Prompt Details
Model
(claude-5-opus)
Token size
4,690
Example input
[CANDIDATE_MATERIALS]: Candidate ANON-101 Security Analyst, 2021–present. Investigated phishing, credential compromise, malware alerts, and suspicious endpoint activity using Microsoft Sentinel and Defender for Endpoint. Created three Sentinel detection rules and supported monthly vulnerability reviews. During a ransomware incident in 2025, collected endpoint evidence, isolated affected devices, and documented findings for the incident lead. The candidate does not state whether they coordinated the response or communicated with executives. Previously worked for two years as an IT Support Specialist. Holds CompTIA Security+. --- Candidate ANON-102 Cybersecurity Specialist with six years of experience. Led incident triage for a financial-services organization. Coordinated technical responders during two high-severity incidents, maintained the incident timeline, and presented post-incident findings to risk and compliance teams. Managed Splunk alert tuning and developed detection use cases for privileged-account misuse. Participated in PCI DSS evidence collection. The CV states that the candidate “dramatically improved detection capability,” but provides no baseline, measurement method, or attributable result. --- Candidate ANON-103 SOC Engineer, 2019–present. Administered Microsoft Sentinel, Defender for Endpoint, and CrowdStrike. Developed KQL queries, automated alert enrichment using PowerShell, and maintained SOC runbooks. Worked in a healthcare organization and attended compliance meetings. The material does not describe direct responsibility for regulatory controls or audit evidence. Supported incident investigations but does not clarify whether the candidate led incident response.
[ROLE_AND_SELECTION_CONTEXT]: Role: Senior Cybersecurity Analyst Essential requirements: - At least four years of cybersecurity operations experience - Hands-on SIEM investigation - Incident-response coordination - Detection engineering - Experience operating under regulated controls Desirable requirements: - Microsoft Sentinel - Security automation - Relevant professional certification Interview capacity: Two candidates Operational constraints: - Must be available to join an on-call rotation - Employment start preferred before November 2026 - No candidate should be excluded automatically when availability is unknown Excluded candidates: None
Example output
COHORT VERDICT
COHORT SIZE: 3 admitted · 0 held out
DISCRIMINATION: 2 of 5 essential requirements are SPLITTING
DECISION INPUT: Whether ANON-102's and ANON-103's unstated incident-leadership scope, and ANON-101's/ANON-103's unclear regulated-control ownership, can be resolved before the shortlist meeting will determine which two candidates are genuinely distinguishable.
---
### Section 1 — Candidate Intake Validation
| Candidate | Material Type | Readability | Role Relevance | Duplicate Status | Exclusion Status | Intake Result | Reason |
|---|---|---|---|---|---|---|---|
| ANON-101 | Candidate summary | Readable | Directly relevant (Security Analyst) | None detected | Not excluded | ADMITTED | Contains extractable SIEM, detection, and incident-support evidence |
| ANON-102 | Candidate summary | Readable | Directly relevant (Cybersecurity Specialist) | None detected | Not excluded | ADMITTED | Contains extractable incident-coordination, SIEM, and compliance evidence |
| ANON-103 | Candidate summary | Readable | Directly relevant (SOC Engineer) | None detected | Not excluded | ADMITTED | Contains extractable SIEM, detection engineering, and regulated-sector evidence |
No unreadable material, no duplicates, no user-specified exclusions. Minimum cohort gate satisfied (3 ≥ 2).
