Evidence from the interviews your team already runs — collected with consent, concluded by your people.
Proctor runs beside your own interview, in the video tool or coding exercise you already use. The candidate installs a native desktop app and agrees to exactly what is captured; a named reviewer on your team reads the evidence and records the conclusion. It is a separate product from the Luminos Hire AI interview, with its own accounts.
Built for
Hiring teams running remote interviews and technical assessments
Your team
Runs the interview as usual — Proctor records consented evidence beside it
Who decides
A named reviewer on your team. Never the software.
macOS, Windows and Linux. No browser extension, no hidden background process.
Proctor — session consent
This session will capture
Nothing starts until you agree, and you can end the session at any point.
screen_recordingShared window only
cameraFront camera
microphoneWhile you answer
Not captured: keystrokes, window titles, installed software, or anything outside this session.
Agree and continueDecline
Recording · this session is monitored
Proctor, or the Luminos Hire AI interview?
Both keep a person responsible for the outcome. They differ in who runs the interview. Proctor is a separate product with separate accounts — signing in to Luminos Hire does not sign you in here.
Proctor — your interviewer runs the interview
Use it when someone on your team conducts the interview or assessment in your own tools, and you want consented evidence of the session for a reviewer to read afterwards. It records observations; it does not assess skill.
The two can also work together: a Luminos Hire interview can be linked to a Proctor session so its desktop evidence is available to the same review. The products still keep separate accounts and separate data.
Four commitments the product is built around
These are not settings. They are properties of how the agent and the API are built, and every release is audited against them.
Consent before anything
No capture, event or upload happens until the server holds a consent record naming the exact scopes. Without one, the ingest API refuses the write.
Always visible
A banner in the app and an indicator in the menu bar or tray, for the whole session. There is no hidden mode to enable — not even for administrators.
Only what was agreed
No keystrokes, no window titles, no software inventory. Screen, audio and camera cross the network only under a scope the candidate agreed to and your policy allows.
A person decides
Observations are described, never scored. There is no risk number, no automatic flag and no pass/fail — because the decision belongs to a named human being.
What is actually in the product
22 capabilities across the agent, the live session, the evidence store and the platform around them — most of which were previously only visible after you logged in.
Native desktop agents
Swift on macOS, WinUI 3 on Windows, GTK4 on Linux — each using its platform's real capture and permission APIs, and installed as a normal application.
Consent-gated capture
No capture, event or upload happens until the server holds a consent record naming the exact scopes. Without one, the ingest API refuses the write.
Live session view
Watch a running session from the browser — media, participants and the event stream as it is written.
Session viewer
Timeline, media and transcript in one view, so a reviewer reads a moment and its context together instead of correlating three exports.
REST API and Node SDK
Provision sessions, fetch evidence and manage retention from your own systems. The OpenAPI document is published, and the SDK is generated from it rather than hand-written.
Provision the session from your own systems — the API, the Node SDK or an ATS connector. It comes back with a join link per participant, and captures nothing yet.
2
Consent
The candidate installs the desktop app and reads exactly what will be collected. Nothing starts until they agree to it.
3
Run
Monitoring runs with the indicator visible. If the network drops, the agent buffers locally and resumes — nothing is lost.
4
Review
A reviewer reads the timeline, media and transcript together, and records their own conclusion in their own words.
What it will not do
It will not tell you whether a candidate did something wrong. There is no score, no risk rating and no automated flag on a person.
It will not log keystrokes, read window titles, or inventory what is installed on the machine.
It will not run hidden or in the background, and it cannot be configured to.
It will not build a face signature or match anyone against a database. Camera signals answer presence and multiple faces, nothing more.
Every one of those is a deliberate limit rather than a missing feature. A tool that made the decision for you would move the responsibility away from the person who has to justify it.
See whether it fits your interviews
Tell us how your team interviews today. A person reads every request and sets up access with you — there is no self-serve sign-up.