On April 15, 2026, the Justice Department sentenced Kejia Wang and Zhenxing Wang to 108 and 92 months for running “laptop farms” that placed North Korean IT workers on the payrolls of more than 100 U.S. companies, using the stolen identities of at least 80 U.S. persons and generating over $5 million for the DPRK. Three weeks later Matthew Isaac Knoot and Erick Ntekereze Prince drew 18 months each for the same scheme against nearly 70 more employers; federal agents have now raided close to 30 laptop farms across 16 states. Every one of those companies ran a hiring process. Most ran background checks. What none of them had was a way to show that the person who submitted the application, the person who sat the interviews, and the person who received the laptop were the same human being.
That continuity is what this stack buys. Four layers, only three of them software: Greenhouse Real Talent (or Gem’s Fraud Detection Agent, depending on the ATS you run) scores the application, CLEAR verification binds a government ID and a live face to a named pipeline stage, Metaview records the interview, and Checkr closes the loop post-offer. The fourth layer is a written rubric and a stage rule, and it is what makes the other three defensible.
How the pieces fit
-
Application scoring is the cheapest layer and it determines everything downstream. Greenhouse sells fraud detection inside Real Talent, a four-part suite: fraud detection, CLEAR identity verification, AI talent matching, and a spam blocklist that drops known IPs and domains before applications reach a recruiter. Fraud Detection, built on IPQS, reads phone number, email, location and IP and returns three signal classes — identity-supporting (an established email account), high-risk (a data-center IP), and weak (a timezone that does not match the stated location). It sits in the Security screening tab of the candidate profile. Greenhouse’s own TA team published what this looked like on one machine-learning req: more than 35% of applicants carried high-risk signals, and 91% of the high-risk candidates its security team reviewed were confirmed fraudulent. Among weaker-signal candidates, 26% were confirmed — which is why that bucket is a review queue and not a filter.
-
Identity verification is the only layer that proves a person, and it runs at one stage. Greenhouse partnered with CLEAR — announced June 3, 2025 — to put verification inside MyGreenhouse. CLEAR runs over 60 security signals including government-ID authentication, a selfie check with liveness detection, and device and network metadata. It returns only a pass/fail plus name, email, phone and IP; the identity record itself stays with CLEAR, which matters for the biometric exposure below. Verified candidates are marked CLEAR verified for the stage in which verification was completed, and you can filter the pipeline on that status.
-
The screening interview is now a Greenhouse surface too, and it cuts both ways. Greenhouse closed its acquisition of Ezra AI Labs on May 27, 2026 and sells the result as Voice AI: a two-way conversational screen rather than a one-way recorded answer, with monthly third-party bias audits published by Warden AI. The gain is that every screen leaves a transcript on the candidate record instead of a recruiter’s note. The hole is that a voice screen with no human on the other end is the cheapest stage in the funnel to send a proxy to. Treat it as evidence collection, not as a verification step.
-
The recorder ties the verified identity to the assessed performance — and its price moved. Metaview repositioned from interview intelligence to an agentic recruiting platform, and the published ladder now meters sourced profiles, not recordings: Free ($0, first 100 profiles), Pro $100/user/month (200 profiles/month), Max $300/user/month (unlimited), Enterprise custom. Notetaker is one agent inside that platform, the Reports add-on is a flat fee with no per-report or per-recording charge, and the full agent bundle is quote-only; the old $60/user/month unlimited-calls Notetaker tier is gone from the page. The function still holds — a proxy interviewer, a second voice off-camera, or answers on a two-second delay leave traces in a recording that they never leave in a scorecard — but you now buy it inside a sourcing-priced platform rather than as a line item.
-
Checkr is post-offer and post-hire, not pre-interview. Published pricing, unchanged: Basic $29.99/report with identity verification a $4.99/check add-on, Essential $59.99/report with identity verification and unlimited county criminal search bundled, Complete $94.99/report. Continuous Criminal Search is $1.70 per individual per month. Essential is the default for a remote knowledge-work hire; the continuous check catches what changes after the report clears.
