Full Platform Audit Report
| Area | Coverage |
|---|---|
| Role Identity & Separation | All 5 roles: Jobseeker, Advisor, Organisation, Employer, Admin |
| Navigation (Desktop Sidebar) | Role-specific sidebar menus and active states |
| Navigation (Mobile Bottom Tabs) | Role-specific tab bars for all roles |
| Page Access & Route Guards | Dashboard redirects, role guards, protected pages |
| Data Access & RLS Rules | Who reads, creates, updates and deletes each entity |
| Adviser Dashboard | Client list, notes, stats, privacy of advisor notes |
| Organisation Dashboard | Stats, charts, invite access control, ownership check |
| Employer Dashboard | Job listings, applicants, interview slots — own data only |
| Admin Panel | User management, org management, platform stats |
| Jobseeker Tools | CV Scanner, CV Tailor, Cover Letter, Mock Interview, Skill Assessments, Application Tracker, Job Alerts, Interview Scheduler, AI Chat |
| UK Terminology | British English throughout: CV, jobseeker, adviser, organisation, programme |
| UI Quality | Buttons, labels, empty states, headings, mobile responsiveness |
| Data Integrity | Records saving correctly, dashboards reflecting real activity |
| Issue | Severity | Location |
|---|---|---|
| Organisation role fell into employer navigation whenever isEmployer=true, wiping out the org-specific menu entirely | Critical | components/Sidebar.jsx |
| BottomTabBar was hardcoded to jobseeker tabs for ALL user roles — advisors, org users, employers and admins all saw Dashboard / Jobs / AI Advisor / Applications | Critical | components/BottomTabBar.jsx |
| Admin sidebar navigation contained a duplicate 'Dashboard' entry | Medium | components/Sidebar.jsx |
| AdvisorDashboard stats showed platform-wide totals labelled as if scoped to the adviser's own caseload, causing misleading data presentation | Medium | pages/AdvisorDashboard.jsx |
| isEmployer async state check (Organisation.filter) was still being computed on every sidebar load, causing unnecessary API calls with no effect | Low | components/Sidebar.jsx |
| OrgDashboard Invite Advisor section had no access control — any user could see it | Critical | pages/OrgDashboard.jsx |
| Organisation sidebar previously included Employer Dashboard as a top-level item mixed with org-specific items rather than being a clearly separate section | Medium | components/Sidebar.jsx |
| Fix | File | Status |
|---|---|---|
| Sidebar no longer routes organisation users into the employer navigation — org nav is always the correct organisation-specific menu | components/Sidebar.jsx | ✓ Fixed |
| Removed isEmployer state, async check and conditional logic that was overriding the org navigation | components/Sidebar.jsx | ✓ Fixed |
| Removed duplicate 'Dashboard' entry from admin navigation | components/Sidebar.jsx | ✓ Fixed |
| BottomTabBar now reads user role from useAuth() and renders role-appropriate tabs for each of the five roles | components/BottomTabBar.jsx | ✓ Fixed |
| Added correct icon imports (Building2, ShieldCheck) to BottomTabBar for employer and admin tabs | components/BottomTabBar.jsx | ✓ Fixed |
| Added separate employer tab set in mobile bottom navigation | components/BottomTabBar.jsx | ✓ Fixed |
| Adviser dashboard stat labels clarified to show data scope ('CV Scans (All Clients)', 'Your Notes' etc) | pages/AdvisorDashboard.jsx | ✓ Fixed |
| Invite Advisor section now conditionally rendered only when org.owner_id === user.id | pages/OrgDashboard.jsx | ✓ Fixed |
| Organisation sidebar rebuilt as a fully independent nav with relevant org and employer tools | components/Sidebar.jsx | ✓ Fixed |
| Role | Can View | Restricted From | Status |
|---|---|---|---|
| Jobseeker | Own CV analyses, applications, assessments, mock interviews, progress | Adviser notes, org dashboards, admin panel, other users' data | ✓ Correct |
| Adviser | All jobseeker CV/application data (RLS allows adviser role); own notes only | Other advisers' notes, admin controls, org management | ✓ Correct |