---
### Section 2 — Requirement Frame
| ID | Requirement | Essential/Desirable | Explicit Threshold | Expected Evidence | Ambiguity Status |
|---|---|---|---|---|---|
| R1 | Cybersecurity operations experience | Essential | ≥4 years | Stated role tenure/dates in cybersecurity operations roles | None |
| R2 | Hands-on SIEM investigation | Essential | None stated | Direct account of using a SIEM tool to investigate alerts/incidents | None |
| R3 | Incident-response coordination | Essential | None stated | Statement of directing, coordinating, or leading responders during an incident | REQUIREMENT AMBIGUITY — "coordination" is not defined; unclear whether it requires formal incident-command authority, informal coordination among peers, or simply timeline/communication ownership. This ambiguity affects grading below. |
| R4 | Detection engineering | Essential | None stated | Statement of building/authoring detection rules, use cases, or analytics logic | None |
| R5 | Experience operating under regulated controls | Essential | None stated | Statement of direct responsibility for, or evidence contribution to, a regulatory control framework (e.g., PCI DSS, HIPAA) | REQUIREMENT AMBIGUITY — unclear whether "operating under" requires personal ownership of controls or merely working inside a regulated environment. Distinct interpretations materially change grading. |
| R6 (desirable) | Microsoft Sentinel | Desirable | None stated | Direct mention of Sentinel use | None |
| R7 (desirable) | Security automation | Desirable | None stated | Direct mention of building automation | None |
| R8 (desirable) | Relevant professional certification | Desirable | None stated | Named certification | None |
---
### Section 3 — Normalized Candidate Evidence Profiles
**ANON-101**
| Req | Grade | Confidence | Anchor | Ownership Level | Limitation |
|---|---|---|---|---|---|
| R1 | EVIDENCED | MEDIUM | "Security Analyst, 2021–present" (~4–5 yrs, plus 2 yrs IT Support not counted as ops) | Individual contributor | Tenure at threshold boundary depending on exact dates |
| R2 | EVIDENCED | HIGH | Investigated phishing, credential compromise, malware, endpoint activity using Sentinel/Defender | Individual contributor | None stated |
| R3 | INFERRED | LOW | Collected evidence, isolated devices, documented findings for the incident lead during 2025 ransomware incident | Participation/contribution, not coordination | Inference step: supporting an incident lead is not the same as coordinating responders; candidate does not state they directed anyone. Explicitly noted as unclear by the candidate material itself. |
| R4 | EVIDENCED | MEDIUM | Created three Sentinel detection rules | Individual contributor | Scope (three rules) is small but explicit |
| R5 | UNKNOWN | — | No mention of a regulated industry, framework, or compliance activity | — | Material simply does not address this requirement |
| R6 | EVIDENCED | HIGH | Used Microsoft Sentinel and Defender for Endpoint | — | — |
| R7 | UNKNOWN | — | No automation activity described | — | — |
| R8 | EVIDENCED | HIGH | Holds CompTIA Security+ | — | — |
**ANON-102**
| Req | Grade | Confidence | Anchor | Ownership Level | Limitation |
|---|---|---|---|---|---|
| R1 | EVIDENCED | HIGH | "Cybersecurity Specialist with six years of experience" | Individual contributor / lead | None stated |
| R2 | EVIDENCED | MEDIUM | Managed Splunk alert tuning | Individual/ownership over tuning | No investigation narrative as explicit as ANON-101's or ANON-103's — tuning is adjacent to but not the same as investigation |
| R3 | EVIDENCED | HIGH | Led incident triage; coordinated technical responders during two high-severity incidents; maintained incident timeline; presented findings to risk/compliance | Leadership/coordination | None stated |
| R4 | EVIDENCED | MEDIUM | Developed detection use cases for privileged-account misuse | Individual contributor | Scope (use case count) not specified |
| R5 | INFERRED | LOW | Participated in PCI DSS evidence collection for a financial-services organization | Participation, not stated ownership of controls | Inference step: "participated in evidence collection" shows contact with a regulated framework but not confirmed personal control ownership |
| R6 | UNKNOWN | — | Sentinel not mentioned; Splunk is named instead | — | — |
| R7 | UNKNOWN | — | No automation activity described | — | — |
| R8 | UNKNOWN | — | No certification named | — | — |
Note: the claim of "dramatically improved detection capability" is PRESENTATION-ONLY — quantified/confident language with no baseline or attributable method — and is not counted as evidence for R4 scope.
**ANON-103**
| Req | Grade | Confidence | Anchor | Ownership Level | Limitation |
|---|---|---|---|---|---|
| R1 | EVIDENCED | HIGH | "SOC Engineer, 2019–present" (~6–7 yrs) | Individual contributor | None stated |
| R2 | EVIDENCED | HIGH | Administered Sentinel, Defender for Endpoint, CrowdStrike; developed KQL queries | Individual/ownership over tooling | None stated |
| R3 | INFERRED | LOW | "Supported incident investigations but does not clarify whether the candidate led incident response" | Participation, ownership unclear | Candidate material explicitly states this is unclear; treated as INFERRED with LOW confidence rather than EVIDENCED |
| R4 | EVIDENCED | HIGH | Developed KQL queries and automated alert enrichment using PowerShell; maintained SOC runbooks | Individual contributor | None stated |
| R5 | INFERRED | LOW | "Worked in a healthcare organization and attended compliance meetings... does not describe direct responsibility for regulatory controls or audit evidence" | Adjacent exposure, not ownership | Inference step: healthcare-sector employment plus meeting attendance suggests proximity to regulated controls but not personal operation under them |
| R6 | EVIDENCED | HIGH | Administered Microsoft Sentinel | — | — |
| R7 | EVIDENCED | MEDIUM | Automated alert enrichment using PowerShell | — | — |
| R8 | UNKNOWN | — | No certification named | — | — |
---
### Section 4 — Extraction Consistency Log
- R3 (incident-response coordination): initial read risked grading ANON-101 and ANON-103 as EVIDENCED based on the word "incident" appearing prominently in their bullets. Corrected to INFERRED/LOW for both, since neither candidate states they directed or coordinated responders — both explicitly describe supporting roles or leave the coordination question open. ANON-102 remains the only EVIDENCED case, based on explicit language ("led," "coordinated technical responders").
