Control Who Can Access from Where
IP Whitelisting: Network Access Controls, Geographic Restrictions & Exceptions
Restrict platform access to approved IP addresses and ranges. Enforce geographic access controls, block unauthorized networks, and manage time-limited exceptions.

Hirebee is a highly recommended global hiring solution
IP Whitelisting
Network-Level Access Restriction
Even strong passwords and MFA can be defeated by sophisticated attacks if access is possible from anywhere in the world. IP whitelisting adds a network-layer control that restricts Hirebee access to approved IP addresses and ranges only \u2014 regardless of whether an authentication attempt uses valid credentials. Configure approved IP addresses for office locations, VPN exit nodes, and approved remote work networks. Attempts to log in from any IP address not on the whitelist are blocked before authentication even begins, with the blocked attempt logged as a security event. For organizations with strict security policies \u2014 financial services, healthcare, government contractors \u2014 IP whitelisting combined with SSO and MFA creates a defense-in-depth access control posture that satisfies the most demanding security auditors.
CIDR Range and Network Segment Support
Managing individual IP addresses is impractical for organizations with large or dynamic office networks. Hirebee supports CIDR notation for IP whitelisting, allowing administrators to approve entire network ranges with a single rule: approve the entire corporate office subnet, the VPN address pool, or a cloud provider's egress range. Rules are labeled with descriptive names (HQ Office, London Branch, US VPN Pool) so administrators can immediately understand what each rule covers without decoding IP ranges. Changes to network infrastructure \u2014 a new office, a VPN provider change, a cloud migration \u2014 are reflected in the whitelist immediately when the relevant rules are updated. A rule preview shows how many current active sessions match each rule, helping administrators assess the impact of a change before saving it.
Geographic Access Controls and Country Blocking
Some organizations need to restrict access by country rather than by specific IP range \u2014 particularly when complying with data residency requirements, export control regulations, or following security policies that prohibit access from specific regions. Hirebee's geographic access controls use IP geolocation to identify the country of origin for each login attempt and apply configured rules. Allow access only from specific countries, block access from specific regions, or configure different access levels based on location. Country-level controls complement IP whitelisting for organizations with mobile or remote workforces where approved individual IP ranges are impractical. Geolocation data is logged with every login event, providing visibility into where the workforce is accessing the platform from even when explicit blocking is not configured.
Exceptions, Overrides, and Emergency Access
Strict network access controls create operational risk when legitimate access is needed from outside approved networks. Hirebee provides structured exception management: administrators can grant time-limited access exceptions for specific users (an executive traveling internationally, a contractor working from an unapproved location) without modifying the organization-wide whitelist. Exceptions are logged with the reason, the approving administrator, and the expiry time, creating an auditable record of every access control override. Emergency access procedures allow designated administrators to log in through a separate, audited channel when normal access is unavailable due to network or VPN issues. All emergency accesses trigger immediate notifications to the security team and are prominently marked in the access log for post-incident review.
Ready to see it in action?
Join 1,000+ companies using Hirebee. Start your free trial — no credit card required.