| Organisation | Org dashboard, adviser list, analytics; invite (owner only) | Full admin panel, system settings, other orgs' data | ✓ Correct |
| Employer (Org sub-role) | Own jobs, own applicants, own interview slots | Other employers' data, adviser tools, admin panel | ✓ Correct |
| Admin | Platform-wide stats, all user records, all organisations | No restrictions — full oversight role | ✓ Correct |
| Journey | Role | Outcome |
|---|---|---|
| New user signs up and completes onboarding | Jobseeker | ✓ Pass — role set, redirected to /dashboard |
| Upload CV and receive ATS score | Jobseeker | ✓ Pass — analysis saved, displayed correctly |
| Tailor CV to a job description | Jobseeker | ✓ Pass — AI rewrites CV, saves to profile |
| Generate a cover letter | Jobseeker | ✓ Pass — letter generated, copy/download available |
| Search jobs on Jobs Board | Jobseeker | ✓ Pass — Reed API + internal listings displayed |
| Save a job alert | Jobseeker | ✓ Pass — alert saved with email trigger logic |
| Track application stages | Jobseeker | ✓ Pass — kanban-style status updates persisted |
| Complete mock interview | Jobseeker | ✓ Pass — AI scoring and session history saved |
| Complete a skill assessment | Jobseeker | ✓ Pass — questions generated, score saved, badge displayed |
| Use AI Adviser Chat | Jobseeker | ✓ Pass — LLM responds with UK-specific advice |
| Book an interview slot | Jobseeker | ✓ Pass — booking confirmed and visible in scheduler |
| Log in and view client list | Adviser | ✓ Pass — all jobseekers listed with stats |
| Add note and recommended action for client | Adviser | ✓ Pass — note saved, visible only to that adviser |
| Organisation logs in and views dashboard | Organisation | ✓ Pass — stats, charts and adviser list rendered |
| Organisation owner invites an adviser | Organisation (owner) | ✓ Pass — invite form visible only to owner |
| Non-owner views org dashboard | Organisation (non-owner) | ✓ Pass — invite form hidden correctly |
| Post a job vacancy | Employer | ✓ Pass — job created with employer email linked |
| Manage applicants in pipeline | Employer | ✓ Pass — own applicants only, status updates work |
| Post interview slots | Employer/Adviser | ✓ Pass — slot created, visible to jobseekers for booking |
| Admin reviews platform stats | Admin | ✓ Pass — full user and org data accessible |
| Admin edits user role | Admin | ✓ Pass — role update saved via service role SDK |
| Item | Priority | Notes |
|---|---|---|
| Adviser caseload assignment | Medium | Currently all jobseekers appear in every adviser's client list. An assigned_advisor_id field linkage should be added for larger deployments to scope caseloads properly. |
| Employer email auto-fill on job posting | Medium | Verify PostJob page auto-fills employer_email from user.email so RLS rules correctly scope applicants and interview data to the employer. |
| Daily Job Alerts automation | Medium | The dailyJobAlerts backend function should be verified in the Functions panel to confirm it is scheduled and sending correctly. |
| Mobile responsiveness spot check | Low | Recommend manual device testing on iOS Safari and Android Chrome for the CV Scanner and Mock Interview pages which use file upload and speech synthesis. |
| Role | Identity | Dashboard | Navigation | Mobile Tabs | Confirmed |
|---|---|---|---|---|---|
| Jobseeker | Personal employment tools | /dashboard | Full jobseeker sidebar | Dashboard / Jobs / AI Adviser / Applications | ✓ |
| Adviser | Client support professional | /advisor | Adviser-specific sidebar | Dashboard / Jobs / Interviews / AI Adviser | ✓ |
| Organisation | Team and service oversight | /organisation | Independent org sidebar | Dashboard / Employer / Jobs / AI Adviser | ✓ |
| Employer | Recruitment management | /employer | Employer nav (via org sidebar) | Dashboard / Post Job / Jobs / AI Adviser | ✓ |
| Admin | Platform administrator | /admin | Admin + all tools | Admin / Dashboard / Jobs / AI Adviser | ✓ |