- R5 (regulated controls): initial read risked treating "healthcare organization" (ANON-103) and "financial-services organization" (ANON-102) as equivalent to "PCI DSS evidence collection" (explicitly stated for ANON-102 only). Corrected: ANON-102 gets INFERRED/LOW (explicit framework named, but ownership unclear) while ANON-103 gets INFERRED/LOW on weaker grounds (sector + meeting attendance only, no framework named) — both capped at LOW rather than one being upgraded to MEDIUM based on sector prestige.
- Quantified claims ("dramatically improved detection capability," "reduced deployment time" pattern from the sample cohort) were checked against the presentation-bias rule and excluded from evidence weight where no baseline or method was supplied.
No other material extraction inconsistency detected.
---
### Section 5 — Cohort Coverage Map
| Req | EVIDENCED | INFERRED | UNKNOWN | Cohort Label | Recruiter Action |
|---|---|---|---|---|---|
| R1 | 3 | 0 | 0 | NON-DISCRIMINATING | All three meet the tenure threshold on stated dates; do not use as a differentiator |
| R2 | 3 | 0 | 0 | NON-DISCRIMINATING (on grade) — see Section 6 for scope differences | All three show hands-on SIEM investigation; differences are in tool/scope, not presence of evidence |
| R3 | 1 | 2 | 0 | SPLITTING | ANON-102 is EVIDENCED with explicit coordination language; ANON-101 and ANON-103 are both INFERRED/LOW on a genuinely different basis (unclear scope of their own stated role) |
| R4 | 3 | 0 | 0 | NON-DISCRIMINATING (on grade) — see Section 6 for scope differences | All three build or maintain detection logic; differences are in described breadth |
| R5 | 0 | 2 | 1 | SPLITTING | ANON-101 has no regulated-environment evidence at all (UNKNOWN); ANON-102 and ANON-103 are both INFERRED/LOW but on different bases (named framework vs. sector proximity only) |
**Essential-requirement discrimination summary:**
- Total essential requirements: 5
- Essential SPLITTING requirements: 2 (R3, R5)
- Essential NON-DISCRIMINATING requirements: 3 (R1, R2, R4)
- Essential COHORT BLIND SPOTS: 0
- Essential requirements insufficiently defined: 0 (R3 and R5 carry REQUIREMENT AMBIGUITY flags from Section 2, but sufficient evidence variation exists to grade under a stated interpretation)
Only 2 of 5 essential requirements currently separate this cohort. Three of five essential requirements do not distinguish the candidates on the evidence supplied.
---
### Section 6 — Pairwise Differences
Three candidates, three possible pairs — all analyzed (under the eight-pair cap).
**Pair: ANON-101 vs ANON-102**
- DIFFERENT ON EVIDENCE (R3): ANON-101 is INFERRED/LOW (supported an incident lead, did not state coordination); ANON-102 is EVIDENCED/HIGH (explicit coordination of responders across two high-severity incidents, timeline ownership, stakeholder presentation). This is a substantive difference: ANON-102's material describes a distinct coordinating function that ANON-101's does not claim.
- DIFFERENT ON EVIDENCE (R5): ANON-101 is UNKNOWN (no regulated-framework mention at all); ANON-102 is INFERRED/LOW (named PCI DSS evidence collection, but ownership unclear). Substantive because ANON-102 at least places the candidate inside a named regulatory activity, while ANON-101's material contains nothing to assess.
- DIFFERENT ON DEMONSTRATED SCOPE (R4): ANON-101 EVIDENCED at individual-tool scope (three Sentinel rules, explicit count); ANON-102 EVIDENCED at use-case-development scope for a specific threat category (privileged-account misuse), without a stated count. Both are individual-contributor scope; the difference is category-specificity, not team/enterprise scope — flagged as a minor scope distinction, not a major one.
