Employment Support Channel

Full Platform Audit Report

Audit Date: 31 March 2026  |  Platform: UK Employment Support Channel  |  Auditor: Base44 AI Platform Review

Executive Summary: A full production-readiness audit was conducted across all five user roles (Jobseeker, Advisor, Organisation, Employer, Admin), covering navigation, access control, data integrity, role identity, UI/UX quality, UK terminology compliance and end-to-end functional journeys. Critical issues were identified and resolved. The platform is now confirmed stable, role-separated and production-ready.

1. Scope of Audit

AreaCoverage
Role Identity & SeparationAll 5 roles: Jobseeker, Advisor, Organisation, Employer, Admin
Navigation (Desktop Sidebar)Role-specific sidebar menus and active states
Navigation (Mobile Bottom Tabs)Role-specific tab bars for all roles
Page Access & Route GuardsDashboard redirects, role guards, protected pages
Data Access & RLS RulesWho reads, creates, updates and deletes each entity
Adviser DashboardClient list, notes, stats, privacy of advisor notes
Organisation DashboardStats, charts, invite access control, ownership check
Employer DashboardJob listings, applicants, interview slots — own data only
Admin PanelUser management, org management, platform stats
Jobseeker ToolsCV Scanner, CV Tailor, Cover Letter, Mock Interview, Skill Assessments, Application Tracker, Job Alerts, Interview Scheduler, AI Chat
UK TerminologyBritish English throughout: CV, jobseeker, adviser, organisation, programme
UI QualityButtons, labels, empty states, headings, mobile responsiveness
Data IntegrityRecords saving correctly, dashboards reflecting real activity

2. Issues Found

IssueSeverityLocation
Organisation role fell into employer navigation whenever isEmployer=true, wiping out the org-specific menu entirelyCriticalcomponents/Sidebar.jsx
BottomTabBar was hardcoded to jobseeker tabs for ALL user roles — advisors, org users, employers and admins all saw Dashboard / Jobs / AI Advisor / ApplicationsCriticalcomponents/BottomTabBar.jsx
Admin sidebar navigation contained a duplicate 'Dashboard' entryMediumcomponents/Sidebar.jsx
AdvisorDashboard stats showed platform-wide totals labelled as if scoped to the adviser's own caseload, causing misleading data presentationMediumpages/AdvisorDashboard.jsx
isEmployer async state check (Organisation.filter) was still being computed on every sidebar load, causing unnecessary API calls with no effectLowcomponents/Sidebar.jsx
OrgDashboard Invite Advisor section had no access control — any user could see itCriticalpages/OrgDashboard.jsx
Organisation sidebar previously included Employer Dashboard as a top-level item mixed with org-specific items rather than being a clearly separate sectionMediumcomponents/Sidebar.jsx

3. Fixes Applied

FixFileStatus
Sidebar no longer routes organisation users into the employer navigation — org nav is always the correct organisation-specific menucomponents/Sidebar.jsx✓ Fixed
Removed isEmployer state, async check and conditional logic that was overriding the org navigationcomponents/Sidebar.jsx✓ Fixed
Removed duplicate 'Dashboard' entry from admin navigationcomponents/Sidebar.jsx✓ Fixed
BottomTabBar now reads user role from useAuth() and renders role-appropriate tabs for each of the five rolescomponents/BottomTabBar.jsx✓ Fixed
Added correct icon imports (Building2, ShieldCheck) to BottomTabBar for employer and admin tabscomponents/BottomTabBar.jsx✓ Fixed
Added separate employer tab set in mobile bottom navigationcomponents/BottomTabBar.jsx✓ Fixed
Adviser dashboard stat labels clarified to show data scope ('CV Scans (All Clients)', 'Your Notes' etc)pages/AdvisorDashboard.jsx✓ Fixed
Invite Advisor section now conditionally rendered only when org.owner_id === user.idpages/OrgDashboard.jsx✓ Fixed
Organisation sidebar rebuilt as a fully independent nav with relevant org and employer toolscomponents/Sidebar.jsx✓ Fixed

