# Kit Documentation

> Kit is a modern hiring platform. This document lists all available documentation pages.

## Getting Started

- [Introduction](https://www.startupkit.app/docs/introduction.md): Learn what Kit is and how it can help you manage your hiring process.
- [Quick Start](https://www.startupkit.app/docs/quick-start.md): Go from zero to accepting applications in under 10 minutes — create an account, post a job, brand your career portal, and invite your team.

## Managing Jobs

- [Creating a Job Posting](https://www.startupkit.app/docs/creating-a-job-posting.md): How to create, configure, publish, and manage job postings — from draft to close and everything in between.
- [Managing Your Pipeline](https://www.startupkit.app/docs/managing-your-pipeline.md): How candidates flow through stages, how to advance or reject them, how auto-advancement works, and what happens when a review needs a decision.
- [Candidate Payouts](https://www.startupkit.app/docs/candidate-payouts.md): How to configure stage-level compensation, manage payout requests, and process payments for candidates.
- [Candidate Data Fields](https://www.startupkit.app/docs/candidate-data-fields.md): How to define custom data fields on job postings to capture structured candidate information with optional AI extraction and privacy controls.
- [AI Extraction for Candidate Data](https://www.startupkit.app/docs/ai-extraction.md): How AI automatically extracts candidate data field values from resumes, form responses, and questionnaire answers.
- [AI Agent and MCP Tools](https://www.startupkit.app/docs/hiring-ai-agent-mcp.md): Run your pipeline from Kit's in-app AI assistant or any external MCP client — triage applications, work your review queue, move candidates, and draft candidate replies.
- [Creating a Job Posting with AI](https://www.startupkit.app/docs/creating-a-job-posting-with-ai.md): Have Claude — or any AI assistant — draft the posting, the salary band, and the hiring stages. You publish it.

## Career Portal

- [Setting Up Your Career Portal](https://www.startupkit.app/docs/setting-up-your-career-portal.md): How to configure, brand, and launch your public career page — including custom domains, logos, and embed options.
- [The Candidate Experience](https://www.startupkit.app/docs/the-candidate-experience.md): What candidates see when they apply — from the public job page through the candidate portal and stage submissions.
- [Embedding Your Career Portal](https://www.startupkit.app/docs/embedding-your-career-portal.md): How to embed your career portal on your company website using an iframe, including customization options and API access.
- [Multi-Language Support](https://www.startupkit.app/docs/multi-language-support.md): How to enable multiple languages on your career portal so candidates can browse in their preferred language.
- [Google Jobs and SEO](https://www.startupkit.app/docs/google-jobs-and-seo.md): How Kit gets your job postings into Google Jobs and search results automatically — structured data, sitemaps, and real-time indexing.
- [Public Jobs API](https://www.startupkit.app/docs/public-jobs-api.md): Build your own job site (e.g. with Next.js on Vercel) on top of your Kit hiring pipeline. List published roles and receive applications through a public REST API, an official TypeScript SDK, and a one-click Next.js template.

## Working with Candidates

- [Candidate Profiles](https://www.startupkit.app/docs/candidate-profiles.md): How to view, search, and manage candidate information across all their applications.
- [Reviewing Applications](https://www.startupkit.app/docs/reviewing-applications.md): How to screen incoming applications, review candidate submissions, and take action on applications.
- [Managing Offers](https://www.startupkit.app/docs/managing-offers.md): Extend, revise, and track offers through the full lifecycle — from draft to candidate response to final decision.
- [Resume Extraction & Search](https://www.startupkit.app/docs/resume-extraction.md): How Kit automatically extracts and indexes resume data for smarter candidate search
- [Talent Pool](https://www.startupkit.app/docs/talent-pool.md): How to build and search a pool of interested candidates before you have open roles.
- [Importing CVs in Bulk](https://www.startupkit.app/docs/bulk-cv-import.md): Drag many PDFs into a live job posting or your talent pool, review what the AI parsed, merge duplicates, and record where the CVs came from — before anything is saved.
- [Sharing a Candidate CV](https://www.startupkit.app/docs/sharing-a-candidate-cv.md): Share a candidate's resume outside Kit through an expiring, email-verified link — so every download is attributable, and you can limit downloads to approved company domains.
- [Seen By on Applications](https://www.startupkit.app/docs/seen-by-on-applications.md): See which teammates opened an application — and optionally let the candidate know their application was opened, with a date and nothing more.
- [Recommended Credentials](https://www.startupkit.app/docs/recommended-credentials.md): Flag a credential you value on a job posting — candidates get one optional email with free courses and can share evidence they already hold it. Kit never scores, ranks, or filters on it.
- [Asking Candidates to Clarify](https://www.startupkit.app/docs/clarify-candidate-insights.md): Ask a candidate to confirm or correct specific AI-extracted insight fields in one email, and write their own answer back into the field with candidate provenance.