-
The rubric and the stage rule are components, not paperwork. Structured interviewing is what makes a recorded interview comparable evidence rather than eight hours of video. A written stage rule — every candidate on this requisition verifies at the same stage — keeps the identity layer from becoming a disparate-treatment claim.
Named handoffs
- Application submitted → fraud report attached. Automatic on Pro, recruiter-initiated on Plus. Nothing auto-rejects — Greenhouse states outright that fraud signals are not a definitive assessment of authenticity, and a human resolves each one.
- Candidate advances past screen → CLEAR verification requested in MyGreenhouse. The stamp attaches to that stage; recruiters filter on verified status before scheduling onsites.
- Interview starts → Metaview records against the loop’s rubric. Transcript and scorecard land on the record that carries the verification stamp.
- Offer accepted → Checkr Essential runs. Its identity check hits a different data source than CLEAR used, which is the point of running both.
- Hire starts → Continuous Criminal Search runs monthly at $1.70/individual, and the device shipping address is checked against the verified identity record. The DOJ cases turned on that mismatch: the employer shipped a real laptop to a real U.S. address, and someone other than the hire opened it.
The ATS fork — read this before you buy anything
Gem shipped its AI Fraud Detection Agent (announced December 16, 2025, generally available April 21, 2026), powered by Tofu and priced per application with per-job controls. It reads six signal families — resume metadata, LinkedIn profile age and activity, email, phone, cross-source person verification, and IP/device data — and returns high/medium/low risk with a plain-language rationale, at a claimed 90%+ accuracy across all six together.
The constraint that decides the stack is the one Gem’s marketing blurs: most Gem AI agents layer on an existing Greenhouse or Workday instance with no migration, but the fraud agent is the exception. Gem’s product page lists it as available for Gem ATS and sends Greenhouse and Workday shops to sales for what is on the roadmap for their setup. Ask that on the first call rather than reading the agent list and assuming. So the rule is not which agent is better:
- Already on Greenhouse Plus or Pro → Real Talent. Fraud Detection and CLEAR verification both require Plus or Pro. Greenhouse rebuilt its ladder in 2026 — Essential / Core / Advanced / Expert is gone, replaced by Core, Plus and Pro — so a tier name in an old contract does not tell you which side of that line you sit on.
- Already on Gem’s all-in-one ATS → the Fraud Detection Agent, and skip Real Talent entirely.
- On neither, and choosing an ATS anyway → Gem publishes startup pricing at $130/month (annual, 1-10 FTE) and gives companies under 30 employees six months free, the only published entry price in this stack. That is an ATS decision that happens to include fraud screening.
Do not migrate an ATS to get a fraud agent. The screening layer is the cheapest part of this stack and the ATS is the most expensive thing to move.
Cost baseline
For a 200-person company hiring 50 people a year with five recruiters on remote roles, the part you can price from public pages:
- Checkr Essential, 50 reports: ~$3,000/year (Basic plus the $4.99 ID add-on is $34.98 per report if you do not need unlimited county search)
- Continuous Criminal Search across 200 employees: ~$4,080/year
- Metaview, 5 seats: $6,000/year at Pro list, $18,000 at Max — but those rates buy sourcing volume, so treat them as the anchor you negotiate the agent bundle against, not the price of the recorder
Checkr alone is ~$7,000/year, and that is the floor. Above it, two variables dominate and neither is on a pricing page. Greenhouse does not publish tier pricing; Vendr’s marketplace data across 873 purchases puts the median contract at $26,587/year against a $10,137-$74,492 range, with buyers taking an average 16% off the first quote, and the Plus-or-Pro requirement decides where in that range you land. Metaview’s agent bundle is the second. Budget $35-45K/year all-in at that headcount, and price the Greenhouse tier upgrade before anything else here.
Variations and when to swap
- BrightHire instead of Metaview. Zoom closed its BrightHire acquisition in December 2025 and runs it as a standalone brand inside Zoom Workplace. Swap if you interview on Zoom and want the recorder in the meeting layer — and it is now the more predictable buy of the two, since Metaview’s published ladder prices sourcing rather than recording. Do not swap if your loops run on Google Meet.
