Free for your first month. No credit card required. Get started »

Comparison

How recruiters manage off-limits lists: memory vs spreadsheet vs ATS vs Bycatch

Every recruitment business has companies it must not source from: current clients, recent clients inside a protection period, and companies in its own group. The question isn’t whether you have an off-limits list. It’s where it lives, and whether a consultant actually sees it at the moment they are about to send a message.

There are really only four ways teams do this. We make one of them, so read the Bycatch column with that in mind. We’ve tried to be straight about where each approach is enough and where it isn’t.

Memory

Everyone is expected to know who the clients are.

How it works

There is no list, or there is one in the founder’s head. Consultants learn the client base by osmosis and ask a colleague when they’re not sure.

Where it’s enough

Genuinely fine for a solo recruiter or a two-person desk with a handful of long-standing clients. Everyone knows everything; there is nothing to maintain.

Where it breaks

The day you hire consultant number three. New joiners don’t know the history, protection periods aren’t written down anywhere, and “I thought they stopped being a client last year” is an honest mistake nobody can check.

Cost: Free, until it isn’t.

Shared spreadsheet

A Google Sheet or Excel file listing protected companies.

How it works

Someone owns a sheet with company names, sometimes a reason and an end date. Consultants are told to check it before approaching anyone.

Where it’s enough

Cheap, familiar, and it exists. For a small team where one person keeps it current and everyone sources slowly enough to cross-check, it does the job most of the time.

Where it breaks

The check is manual and happens in a different window from the sourcing. At volume, or under deadline, people stop looking. Subsidiaries and rebrands don’t match the name in the sheet. And “most of the time” is the problem: one missed check is one client conversation you don’t want to have.

Cost: Free. Real cost is the one approach a year it doesn’t catch.

ATS / CRM tags

Companies flagged as off-limits inside Bullhorn, Vincere, JobAdder or similar.

How it works

Client records carry a “do not approach” flag or status. Candidates linked to those companies inherit a warning inside the ATS.

Where it’s enough

Good when your consultants source from inside the ATS: the warning is in the same tool as the work, and it ties to the real client record, so protection periods can live on the contract.

Where it breaks

Most sourcing doesn’t happen in the ATS. It happens on LinkedIn, and the candidate usually isn’t in your database yet. A flag on a client record you haven’t opened protects nobody. It also depends on every candidate’s current employer being accurate in the system, which it rarely is.

Cost: Included in the ATS you already pay for.

Bycatch

A Chrome extension that flags protected candidates on their LinkedIn profile.

How it works

The team shares one list of off-limits companies. Anyone who works for one of them gets a visible warning on their LinkedIn and LinkedIn Recruiter profile, before a message is sent.

Where it’s enough

The check happens automatically, in the place sourcing happens, at the moment it matters. New consultants inherit the list on day one. Nothing about the candidate leaves the browser.

Where it breaks

It only covers LinkedIn in Chrome. It doesn’t read email, phone or other job boards, and it warns rather than blocks, so a consultant who chooses to ignore it can. It also depends on the candidate’s LinkedIn profile being up to date, which is usually but not always the case.

Cost: From £30 a month per team (not per seat).

Side by side

MemoryShared spreadsheetATS / CRM tagsBycatch
Where the check happensIn someone’s headIn a separate windowInside the ATSOn the LinkedIn profile
Who has to rememberEvery consultantEvery consultantWhoever opens the recordNobody
Covers candidates not yet in your databaseSometimesOnly if checkedNoYes
New joiner is protected on day oneNoOnly if sent the sheetYes, inside the ATSYes
Handles subsidiaries and rebrandsIf someone knowsOnly if listedIf linked in the ATSCompany-level match on LinkedIn
Protection periodsUnwrittenA column, if keptOn the client recordOn the shared list
Covers email, phone, other boardsOnly if checkedOnly inside the ATSNo
CostFreeFreePart of the ATSFrom £30/month per team

Which one do you actually need?

  • One or two people, a handful of clients: memory or a spreadsheet is fine. Write the protection end dates down and move on.
  • A team that sources mostly from the ATS: use the ATS flags properly and keep the contract terms on the client record. Add a LinkedIn layer only if approaches are going out from LinkedIn too.
  • A team that sources on LinkedIn, with people joining and leaving: this is where spreadsheets fail and where Bycatch earns its keep. The list has to be in the window the consultant is looking at, for every consultant, without anyone remembering to check.
  • If a client has ever noticed an approach: whatever you were using was the method that let it through. Change the method, not just the reminder.

FAQ

Questions teams ask when comparing

Straight answers, including the limits of our own product.

Is a spreadsheet good enough for an off-limits list?

For a small team that sources slowly and has one person who keeps the sheet current, often yes. It stops being enough when the check is skipped under pressure, when a new joiner hasn’t been sent it, or when the candidate’s employer is a subsidiary that isn’t listed. If you have ever had a client notice an approach, the spreadsheet was the system that let it through.

Can’t we just do this in our ATS?

If your consultants source from inside the ATS, an off-limits flag on the client record works well. The gap is LinkedIn: most first approaches go to people who aren’t in your database yet, and the ATS can’t warn you about a record you haven’t created. Many teams run both: the ATS holds the contract terms and Bycatch shows the flag on LinkedIn.

Does any of these methods prove we didn’t approach someone?

No. None of them, including Bycatch, can prove a negative: approaches can happen by email, phone or from a personal account. What a good system does is prevent the accidental approach, which is nearly all of them, and let you show a client that every consultant has the current list in front of them when they source.

What should a protection period be?

That is set by your terms of business with each client, not by the tool. Twelve to twenty-four months after the last placement is common in agency recruitment, longer in retained executive search. Whichever method you use, write the end date down; an undated list is a list nobody trusts.

See the flag on a real profile

Install Bycatch, mark one client as off-limits, and open one of their employees on LinkedIn. Free for a month.

  • Free for first month
  • No credit card required
  • Set up in under 2 minutes