## Team Collaboration

- [Inviting Your Team](https://www.startupkit.app/docs/inviting-your-team.md): How to invite team members, pick a role at invite time, and control access to job postings.
- [Reviews and Feedback](https://www.startupkit.app/docs/reviews-and-feedback.md): How team reviews work — blind voting, scoring criteria, automatic advancement, and resolving split decisions.
- [Slack Permission Levels](https://www.startupkit.app/docs/slack-permission-levels.md): Choose how much access Kit's Slack integration gets — from notifications-only posting to full candidate channel collaboration.
- [Slack Candidate Channels](https://www.startupkit.app/docs/slack-candidate-channels.md): How Kit automatically creates private Slack channels for each candidate so your team can collaborate in real time.
- [Holiday Mode](https://www.startupkit.app/docs/holiday-mode.md): Pause email notifications while you're away without losing track of what happens. Your team stays informed and candidates keep moving.
- [Share Ideas](https://www.startupkit.app/docs/idea-box.md): Submit improvement ideas and feature requests from anywhere in the app.
- [Personal Slack Notifications](https://www.startupkit.app/docs/personal-slack-notifications.md): How Kit sends you a direct Slack message when something needs your action — and how to pause, resume, or control these DMs.
- [Using @KitBot in Slack](https://www.startupkit.app/docs/using-kitbot-in-slack.md): How to mention Kit's @KitBot assistant in Slack — which channel answers what, and how it routes hiring vs. security questions.
- [Anti-Stall Reminders](https://www.startupkit.app/docs/anti-stall-reminders.md): How Kit nudges whoever owes the next hiring action so candidates never get stuck waiting.
- [Slack Message Language](https://www.startupkit.app/docs/slack-message-language.md): How Kit picks the language of a Slack message — one language your account chooses for shared channels, each person's own language for direct messages.
- [Team Access Control](https://www.startupkit.app/docs/team-access-control.md): Give each team member the right level of access to Hiring, Security, Outreach, Training, and Performance — and audit or revoke it when they leave.
- [Team Roles](https://www.startupkit.app/docs/team-roles.md): Set up a new team member in one click — pick a predefined role like Recruiter, Security Analyst, or Billing Admin, then fine-tune their access if needed.
- [Item-Level Access](https://www.startupkit.app/docs/per-item-access-grants.md): Restrict a single security report or outreach campaign to a handpicked few — then grant teammates a Member (view) or Lead (manage) role on just that item.
- [Your Daily Digest](https://www.startupkit.app/docs/daily-digest.md): One email each morning with everything waiting on you across hiring, security reports, and outreach — and the rules that keep it quiet when there's nothing to say.

