# Job board PRD and acceptance checklist

Original sample by PlanSmith. Updated 28 September 2026.
Guide: https://plansmith.io/blog/job-board-requirements
You may adapt this document for your project.

## Decisions to complete

Audience/niche:
Problem and success measure:
Listing source:
Applications: on-site / external link
Employer registration and verification:
Moderation and abuse owner:
Free / paid listings:
Listing lifetime and expiry timezone:
Administrator applicant-access policy:
Withdrawal and retention policy:
Resume file limits and allowed formats:
Notification delivery/retry owner:
Accessibility and supported devices:
Deployment, backup and recovery owner:

## Example first-release scope

Required in this example: public published listings, search/filter, employer
accounts scoped to their organisation, moderated publication, candidate
applications and withdrawal. Review these choices before accepting them.

Optional: paid posting, saved jobs, job alerts, scoped employer exports.
Excluded: recruitment CRM, searchable resume marketplace, chat, AI matching,
multiple billing plans and automatic job scraping.

## Roles and ownership

| Capability | Visitor | Candidate | Employer | Admin |
|---|---|---|---|---|
| Read published jobs | Yes | Yes | Yes | Yes |
| Manage draft job | No | No | Own organisation | Explicit moderation scope |
| Submit/withdraw application | No | Own | No | No impersonation |
| Read application/resume | No | Own | Own job; withdrawal rules apply | Explicit logged exception only |
| Publish/reject job | No | No | No | Yes |
| Close job | No | No | Own organisation | Yes |
| Export applications if included | No | Own data if offered | Own job only | Same declared policy |

The server must enforce the matrix for every UI, API and file endpoint.

## Core records

- Organisation: ID, name, verification state.
- User and organisation membership: identity, role, organisation binding.
- Job: ID, owning organisation, title, description, location/remote policy,
  status, publication/expiry timestamps, moderation history.
- Application: ID, job ID, candidate ID, submitted timestamp, withdrawal
  timestamp, employer review state, private attachment references.
- Audit event: actor, action, record, timestamp and safe change metadata.
- Optional payment/entitlement: provider event ID, payment state, amount and
  currency, listing entitlement and the job to which it was applied.

## State rules

Job: Draft → Pending review → Published or Rejected. Rejected → Draft.
Published → Closed or Expired. Define the re-review rule for published edits.
Recheck eligibility when an application is submitted, not only on page load.

Application: Submitted → Withdrawn. Keep employer review status separate.
Choose what remains visible after withdrawal and enforce the rule on downloads.
Use a unique constraint or equivalent transaction rule for duplicate applications.

Optional paid listing: verified event → settled payment → single entitlement.
Duplicate events must be safe. Payment success does not bypass moderation.
Define refund, chargeback, expiry and failed publication behavior explicitly.

## Acceptance record

For each row fill Result with Pass, Fail or Not tested, and attach evidence.

| ID | Scenario | Expected result | Result / evidence |
|---|---|---|---|
| JB-01 | Employer A creates Job A | Saved draft visible to A after reload | |
| JB-02 | Employer B reads/edits Job A draft | Denied in UI and direct API | |
| JB-03 | Visitor searches listings | Only published, eligible jobs returned | |
| JB-04 | Admin rejects and employer revises | History retained; resubmission works | |
| JB-05 | Candidate One applies to Job A | One saved application; clear confirmation | |
| JB-06 | Owning employer reads application | Succeeds as control for isolation tests | |
| JB-07 | Other employer/candidate/visitor requests record and resume | Denied without applicant data | |
| JB-08 | Same submit is repeated | No duplicate application | |
| JB-09 | Job closes while application form stays open | Server rejects the later submission | |
| JB-10 | Candidate withdraws | Chosen visibility/retention rule applies to all endpoints | |
| JB-11 | Optional export with another organisation's ID | Denied; own export uses same filters as screen | |
| JB-12 | Optional payment event arrives twice | One payment effect and one entitlement | |
| JB-13 | Optional refund after publication | Documented refund policy applied once | |
| JB-14 | Narrow screen and keyboard-only workflow | Forms, errors, focus and core actions usable | |
| JB-15 | Restore database and private files to separate environment | Relevant job/application history recoverable | |
| JB-16 | Repeat core journeys against deployment URL | Live results recorded separately from local results | |

## Release record

Revision:
Local commands and results:
Preview URL and checks:
Production URL and checks:
Untested paths:
Known limitations:
Rollback revision/procedure:
Operational owner:

## Supporting evidence

PlanSmith's job-board benchmark documents tested isolation boundaries and review
limits, not a blanket production certification:
https://plansmith.io/benchmarks/job-board
Build sequence: https://plansmith.io/blog/how-to-build-a-job-board-with-ai