- SAME EVIDENCE, DIFFERENT PRESENTATION (R2): Both candidates evidence hands-on SIEM investigation/tuning at HIGH-to-MEDIUM confidence. ANON-102's CV is noted as "highly quantified" in framing generally, but the core investigation/tuning claim itself is comparably concrete to ANON-101's. This is not fully presentation-only since tool scope differs (investigation vs. tuning), but the confident tone of ANON-102's material should not be read as stronger competency than ANON-101's absent additional scope detail.
**Pair: ANON-101 vs ANON-103**
- DIFFERENT ONLY ON UNKNOWNS / SAME EVIDENCE (R3): Both are INFERRED/LOW. Not a supported difference. Both require clarification — neither candidate's material states whether they directed or coordinated responders.
- DIFFERENT ON DEMONSTRATED SCOPE (R2): ANON-101 evidences investigation across phishing, credential compromise, malware, and endpoint activity using two named tools; ANON-103 evidences broader tool administration (Sentinel, Defender, CrowdStrike) plus authored KQL query development. ANON-103's evidence extends into building investigative logic (R4-adjacent), which ANON-101's R2 evidence does not claim.
- DIFFERENT ON EVIDENCE (R5): ANON-101 is UNKNOWN; ANON-103 is INFERRED/LOW (healthcare-sector employment, compliance-meeting attendance, explicitly no stated control ownership). This is a real but narrow difference — ANON-103 has *something* to point to, ANON-101 has nothing, but neither has ownership-level evidence.
- DIFFERENT ON EVIDENCE (R7, desirable): ANON-103 is EVIDENCED/MEDIUM (PowerShell-based alert enrichment automation); ANON-101 is UNKNOWN. Desirable requirement, noted for completeness, not decisive for essential-requirement separation.
**Pair: ANON-102 vs ANON-103**
- DIFFERENT ON EVIDENCE (R3): ANON-102 EVIDENCED/HIGH (explicit coordination language); ANON-103 INFERRED/LOW (candidate's own material states it is unclear whether they led response). Substantive difference on the same basis as the ANON-101 comparison above.
- DIFFERENT ON CONFIDENCE (R5): Both INFERRED/LOW, but on different grounds — ANON-102 names a specific framework (PCI DSS) and a specific activity (evidence collection); ANON-103 offers only sector context and meeting attendance with no named framework or activity. Both remain LOW confidence; the difference in grounds does not currently justify separating them into different confidence tiers under the evidence supplied, but a clarification question could resolve this.
- SAME EVIDENCE, DIFFERENT PRESENTATION (R4): Both EVIDENCED for detection engineering. ANON-102's "dramatically improved detection capability" is unsupported quantified language (presentation-only, excluded from grading per Section 4); once that language is discounted, ANON-102's underlying evidence (developed use cases for privileged-account misuse) and ANON-103's underlying evidence (KQL queries, automated enrichment, runbooks) are comparable in kind — individual-contributor detection-content authorship — even though ANON-103's material reads as more technically detailed. This detail difference is partly presentation (more bullets, more named tools) and partly a genuine scope difference (ANON-103 explicitly shows automation of enrichment, which ANON-102 does not claim) — see R7 desirable distinction below.
- DIFFERENT ON EVIDENCE (R7, desirable): ANON-103 EVIDENCED/MEDIUM (PowerShell automation); ANON-102 UNKNOWN. Desirable requirement only.