## Scheduling & Interviews

- [Scheduling Overview](https://www.startupkit.app/docs/scheduling-overview.md): Built-in interview scheduling with personal availability, calendar integration, and team coordination — no external booking tool required.
- [Managing Your Availability](https://www.startupkit.app/docs/managing-your-availability.md): Define your interview availability with weekly hours, date overrides, meeting limits, buffers, and scheduling windows.
- [Calendar Integration](https://www.startupkit.app/docs/calendar-integration.md): Connect Google Calendar to prevent double-booking, detect scheduling conflicts automatically, and optionally put booked interviews straight onto the lead interviewer's calendar.
- [Interview Scheduling](https://www.startupkit.app/docs/interview-scheduling.md): Configure interview stages, assign interviewers, manage bookings, and handle cancellations and reschedules.
- [Calendar Feeds (ICS)](https://www.startupkit.app/docs/calendar-feeds.md): Subscribe to any calendar via ICS link without granting OAuth access. Works with Google Calendar, Outlook, Apple Calendar, and more.
- [Proactive Process Notifications](https://www.startupkit.app/docs/proactive-process-notifications.md): Kit automatically detects scheduling problems and notifies your team before candidates are impacted, then re-notifies candidates when issues are resolved.
- [Calendly External Scheduling](https://www.startupkit.app/docs/calendly-external-scheduling.md): Let candidates self-schedule live interviews on your Calendly event types — an optional, per-stage alternative to Kit's built-in scheduling.

## Hiring Guides

- [Writing Effective Job Descriptions](https://www.startupkit.app/docs/writing-effective-job-descriptions.md): A practical guide to writing job descriptions that attract qualified, diverse candidates.
- [Process Template Configuration](https://www.startupkit.app/docs/process-template-configuration.md): Complete reference for configuring hiring process templates with YAML — stage types, config options, reviewers, and examples.
- [Building Ideal Candidate Profiles](https://www.startupkit.app/docs/building-ideal-candidate-profiles.md): How to define who succeeds in a role before you start interviewing — using outcomes, competencies, and scorecards to hire fairly and consistently.

## Compensation Research

- [Compensation Research Overview](https://www.startupkit.app/docs/compensation-research-overview.md): What Compensation Research is, who it's for, and what's included.
- [Setting Up Compensation Research](https://www.startupkit.app/docs/compensation-research-setup.md): Activate Compensation Research and configure which roles and regions to track.
- [Dashboard & Analytics](https://www.startupkit.app/docs/compensation-research-dashboard.md): Understand the Compensation Research dashboard — filters, charts, role drill-downs, multi-currency, and board requests.
- [AI-Powered Compensation Insights](https://www.startupkit.app/docs/compensation-research-ai-insights.md): Use natural language to query salary benchmarks, compare roles, and explore market trends with Kit's AI assistant.

## Integrations

- [Connecting AI Assistants](https://www.startupkit.app/docs/connecting-ai-assistants.md): Connect Claude Desktop, Claude Code, Codex CLI, OpenCode, or any other MCP client to manage your hiring workflows with AI.
- [MCP Tools Reference](https://www.startupkit.app/docs/mcp-tools-reference.md): Complete reference for all MCP tools available to AI assistants — parameters, return data, and required permissions.
- [Webhooks Overview](https://www.startupkit.app/docs/webhooks-overview.md): Send real-time notifications to external systems when hiring events happen.
- [Webhook Events Reference](https://www.startupkit.app/docs/webhook-events-reference.md): Payload shapes, headers, and field definitions for every webhook event.
- [Webhook Security & Delivery](https://www.startupkit.app/docs/webhook-security-and-delivery.md): Verify webhook signatures, understand retry behavior, and troubleshoot delivery issues.
- [API Reference](https://www.startupkit.app/docs/api-reference.md): Authenticate and query the Hiring API for job postings, candidates, and applications.
- [Knowledge Base](https://www.startupkit.app/docs/knowledge-base.md): How to create knowledge entries that give Kit's outreach AI agent company context for better prospect research and email drafting.
- [GitHub Template Repository Setup](https://www.startupkit.app/docs/github-template-repository-setup.md): How to configure a GitHub template repository for code assignment stages, and how reviewers get access to candidate repositories.
- [Startupkit Email](https://www.startupkit.app/docs/startupkit-email.md): Receive inbound emails on your own domain using Startupkit's managed mail service. Add a domain, point an MX record, and you're done.
- [Posting Jobs to OLX.pl](https://www.startupkit.app/docs/olx-job-distribution.md): Connect OLX.pl once, then post any opening to Poland's largest marketplace with an AI-assisted review — kept in sync as the job changes.

