Internal implementation brief

From strong prototype to safe recruitment service.

This page records the audit, product strategy, information architecture, technology recommendation, MVP backlog, acceptance tests and decisions HIF must approve before launch.

Phase 1

Concise audit

Grounded in the public HIF website and selected internal governance, role, program and volunteer documents.

AreaFindingRiskResponse built or recommended
Recruitment discoveryPublic website relies on a generic contact form and an external Google Form rather than a searchable opportunity directory.HighReplace with structured opportunity records, filters, role detail pages and clear statuses.
Content freshnessPublic pages include past 2025 deadlines, “currently being updated” pages and role/team information that appears stale.HighAdd owners, review dates, evidence status and automatic expiry for time-sensitive content.
Role classificationOlder internal drafts say a salary may become available later, which can blur the volunteer relationship.CriticalUse a mandatory unpaid disclosure at every recruitment stage and obtain workplace-relations advice.
Role qualityLegacy descriptions often emphasise senior titles and broad duties without realistic hours, support, deliverables or community need.HighUse the role health gate and role template implemented in this portal.
SafeguardingThe 2023 Code of Conduct contains checks and complaint provisions but concentrates escalation around a small number of leaders.CriticalCreate independent pathways, restricted records, recusal rules and role-specific safeguards.
Applicant privacyHistorical recruitment responses are held in spreadsheets and should never be exposed through public views.CriticalMigrate only necessary active records into role-based storage; archive or delete under an approved schedule.
Candidate experienceNo reusable profile, visible status, saved roles, accessible alternative or structured acknowledgement journey is evident publicly.HighUse the applicant dashboard, progressive form and support centre implemented here.
Evidence claimsSome program pages make ambitious claims while other pages are incomplete or describe planned work as current.HighClassify every claim and attach an internal source, owner and review date.
Visual identityThe main site has authentic imagery but dense navigation, inconsistent page maturity and a student-club feel.MediumUse the calm editorial design system, modular content and evidence-first language shown here.

Retain

Authentic project photography, global-health mission, volunteer-powered identity, multidisciplinary ambition and real prevention programs.

Retire

Generic contact-form recruitment, stale deadlines, unverified scale claims, broad senior titles, private contact details and misleading future-pay language.

Build on

Cardiac pop-up clinics, sun safety, health education, student pathways, Health Challenge Rooms, sustainable healthcare, child-and-family systems research and locally led international partnerships.

Phase 2

Product strategy

A serious recruitment service, not merely a refreshed vacancy page.

Product vision

Make every volunteer role explainable from need to impact.

Applicants can discover where they fit, understand the unpaid commitment, apply accessibly and track a respectful process. Administrators can publish only healthy roles, assess against evidence, restrict sensitive data and explain every decision.

Applicant job

“Help me find a credible role that uses my skills, respects my time and shows how my contribution connects to a real need.”

Program-lead job

“Help me recruit capable volunteers without creating unsafe work, opaque decisions or administrative chaos.”

Governance job

“Help me see whether roles, decisions, access and retention comply with HIF’s stated values and obligations.”

Candidate clarity

≥90% understand unpaid status and next step

Accessibility

WCAG 2.2 AA + successful assisted journey tests

Decision quality

100% final outcomes have criterion-linked rationale

Role health

100% public roles pass mandatory safety and supervision gates

Timeliness

Immediate acknowledgement; median first review <10 business days

Trust

Track applicant satisfaction, withdrawal reasons and complaint closure

0

Phase 0 — governance gate

Approve volunteer classification, privacy, safeguarding, complaints, data retention, role publication and content ownership.

1

Phase 1 — public MVP

Launch homepage, verified opportunity directory, role pages, support, selection, safeguarding, privacy and role matching.

2

Phase 2 — applicant accounts

Add approved public identity, reusable profiles, saved roles, draft applications, secure uploads, statuses and privacy controls.

3

Phase 3 — administration

Add structured review, interviews, references, credentials, offers, onboarding, audit logs and permissions.

4

Phase 4 — learning system

Connect recruitment to role health, program need, retention, volunteer satisfaction and community benefit.