---
### Section 7 — Cohort Question Set
**Cohort-wide questions**
| ID | Question | Candidates | Requirement | Current Label | Uncertainty Resolved | Expected Evidence | Type |
|---|---|---|---|---|---|---|---|
| Q1 | "Walk me through the ransomware/high-severity incident you mentioned. What decisions did you personally make, and who did you direct or communicate with during it?" | ANON-101, ANON-103 | R3 | SPLITTING (both currently INFERRED/LOW) | Whether either candidate held a coordinating role vs. a purely supporting role | Named decisions, named direction of others, or explicit confirmation of a supporting-only role | COHORT-WIDE |
| Q2 | "Describe your personal responsibility, if any, for maintaining or operating a specific regulatory control (e.g., PCI DSS, HIPAA). What was the control, and what did you personally do?" | ANON-101, ANON-102, ANON-103 | R5 | SPLITTING | Whether "regulated environment" exposure reflects personal control ownership for any candidate, including ANON-101 who currently has no evidence at all | Named control, named personal action, or confirmation of no direct ownership | COHORT-WIDE |
**Candidate-specific questions**
| ID | Question | Candidate | Requirement | Current Label | Uncertainty Resolved | Expected Evidence | Type |
|---|---|---|---|---|---|---|---|
| Q3 | "You mentioned presenting incident findings to risk and compliance teams — was this a task you owned end-to-end, or one part of a larger team effort?" | ANON-102 | R3 | SPLITTING | Confirms whether the EVIDENCED/HIGH grade on R3 reflects individual ownership or shared team credit | Clarified ownership scope | CANDIDATE-SPECIFIC |
| Q4 | "You noted detection capability improved dramatically — what was measured, what was the baseline, and how was it calculated?" | ANON-102 | R4 | NON-DISCRIMINATING (grade) | Whether the unsupported quantified claim reflects a real measurable outcome | Named metric, baseline, method | CANDIDATE-SPECIFIC |
| Q5 | "Can you describe a specific example of a Sentinel detection rule you built end-to-end, including what it detected and why?" | ANON-101 | R4 | NON-DISCRIMINATING (grade) | Confirms individual authorship and depth behind the stated count of three rules | Named rule logic, detection logic, and rationale | CANDIDATE-SPECIFIC |
| Q6 | "How much of your KQL query and PowerShell automation work was solo work versus built on existing team templates?" | ANON-103 | R4/R7 | NON-DISCRIminating (R4) / SPLITTING (R7, desirable) | Confirms individual ownership level behind the detection-content authorship | Clarified authorship scope | CANDIDATE-SPECIFIC |
---
### Section 8 — Operational Constraints
| Candidate | On-call availability | Start date before Nov 2026 |
|---|---|---|
| ANON-101 | Constraint status unknown — not addressed in supplied material | Constraint status unknown — not addressed |
| ANON-102 | Constraint status unknown — not addressed in supplied material | Constraint status unknown — not addressed |
| ANON-103 | Constraint status unknown — not addressed in supplied material | Constraint status unknown — not addressed |
No candidate should be excluded automatically for unknown availability, per the supplied selection context. All three require additional confirmation before this constraint can be applied.
---
### Section 9 — Shortlist Decision Inputs
- **Distinguishable on demonstrated evidence:** ANON-102 is currently distinguishable from ANON-101 and ANON-103 on R3 (incident-response coordination), where ANON-102 holds the only EVIDENCED/HIGH grade in the cohort.
- **Indistinguishable pairs:** ANON-101 and ANON-103 remain indistinguishable on R3 (both INFERRED/LOW, same underlying uncertainty). All three candidates remain close on R5 (regulated controls), with only degree-of-proximity differences (named framework vs. sector context vs. no evidence) rather than confirmed ownership differences for any candidate.
- **Requirements creating distinction:** R3 and R5 only; R1, R2, and R4 do not currently separate the cohort.
- **Operational constraints confirmed:** None.
- **Constraints remaining unknown:** On-call availability and start-date availability for all three candidates.
- **Interview capacity note:** Two interview slots are available for three admitted candidates. Because only 2 of 5 essential requirements currently discriminate the cohort, and operational constraints are unknown for all three candidates, Human prioritization is required because the evidence analysis does not determine which business priority should control the shortlist.
---
### Section 10 — Scope and Limits
Scope and limits. This analysis compares evidence contained in supplied candidate materials. It compares documents, not people. It does not rank candidates, predict job performance, or produce a shortlist decision.
Human decision required. Output is decision support for a qualified recruiter or hiring manager. It must not be used as an automated screening filter, an automatic rejection gate, or the sole basis for an employment decision.
Regulatory note. Employment screening and candidate evaluation may be treated as regulated or high-risk uses of automated systems depending on jurisdiction, deployment context, and system function. Applicable obligations may include human oversight, transparency, notice, recordkeeping, impact assessment, bias testing, data-protection safeguards, and restrictions on solely automated decisions. Confirm current legal obligations with qualified counsel before deployment.
Bias. Structured evidence comparison may reduce presentation bias. It does not remove bias contained in candidate materials, the job description, evidence interpretation, interview design, selection constraints, or the applicant pool. A COHORT BLIND SPOT may reflect how the requirement was written rather than what candidates can demonstrate.
$29.99-25%
$22.49
SPECIAL PROMOTION — Offer ends 3 August
By purchasing this prompt, you agree to our terms of service
CLAUDE-5-OPUS
Compare multiple candidates using structured competency evidence instead of CV presentation quality. Validate graph compatibility, expose requirements that genuinely separate the cohort, identify shared blind spots, distinguish evidence differences from writing differences, and generate the interview question that removes the most uncertainty. Produces no ranking, score, hiring recommendation, or automatic shortlist.
...more
Added 4 hours ago
