human review within three business days. You can see the process, update your information, request an accommodation, or withdraw at [secure link].

We will not add you to marketing or use your information to train a general AI model.

Confidentiality request

Subject: One clear agreement before we go deeper

We would like to invite you into the substantive interview stage for [role]. The conversation may include non-public product and business context, so we ask every candidate at this stage to sign the attached Candidate Confidentiality Agreement first.

It is designed to protect actual confidential information while preserving protected reporting, wage discussion, legal advice, and other rights that cannot or should not be restricted. Please read it carefully, keep a copy, and send questions to [human contact]. Once signed, your scheduling link and interview context will unlock automatically.

Interview invitation

Subject: Your [role] conversation with hussh

You will meet [name] for [duration]. The conversation is designed to understand [published competency]. We will discuss one outcome you owned, the decisions you made, what changed for the user, and what you learned. No surprise puzzle is required.

Agenda, scheduling, accessibility options, and your status are at [secure link].

Work-sample invitation

Subject: A small, paid build session

We would like to invite you to the final work stage. The exercise is designed for approximately two hours, is capped at four, and pays the greater of $300 or the role's stated hourly-equivalent amount under the attached terms.

The prompt uses synthetic data. Please do not share personal information, credentials, customer information, or another employer's work. The rubric and ownership terms are visible before you accept. AI tools are welcome; explain how they helped and how you verified the result.

Decline

Subject: An update from hussh

Thank you for the time and care you invested in [role]. We have decided not to move forward.

The decision was made by [Role Owner] against the published requirements for this opening. It is not a judgment on your worth or future slope. Any work-sample payment already earned will be completed regardless of this decision.

You can choose whether we retain your profile for future roles, request deletion subject to legal retention, or share process feedback at [secure link].

Offer

Subject: Come build the future people actually own

We would like you to join hussh as [role].

The formal offer at [secure link] states the role, manager, location, compensation, equity terms subject to approval, benefits, start date, contingencies, and employment terms. Your 30/60/90 outcomes are included so the promise is clear before you sign.

Read everything. Ask every question. If we both choose yes, we will make Day 0 worthy of the decision.

Appendix E: counsel and compliance review triggers

This document is an operating design, not a substitute for legal advice. Before launch, qualified counsel should review:

  • Candidate Confidentiality Agreement and all protected-rights carve-outs
  • Federal trade-secret immunity notice
  • Washington and other state restrictions on nondisclosure and nondisparagement
  • The federal Speak Out Act
  • Wage discussion, concerted activity, whistleblower, discrimination, harassment, retaliation, and agency-reporting rights
  • Pay-transparency requirements for every role location
  • Salary-history prohibitions and protected discussions of wages, benefits, and working conditions
  • Candidate and employee privacy notices, retention, recording, biometric, and automated-decision rules
  • Accessibility and reasonable-accommodation paths
  • AI or automated employment decision tool rules in every jurisdiction in which the system is used
  • Work-sample payment, wage, IP, tax, and reimbursement treatment
  • Background-check timing, standalone disclosure and authorization, pre-adverse and adverse action, and local fair-chance rules
  • Worker classification and contractor conversion review
  • Immigration, STEM OPT, E-Verify if applicable, and Form I-9 timing and storage
  • International EOR, data transfer, export controls, tax, benefits, and permanent-establishment concerns
  • Required recruiting-record retention and legal holds
  • Offer, at-will, equity, inventions, confidentiality, dispute, and policy language

Product policy

Even where a rule does not yet apply to a seven-person employer, hussh should voluntarily adopt the clearer, fairer standard when it is operationally reasonable. Trust is easier to preserve than to repair.

Headcount is never a blanket exemption. Coverage depends on the law, the candidate and worker locations, related entities, and the activity involved. The operating system should use a high national baseline and route location-specific exceptions to counsel.

Appendix F: source notes

Company source of truth:

  • Brand and legal identity
  • Company and history
  • Product system
  • Agent One and Personal Supercomputing
  • Business principles
  • Current careers page

Systems:

  • Ashby pricing and startup plan
  • Ashby recruiting capabilities
  • DocuSign eSignature

Primary compliance references:

  • EEOC: AI and disability discrimination
  • FTC: background checks for employers
  • USCIS: completing Form I-9
  • Washington RCW 49.44.211
  • Speak Out Act, Public Law 117-224
  • Federal trade-secret immunity notice, 18 U.S.C. 1833
  • SEC whistleblower protections
  • New York City automated employment decision tools
  • IRS worker classification

The invitation

Show us something you made, the person it helped, and what you learned when reality disagreed with your plan.

Come help build a world in which your information is your decision, your capability, and your business.

Build for the human.

careers@hushh.ai

Explore current roles

HushOne, Inc. | hussh | Talent 1.0