## Account & Compliance

- [Exporting Your Account Data](https://www.startupkit.app/docs/data-export.md): How to request, download, and understand a full export of your account data for compliance or portability — including a complete breakdown of VDP/CSIRT data categories.
- [Custom Domains](https://www.startupkit.app/docs/custom-domains.md): Replace your default Kit URLs with your own branded domain for your admin dashboard, career portal, or security portal.
- [Candidate Privacy & Consent](https://www.startupkit.app/docs/candidate-privacy-and-consent.md): How Kit handles candidate data consent on job application and talent pool forms, and how to customize the consent language for your organization.
- [Billing & Add-ons](https://www.startupkit.app/docs/billing-and-addons.md): How to manage your Kit subscription and enable add-on features like VDP, Compensation Research, and Outreach.
- [Email & Notification Preferences](https://www.startupkit.app/docs/email-preferences.md): How Kit notifies you across in-app, email, and Slack — and how to control what you receive.
- [Breach Monitoring](https://www.startupkit.app/docs/breach-monitoring.md): Kit checks your team's login emails — and extra addresses you choose to monitor — against the Have I Been Pwned breach database every day and alerts you when one turns up in a recent leak.
- [SSO & Directory Provisioning](https://www.startupkit.app/docs/single-sign-on-and-provisioning.md): Set up SAML single sign-on and automatic user provisioning/deprovisioning from Google Workspace so your team's access stays in lockstep with your directory.
- [Sign-in Security](https://www.startupkit.app/docs/sign-in-security.md): Review your recent sign-ins, spot the ones you don't recognize, and manage the trusted browsers that skip two-factor authentication.
- [Passkeys](https://www.startupkit.app/docs/passkeys.md): Add a passkey to your Kit account, understand what happens when an account requires one, and recover if you lose the device you set it up on.
- [Requiring Passkeys](https://www.startupkit.app/docs/requiring-passkeys.md): Require every member to hold a passkey before they can open your account — who's exempt, what members see, and how to recover someone who lost theirs.

