Policy

What You Hand Over When a Bot Applies From Your Account

Giving a job-application bot your passwords is not safe by default, and the risk is documentable rather than speculative. LinkedIn's User Agreement prohibits bots and unauthorized automated access outright, other boards carry their own terms worth the same check, and the account at stake is the profile recruiters search from. A mailbox credential grants access to everything in the inbox, not just recruiting mail. And whatever a bot submits under your name is your representation to an employer, no matter who clicked send.

The takeNo vendor selling submissions is going to volunteer the clause that bans the thing it sells. That's an ordinary incentive, not a conspiracy, and it means the burden of reading the actual terms sits with the applicant, at the exact screen built to move fastest. Ten minutes with a terms page before granting access is the cheapest insurance available in this category, and almost nobody spends it.

Where Olive fits

Open a role and see what the work shows

Olive produces no automated decision and no composite score at all: a person writes each of six findings about how a candidate worked with AI, each carries the evidence it rests on, and the candidate is granted the identical report the employer reads, free, on every tier.

Rank your shortlist

What a Credential Actually Grants

A mailbox credential grants read access to an entire inbox, not just the messages a recruiting tool needs. A job-board login grants control of the profile employers and recruiters already search, the same profile a resume represents you with elsewhere. Both are broader grants than the narrow task, submitting applications, they're being asked for.

  • Mailbox password: everything in the inbox, not just job-related mail
  • Job-board login: the profile recruiters search, and its account history
  • Either one: whatever the tool's own security turns out to be, now yours to trust

None of that means the access will be misused. It means the access exceeds the task, and a tool asking for more than it needs is worth a second look before the first click of a signup flow, not after.

A useful habit is asking what a browser extension or a resume builder would need for the same task, then comparing. Most of them ask for far less, because most of them were never designed to act as you on someone else's platform, only to help you prepare something you send yourself.

Read the Terms Before You Say Yes

Read the specific clause before you sign up, not the marketing page above it. LinkedIn's User Agreement, effective November 2025, directly prohibits members from using bots or unauthorized automated methods to access the service, and from developing or using software that scrapes it or bypasses its use limits 1. That prohibition sits inside the terms every profile owner already accepted.

What the agreement puts at stake for tripping it is action against the account, and the account is the exact profile recruiters already search. Losing that profile would be a real cost even when nothing else about the tool goes wrong, and it's the cost that gets left out of a signup page that only talks about how many applications it can send. Other boards' terms are separate documents this article didn't open; the habit of reading the clause generalizes even though LinkedIn's clause doesn't.

A tool that submits through a job board's own application path is a different thing from one that logs in as you to do it. The first uses a door the board built for automated submission. The second impersonates you on infrastructure whose terms were written against exactly that, and "the tool did it, not me" is not a distinction the terms recognize.

What an Application Submitted in Your Name Means

At least one large employer states the consequence in writing. The UK Civil Service tells candidates that before submitting, they must confirm the information provided is true and accurate, and that applications may be rejected where AI is used inappropriately at any stage 3. That's one employer's specific rule, not a universal one, but the principle behind it generalizes: whatever gets submitted under your name is your representation, whether you typed the final word or a tool did.

Employers weighing whether to let an agent handle parts of an application are told to require the person for anything that carries a signature while allowing the logistics an agent handles, because a signed authorization is the candidate's own representation regardless of who typed it. The same logic runs the other direction. If your name is on the application, you're answerable for what it says, and a bot's authorship doesn't move that answerability anywhere else.

What Happens When a Bot Answers a Screening Question

Eligibility and screening questions are exactly where an application can be ended automatically at the moment it's submitted. Workday's own documentation describes "automatic stage routing," condition rules that advance or decline a candidate the instant they apply, using the answers given on the questionnaire 2. If a bot answers one of those questions on your behalf and gets it wrong, the rule fires without anyone reading the rest of the application.

Greenhouse's own support documentation states plainly that anyone set up to receive notifications about new applications is not notified when an auto-reject rule fires 5. A bot's wrong answer to a screening question can end a candidacy at a company you'd have been genuinely competitive at, and the people who would normally be alerted to a new application are, by the vendor's own description, never alerted to that one.

