Quick Start
Set up your team, choose a product workflow, test it, and go live.
1. Set Up the Team Boundary
Complete your name and time zone, then invite the people who will operate the workflow. Time zones affect scheduling; product access affects what each person can see and change.
Choose a role preset, then review its module levels. Admin controls the account. Product admins control one module. Most operators need access to one or two modules, not the whole account. See Team Roles and Per-Item Access Grants.
2. Pick One First Workflow
Do not configure every product at once. Pick the outcome you need now and complete its smallest useful loop.
| Product | First useful loop | Setup guide |
|---|---|---|
| Hiring | Create a draft role, review its stages, publish it, and submit one test application | Creating a Job Posting |
| Vulnerability Disclosure | Define scope and contact details, activate the program, and submit one internal test report | Configuring Your Program |
| Training | Build or edit a program, preview it, publish it, and invite an internal participant | Security Training Overview |
| Performance | Publish a template, create a cycle, add participants, and verify reviewer assignments before activation | Review Cycles |
| Outreach | Connect sending and reply detection, create a draft campaign, add one internal prospect, and review the draft without sending it externally | Setting Up Email Delivery |
| Compensation Research | Choose roles and regions, then check the sample behind a benchmark before using it | Setting Up Compensation Research |
If a product is not visible, ask an account admin to check your module access and, where applicable, the account’s add-ons.
3. Connect Only What the Workflow Needs
Open Integrations after choosing the workflow and add the dependencies it needs before the end-to-end test.
| Need | Typical integration |
|---|---|
| Interview conflict checking, meeting links, and external scheduling | Google Calendar checks busy times, Google Meet creates links for Kit-scheduled interviews, and Calendly handles external self-scheduling. Calendar feeds only preview cached busy windows today; they do not remove candidate booking slots or create meeting links. |
| Team notifications and collaboration | Slack |
| Code assignments | GitHub |
| Inbound replies or security reports | Startupkit Email or another supported inbound-email setup |
| Calls or text messages | Twilio |
| Training or candidate video | Mux |
| AI features billed to your provider account | Google AI, Anthropic, or OpenRouter |
| External automation | MCP, API tokens, or webhooks |
The Integrations Overview explains ownership and safe rollout. Integration availability can depend on your role and enabled products.
4. Test the Recipient Experience
Use internal addresses and non-sensitive test data first.
- Open the candidate, researcher, or training-participant experience in a separate browser session.
- Verify the sender identity, links, deadlines, time zone, and reply path.
- Confirm that a teammate without access cannot open the protected staff record.
- For AI output, inspect the source material and edit the result before approving or sending it.
- For webhooks or exports, inspect one real payload or file before relying on downstream automation.
5. Go Live With an Owner
Before publishing, activating, inviting, or sending:
- Name the person who owns the queue and the backup who covers absences.
- Decide which notifications matter and where they should arrive.
- Record any deadline, service level, reminder cadence, or approval rule the team is promising.
- Know which report or export you will use to check that the workflow completed.
Product Checklists
Hiring
- Publish one tested job posting
- Check the career portal and application form
- Assign stage reviewers and scheduling availability
- Decide how candidate email and reference checks will be handled
Vulnerability Disclosure
- Define in-scope and out-of-scope systems
- Set the program email identity and response ownership
- Test report intake and the researcher portal
- Review SLA, bounty, spam, and disclosure settings before activation
Training
- Review every slide or checkpoint and the attestation
- Preview the participant flow
- Invite an internal participant first
- Check the completion register and export you plan to retain
Performance
- Publish the exact question set before activation
- Confirm participants, managers, peers, and due dates
- Explain how AI drafts and optional work signals are reviewed
- Finalize only after the completion register is correct
Outreach
- Verify SMTP and reply detection
- Review suppression and tracking settings
- Inspect research sources and approve the first message yourself
- Test the reply and meeting-booking path with an internal address
Compensation Research
- Select the roles, regions, currency, and workplace filters you need
- Check listing count and distribution, not only a headline number
- Export the filtered evidence when a decision needs an audit trail
Next Step
Return to the Introduction for the guide map, or open the relevant product section in the documentation sidebar.