## Vulnerability Disclosure

- [Vulnerability Disclosure Overview](https://www.startupkit.app/docs/vulnerability-disclosure-overview.md): What Kit's VDP module is, who it's for, and what's included.
- [Configuring Your Program](https://www.startupkit.app/docs/configuring-your-program.md): Step-by-step guide to all seven program settings tabs — scope, bounty matrix, SLAs, triage, payouts, spam, and security.txt.
- [Triaging Reports](https://www.startupkit.app/docs/triaging-reports.md): How to use the Kanban triage board, read SLA indicators, assess severity, and resolve or dismiss reports.
- [Communicating with Researchers](https://www.startupkit.app/docs/communicating-with-researchers.md): How to use message threads, use reply templates in the composer, configure Slack notifications, and handle escalations.
- [The Researcher Portal](https://www.startupkit.app/docs/the-researcher-portal.md): How researchers submit reports, track status, appeal decisions, and set up payout info through the secure portal.
- [Bounties and Payouts](https://www.startupkit.app/docs/bounties-and-payouts.md): How to approve bounties, manage the disbursement pipeline, read and re-queue a failed payout, handle tax documents, and use the immutable financial ledger for SOC 2 evidence.
- [security.txt Setup](https://www.startupkit.app/docs/security-txt-setup.md): How to configure, preview, and serve your RFC 9116-compliant security.txt file — the primary discovery mechanism for ethical hackers.
- [AI Integration](https://www.startupkit.app/docs/ai-integration-vdp.md): How to use the built-in AI assistant and external MCP tools to automate VDP triage, severity assessment, and researcher communication.
- [Metrics and Exports](https://www.startupkit.app/docs/metrics-and-exports.md): How to read your VDP metrics dashboard, manage researcher karma, publish the Hall of Fame, and generate SOC 2 evidence exports.
- [On-Call Rotation](https://www.startupkit.app/docs/on-call-rotation.md): How to set up on-call shifts and scheduled rotation so there is always someone responsible for triaging vulnerability reports.
- [PagerDuty Integration](https://www.startupkit.app/docs/pagerduty-integration.md): Connect PagerDuty to receive VDP alerts, sync on-call schedules, and track incident status in Kit.
- [Vanta Integration](https://www.startupkit.app/docs/vanta-integration.md): Connect Vanta to turn your triaged VDP vulnerabilities into live SOC 2 and ISO 27001 compliance evidence automatically.
- [PDF Sanitizer](https://www.startupkit.app/docs/pdf-sanitizer.md): Upload an untrusted PDF and get back a flattened, image-based copy that is safe to open — JavaScript, embedded files, and actions stripped.
- [Set up a VDP with an AI agent](https://www.startupkit.app/docs/set-up-vdp-with-ai-agent.md): Go from zero to a live vulnerability disclosure program by chatting with an AI agent — create, configure, and activate the VDP through MCP tools, with human confirmation on the steps that matter.
- [Sharing Reports With Peers](https://www.startupkit.app/docs/sharing-reports-with-peers.md): Share a single vulnerability report with an engineer outside your team via a secure, email-gated, expiring link — without exposing the researcher, bounty, or internal notes.
- [Code-Aware AI Triage](https://www.startupkit.app/docs/code-aware-ai-triage.md): Run your own AI security agent over every incoming VDP report and your own codebase — in your CI, on your model, fully airgapped — to produce pre-engineer triage context. Advisory only; Kit never auto-acts.
- [Set up the airgapped triage agent](https://www.startupkit.app/docs/set-up-triage-agent.md): Connect your forked VDP triage repo to Kit through a guided stepper — fork the example repo, wire the pipeline trigger, and verify with a real round-trip.
- [How the airgap works](https://www.startupkit.app/docs/triage-agent-airgap.md): The security model behind Code-Aware AI Triage — why the network boundary lives outside the agent, how to airgap a GitLab runner, and why an attacker-submitted report still can't exfiltrate your code.
- [Customizing the triage prompt and model](https://www.startupkit.app/docs/customizing-triage-agent.md): Point the VDP triage agent at your own model (DeepSeek, local vLLM, Anthropic, OpenRouter), tune the security-research prompt with prompt-injection hygiene, and shape the output schema — all in your forked repo.
- [Postmortems and Root-Cause Analysis](https://www.startupkit.app/docs/postmortems-and-rca.md): Attach a private, structured root-cause analysis to any resolved report — your internal audit record, downloadable as a per-report PDF dossier.
- [Routing Reports to Teams](https://www.startupkit.app/docs/routing-reports-to-teams.md): Build a component catalog of product areas so incoming vulnerability reports are suggested to — and claimed by — the team that owns them.
- [Triaging Your VDP Queue with Claude](https://www.startupkit.app/docs/ai-native-vdp-triage.md): Connect Claude to Kit's MCP server and work the vulnerability-disclosure queue with ready-made prompts that orchestrate scope, severity, duplicate, bounty, and postmortem workflows.
- [IP Investigation](https://www.startupkit.app/docs/ip-investigation.md): Look up any IP address and get an at-a-glance profile — classification, ownership/abuse contact, routing/ASN, reverse DNS, host exposure, cloud attribution, reputation, and malware/C2 threat intel — pulled live from public sources.
- [Email Checker](https://www.startupkit.app/docs/email-checker.md): Screen any email address to decide whether it's disposable or temporary — a throwaway inbox like mailinator or 10minutemail — combining a daily-refreshed blocklist with a mail-server fingerprint, before you trust a signup or a report.
- [Seen By on Reports](https://www.startupkit.app/docs/seen-by-on-reports.md): See which teammates have viewed a report — a live avatar row on every report, with an account-wide toggle in program settings.
- [Stalled Report Nudges](https://www.startupkit.app/docs/stalled-report-nudges.md): How Kit reminds the owner of a vulnerability report that has gone quiet, and escalates to your program admins if it stays quiet.
- [Jira Integration](https://www.startupkit.app/docs/jira-integration.md): Push validated vulnerability reports to Jira as engineering tickets without moving exploit details out of Kit.
- [Submission Limits and Spam Blocks](https://www.startupkit.app/docs/submission-limits-and-spam-blocks.md): Every reason Kit can turn a vulnerability report away — bot checks, per-IP throttling, burst blocks, invite-only portals, and the monthly report limit — plus how to read a spam record and release someone who was caught by mistake.
- [Linear Integration](https://www.startupkit.app/docs/linear-integration.md): Push validated vulnerability reports to Linear as issues, and read remediation status back, without moving exploit details out of Kit.
- [Slack Report Threads](https://www.startupkit.app/docs/slack-report-threads.md): How one vulnerability report maps to one Slack card and one thread — what the card shows, what posts a reply, which channel it lands in, and why restricted reports never appear.
- [Bounty Proposals and Team Voting](https://www.startupkit.app/docs/bounty-proposals.md): Put an amount on the table before it becomes money — how proposals, blind or live voting, counter-amounts and amendments work, and why the researcher never sees any of it.
- [Takedown Notices](https://www.startupkit.app/docs/takedown-notices.md): Receive and act on third-party abuse reports — phishing and brand-impersonation complaints from CERT teams and abuse desks — alongside your vulnerability disclosure program.
- [The Low Signal Marker](https://www.startupkit.app/docs/low-signal-researchers.md): A staff-only hint next to reports from researchers whose submissions to your program are usually rejected — how the acceptance ratio is measured, and why it isn't karma.