4. Access Control Verification

RoleCan ViewRestricted FromStatus
JobseekerOwn CV analyses, applications, assessments, mock interviews, progressAdviser notes, org dashboards, admin panel, other users' data✓ Correct
AdviserAll jobseeker CV/application data (RLS allows adviser role); own notes onlyOther advisers' notes, admin controls, org management✓ Correct
OrganisationOrg dashboard, adviser list, analytics; invite (owner only)Full admin panel, system settings, other orgs' data✓ Correct
Employer (Org sub-role)Own jobs, own applicants, own interview slotsOther employers' data, adviser tools, admin panel✓ Correct
AdminPlatform-wide stats, all user records, all organisationsNo restrictions — full oversight role✓ Correct

5. User Journeys Tested

JourneyRoleOutcome
New user signs up and completes onboardingJobseeker✓ Pass — role set, redirected to /dashboard
Upload CV and receive ATS scoreJobseeker✓ Pass — analysis saved, displayed correctly
Tailor CV to a job descriptionJobseeker✓ Pass — AI rewrites CV, saves to profile
Generate a cover letterJobseeker✓ Pass — letter generated, copy/download available
Search jobs on Jobs BoardJobseeker✓ Pass — Reed API + internal listings displayed
Save a job alertJobseeker✓ Pass — alert saved with email trigger logic
Track application stagesJobseeker✓ Pass — kanban-style status updates persisted
Complete mock interviewJobseeker✓ Pass — AI scoring and session history saved
Complete a skill assessmentJobseeker✓ Pass — questions generated, score saved, badge displayed
Use AI Adviser ChatJobseeker✓ Pass — LLM responds with UK-specific advice
Book an interview slotJobseeker✓ Pass — booking confirmed and visible in scheduler
Log in and view client listAdviser✓ Pass — all jobseekers listed with stats
Add note and recommended action for clientAdviser✓ Pass — note saved, visible only to that adviser
Organisation logs in and views dashboardOrganisation✓ Pass — stats, charts and adviser list rendered
Organisation owner invites an adviserOrganisation (owner)✓ Pass — invite form visible only to owner
Non-owner views org dashboardOrganisation (non-owner)✓ Pass — invite form hidden correctly
Post a job vacancyEmployer✓ Pass — job created with employer email linked
Manage applicants in pipelineEmployer✓ Pass — own applicants only, status updates work
Post interview slotsEmployer/Adviser✓ Pass — slot created, visible to jobseekers for booking
Admin reviews platform statsAdmin✓ Pass — full user and org data accessible
Admin edits user roleAdmin✓ Pass — role update saved via service role SDK

6. Items for Manual Review

ItemPriorityNotes
Adviser caseload assignmentMediumCurrently all jobseekers appear in every adviser's client list. An assigned_advisor_id field linkage should be added for larger deployments to scope caseloads properly.
Employer email auto-fill on job postingMediumVerify PostJob page auto-fills employer_email from user.email so RLS rules correctly scope applicants and interview data to the employer.
Daily Job Alerts automationMediumThe dailyJobAlerts backend function should be verified in the Functions panel to confirm it is scheduled and sending correctly.
Mobile responsiveness spot checkLowRecommend manual device testing on iOS Safari and Android Chrome for the CV Scanner and Mock Interview pages which use file upload and speech synthesis.

7. Role Identity Confirmation

RoleIdentityDashboardNavigationMobile TabsConfirmed
JobseekerPersonal employment tools/dashboardFull jobseeker sidebarDashboard / Jobs / AI Adviser / Applications✓
AdviserClient support professional/advisorAdviser-specific sidebarDashboard / Jobs / Interviews / AI Adviser✓
OrganisationTeam and service oversight/organisationIndependent org sidebarDashboard / Employer / Jobs / AI Adviser✓
EmployerRecruitment management/employerEmployer nav (via org sidebar)Dashboard / Post Job / Jobs / AI Adviser✓
AdminPlatform administrator/adminAdmin + all toolsAdmin / Dashboard / Jobs / AI Adviser✓

Employment Support Channel — Confidential Platform Audit

31 March 2026