Later stages that do involve a person raise a related question worth asking before you sign up for anything: what a tool retains once you've used it, and for how long. Consent and retention rules employers are held to for recorded assessments are a reasonable bar to hold an application bot to as well, even where no law requires it of the vendor. Ask directly whether deletion is actually available, and don't take silence on the question as a yes.

Should You Ever Say Yes?

Sometimes, for a narrower task than most tools ask for. In Greenhouse's 2025 survey of more than 2,200 workers and active job seekers, 22 percent of US respondents said they use an AI agent to submit applications on their behalf 4, so declining entirely isn't the only reasonable position here.

Prefer a tool that submits through the board's own application path over one that logs in as you, never hand over a primary email, use a dedicated address if you use one at all, and ask directly what the tool retains and whether it actually deletes anything on request. A tool that can't answer that last question plainly is telling you something, even when the answer it gives is a shrug rather than a no.

None of that removes the risk. It narrows what you're exposed to down to the one thing that was always true regardless of which tool you picked: you own whatever gets sent under your name, and that ownership doesn't transfer to whatever software clicked submit. The account, the inbox, and the representation are still yours to answer for on the other end of a phone call.

Read the evidence

Common questions

What's the actual risk if I share my job-board login with an app?

Two risks stack: the terms you accepted when you made the profile can prohibit automated access outright, as LinkedIn's explicitly do, which puts the account itself at stake, and the tool now has whatever the profile carries, not just the ability to apply. Losing that account costs you the exact profile recruiters search from, which is a real loss even if nothing else goes wrong.

Is it safer to give a bot my email password instead of my job-board login?

No, arguably worse. A mailbox credential grants read access to the entire inbox, not a scoped view of job-related mail. If you use a tool that needs email access at all, a dedicated address used only for the search limits what any single credential exposes.

Can an auto-apply bot get my application rejected without my knowledge?

Yes, if it answers an eligibility or screening question incorrectly. Some large applicant tracking systems can decline a candidate automatically the moment those answers come in, and at least one states explicitly that the people set up to be notified of new applications aren't notified when that happens, so you may never see the rejection coming.

What should I check before signing up for any auto-apply tool?

Whether it submits through the job board's own application path or logs in as you, whether it needs a password or a mailbox at all, and what it retains once you've used it, including whether deletion is actually available on request rather than just promised.

If I've already given a tool my credentials, should I change them now?

Reasonable if you're unsure what the tool actually does with them. Changing the password revokes access cleanly, and you can decide afterward, deliberately, whether to grant a narrower version of it again rather than leaving a standing grant you no longer remember agreeing to.

References

  1. 1. LinkedIn User Agreement LinkedIn, 2025. linkedin.com Supports that a major job-networking platform's terms directly prohibit bots and unauthorized automated access, the clause a candidate accepts by having a profile.
  2. 2. Steps: Automatically Advance or Decline Candidates (Workday Administrator Guide) Workday, Inc., 2024. doc.workday.com Supports that a screening-question answer can decline a candidate automatically the moment an application is submitted, the mechanism a bot's wrong answer would trigger.
  3. 3. A candidate's guide to artificial intelligence (AI) in recruitment UK Civil Service Careers (civil-service-careers.gov.uk), 2025. civil-service-careers.gov.uk Supports that at least one named large employer requires candidates to confirm their application is true and accurate before submission, grounding the representation point.
  4. 4. Greenhouse 2025 workforce and hiring report Greenhouse, 2025. cdn.prod.website-files.com Supports how common using an AI agent to submit applications already is among US job seekers, used to size the decision rather than treat it as fringe.
  5. 5. Auto-reject (Greenhouse Support) Greenhouse Software, Inc., 2026. support.greenhouse.io Supports that an auto-rejected application does not notify the people who'd normally be alerted to a new application, so a bot's wrong answer can go unnoticed.

5 sources, numbered by first appearance. How Olive sources claims

General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.