## Outreach

- [Outreach Overview](https://www.startupkit.app/docs/outreach-overview.md): What Kit's Outreach module is, how AI-powered cold email works, and what's included in the addon.
- [Setting Up Email Delivery](https://www.startupkit.app/docs/outreach-email-delivery.md): Configure SMTP and IMAP for sending outreach emails and detecting prospect replies.
- [Creating Campaigns](https://www.startupkit.app/docs/outreach-campaigns.md): Create campaigns from templates or scratch, configure sequences and AI directives, and manage the campaign lifecycle.
- [Adding and Managing Prospects](https://www.startupkit.app/docs/outreach-prospects.md): Add prospects manually, import CSV, or paste a URL for AI enrichment — with duplicate detection and status tracking.
- [AI Research and Knowledge Base](https://www.startupkit.app/docs/outreach-ai-research.md): How Kit's AI agent researches prospects, the knowledge base for product context, and confidence scoring.
- [Reviewing and Sending Messages](https://www.startupkit.app/docs/outreach-messages.md): Review AI-drafted emails, approve or reject drafts, and understand the sending pipeline with daily caps and suppression checks.
- [Handling Replies](https://www.startupkit.app/docs/outreach-replies.md): How Kit detects prospect replies, classifies sentiment, and helps you respond — including AI-drafted responses.
- [Suppressions, Bounces, and Deliverability](https://www.startupkit.app/docs/outreach-deliverability.md): Manage your suppression list, understand bounce handling, and protect your sender reputation.
- [Engagement Tracking](https://www.startupkit.app/docs/outreach-engagement-tracking.md): Track email opens and link clicks to measure campaign performance, with optional custom tracking domains.
- [Notifications & Alerts](https://www.startupkit.app/docs/outreach-notifications.md): How Kit notifies your team about outreach events — email alerts, Slack integration, and notification preferences.
- [Remote MCP Servers in Campaigns](https://www.startupkit.app/docs/remote-mcp-servers-in-campaigns.md): Connect your own MCP servers to give the outreach AI agent access to live tools — CRMs, internal docs, analytics, anything that speaks Model Context Protocol.
- [Outreach Agent](https://www.startupkit.app/docs/outreach-ai-agent.md): Use the conversational AI agent on any outreach page to check metrics, diagnose campaigns, approve drafts, and surface silver medalist matches.
- [Inbox Drafts](https://www.startupkit.app/docs/outreach-inbox-drafts.md): Push AI-generated outreach drafts to your email client's Drafts folder. Review, edit, and send from Gmail, Outlook, or any IMAP client.
- [Prospect Memory for AI Agents](https://www.startupkit.app/docs/outreach-agent-memory.md): Durable per-company research memory that external AI agents recall before researching and write back to afterwards, shared across every campaign in your account.