- Add proctored assessment for engineering roles. HackerRank and CodeSignal address a different failure than this stack does — answer assistance by a real, correctly-identified candidate. HackerRank has stopped trying to block AI use and now scores it, with guarded and unguarded modes per question, and its desktop proctoring app sits on Enterprise rather than the $79/month Starter plan. Add them when the risk is cheating; they do nothing about a stolen identity. See the technical hiring stack.
- Drop the continuous check for contractor-heavy or short-tenure populations where the monthly per-head fee outruns the average engagement.
What this stack does not replace
- It is not an interview-quality stack. Recording for evidence and recording for coaching are different jobs; the interview intelligence stack covers scoring, debriefs, and interviewer calibration.
- It is not an assessment stack. Nothing here measures whether the verified person can do the work.
- It does not decide. Every layer produces signals that a named human resolves. A stack that auto-rejects on a fraud flag is a stack that rejects candidates on VPNs.
- It does not cover work authorization. I-9 and E-Verify are a separate obligation with separate timing rules, and a CLEAR stamp is not a substitute.
- It does not cover IT onboarding. The laptop-farm scheme survived hiring and failed at the device-and-network layer — shipping-address verification, no-remote-desktop-on-company-hardware, and hardware-key enrollment belong to security.
Watch-outs, each with a guard
- Biometric verification is regulated, and Illinois is the live risk. CLEAR’s selfie-with-liveness collects a biometric identifier, which puts Illinois BIPA (740 ILCS 14) in play: written notice and a written release before collection, plus a retention schedule. The August 2024 amendment caps recovery at one claim per person per collection method without removing exposure. Guard: turn verification on at one named stage for every candidate on the requisition, keep the notice and release in the candidate record, and rely on the identity data staying with CLEAR rather than in your ATS.
- Selective verification is a discrimination claim waiting to happen. Guard: the stage rule is written and applies per requisition. Never trigger a check because a recruiter found a name or an accent suspicious.
- An AI voice screen is the easiest stage to send a proxy to. No human is on the call to notice that the voice does not match the face on the ID. Guard: never let Voice AI be the last stage before an offer on a remote role with system access, and put the CLEAR stamp after it rather than before, so verification covers a stage a human also attended.
- Checkr output is a consumer report under the FCRA — standalone disclosure and authorization, a pre-adverse-action notice with a copy of the report and the summary of rights, and a waiting period before the final decision. Guard: run rejections through Checkr’s adverse-action flow, and never mark the candidate rejected in the ATS first; the ATS status is the paper trail that contradicts you.
- High-risk signals catch legitimate candidates. Data-center IPs mean VPNs, and a relocating candidate’s timezone will not match. The 26% confirmation rate on weak signals is the number to internalize. Guard: require corroboration from a second signal class before any action.
- Verification stamps are per-stage, and a stamp at screen says nothing about who joins the onsite. Guard: for fully remote roles with system access, re-verify at the final round with the recorder running.
Match rules
Right pick when: hiring is fully remote; the roles carry system, code, or financial access; application volume per requisition runs into the hundreds; and you are already on Greenhouse Plus/Pro or Gem’s ATS. It is strongest on engineering, IT, and finance reqs at companies between roughly 100 and 1,000 people — large enough that recruiters cannot know every candidate, small enough that there is no internal fraud team.
Wrong pick when: hiring is in-person and hourly — the high-volume recruiting stack fits that motion, and physical presence solves identity for free. Also wrong when an agency owns sourcing and screening end to end, when you make fewer than about ten hires a year, or when the upgrade to the tier that gates the screening layer costs more than the fraud does.
If you can only do one thing: turn on application-layer fraud scoring and read AI interview fraud before you write the stage rule. It is the cheapest layer, it runs before any recruiter time is spent, and Greenhouse’s own pilot suggests it is where the volume actually is.