## Security Training

- [Security Training Overview](https://www.startupkit.app/docs/security-training-overview.md): What Kit's Training module is, who authors it, and how a security-awareness program is built.
- [Training Template Library](https://www.startupkit.app/docs/training-template-library.md): Browse Kit's shared library of ready-made decks — SOC 2, GDPR, ISO 27001, HIPAA, plus two evidence checklists — and seed a complete program from one.
- [Build from the Smart Template](https://www.startupkit.app/docs/training-smart-template.md): Seed a complete 12-slide security-awareness deck, 7-question quiz, and attestation by answering a few company questions.
- [Editing Slides](https://www.startupkit.app/docs/training-editing-slides.md): Add, edit, reorder, and delete training slides, and use company variables in the rich-text callout.
- [Knowledge Check, Attestation & Publishing](https://www.startupkit.app/docs/training-quiz-and-attestation.md): Configure the knowledge-check quiz and sign-off attestation, then publish or pause the program.
- [Reminders & Deadlines](https://www.startupkit.app/docs/training-reminders-and-deadlines.md): How Kit automatically nudges participants who haven't finished their training, and how those reminder emails are paced and personalized.
- [Evidence Checklists](https://www.startupkit.app/docs/training-evidence-checklists.md): Collect SOC 2 evidence from the people your MDM cannot reach — contractors and BYOD staff configure their own machines, attest to it, and upload a screenshot you can hand an auditor.

## Performance Reviews

- [Performance Reviews Overview](https://www.startupkit.app/docs/performance-reviews-overview.md): What Kit's Performance module is, the SOC 2 CC1.4/CC1.5 evidence wedge, and what's included.
- [Review Cycles](https://www.startupkit.app/docs/performance-review-cycles.md): Create a cycle, set cadence, add participants with default reviewers, and move it through the draft → active → finalized → archived lifecycle.
- [Templates and Questions](https://www.startupkit.app/docs/performance-templates-and-questions.md): Build versioned review templates with rating scales and competency questions, and understand how the question set is frozen at cycle activation.
- [Writing Reviews](https://www.startupkit.app/docs/performance-writing-reviews.md): Fill a structured review as manager, peer, or self-reviewer — ratings, questions, narrative — then save drafts, submit, or retract while the cycle is active.
- [Goals and Check-ins](https://www.startupkit.app/docs/performance-goals-and-checkins.md): Set personal goals, record lightweight progress check-ins, and build the evidence trail that feeds your next review.
- [AI-Drafted Reviews](https://www.startupkit.app/docs/performance-ai-drafted-reviews.md): Evidence-gathered AI drafts from goals, prior reviews, and work signals — with a hard human-accountability gate so the AI never submits.
- [SOC 2 Evidence and Exports](https://www.startupkit.app/docs/performance-soc2-evidence-exports.md): The evaluation register, immutable append-only evidence records, integrity verification, and Vanta-shaped CSV/PDF exports for CC1.4 and CC1.5.
- [Work Signal Sources](https://www.startupkit.app/docs/performance-work-signal-sources.md): Connect GitLab so AI review drafts cite real shipped work — fetch-on-demand, privacy-scoped, opt-in per draft, never a surveillance warehouse.
- [AI Agent and MCP Tools](https://www.startupkit.app/docs/performance-ai-agent-mcp.md): Drive review cycles from Kit's in-app AI assistant or any external MCP client — list cycles, submit your reviews, and pull the SOC 2 register conversationally.