Phase 3

Information and service architecture

Public discovery, applicant work and administration are connected without sharing the same permissions.

Public portal

  • Home
  • Opportunity directory
  • Role detail
  • Compare roles
  • HIF Role Navigator
  • Volunteering at HIF
  • Selection process
  • Safeguarding and ethics
  • Applicant support
  • Privacy centre

Applicant account

  • Profile
  • Saved roles and searches
  • Draft applications
  • Submitted applications
  • Outstanding actions
  • Interviews
  • Messages
  • Talent preferences
  • Privacy and consent
  • Accessibility preferences

Administration

  • Role builder and publication gate
  • Application pipeline
  • Structured assessment
  • Interview scheduling and scorecards
  • References and credentials
  • Offers and onboarding
  • Safeguarding escalation
  • Communications
  • Analytics
  • Audit and retention
Standard workflow

Explore → profile → tailored application → completeness → structured review → interview/checks → outcome → induction

International workflow

EOI → eligibility → interview → group assessment → checks → conditional offer → training/readiness → final confirmation

Relational data model

Thirty-two core entities, separated by purpose.

Applicant, assessment, credential, safeguarding, adjustment, consent, communication and audit records are related by controlled identifiers, not collapsed into one spreadsheet.

usersapplicant_profilesvolunteer_profilesopportunitiesprogramsregionsdivisionsrole_criteriaapplication_questionsapplicationsapplication_responsesuploaded_documentsreviewer_assignmentsassessment_scorecardsinterviewsinterview_feedbackreferencescredentialssafeguarding_checksaccessibility_adjustmentsconsentscommunicationsoffersonboarding_requirementsvolunteer_agreementstalent_poolssaved_searchesopportunity_alertsaudit_logsretention_actionssupport_requestscomplaints
Phases 4–5

Implementation recommendation

Softr is suitable for a limited public MVP; sensitive end-to-end recruitment requires a stronger application architecture.

Softr-first MVP

Use for verified public content and low-risk workflows.

  • Public opportunity directory and role pages
  • Basic filters, conditional visibility and simple forms
  • Non-sensitive applicant acknowledgement
  • Limited user groups and dashboard views
  • Fast editorial adoption by a volunteer team

Complex least-privilege permissions, separate sensitive records, strong audit history, secure uploads, structured assessment, retention automation and transparent AI controls require fragile workarounds.

Permission model

Recruitment administrators manage vacancies and routine applications. Interviewers see assigned applications. Credential reviewers see identity and credential data only. Safeguarding officers manage restricted records. Program leads see their programs. Executive approvers see finalists and documented rationale. Auditors receive read-only, logged access. System administrators do not automatically receive content access.

View the admin prototype
Prioritised MVP backlog

Build safety and clarity before automation.

Priority reflects launch dependency, not technical novelty.

P0 — Launch blockers

  • Approve volunteer classification and mandatory wording
  • Name independent safeguarding and complaint pathways
  • Approve privacy notices, identity path and retention
  • Verify every role, claim, partner and program
  • Complete accessibility and permission tests

P1 — Public MVP

  • Opportunity CMS and publication gate
  • Directory, filters, compare and role pages
  • Role matching with explainable suggestions
  • Volunteering, selection, support, privacy and safeguarding pages
  • Editable communication templates

P2 — Applicant accounts

  • Reusable profile and preferences
  • Draft and submitted applications
  • Secure uploads and credentials
  • Dashboard, messages and interview dates
  • Data access, export and deletion controls

P3 — Administration

  • Structured review and reviewer reconciliation
  • Interview scorecards and scheduling
  • References, offers and onboarding
  • Audit log and retention automation
  • Ethical analytics and recruitment learning loop
Acceptance criteria

A feature is not complete because it renders.

  • Keyboard-only user can complete every public task with visible focus.
  • Screen-reader labels, headings, errors and status changes are understandable.
  • Unpaid disclosure appears on card, role, start, review, confirmation, interview and offer content.
  • No applicant can access another applicant’s record or document.
  • Recruiters cannot access restricted adjustment or safeguarding content.
  • Every selection outcome stores a human, criterion-linked rationale.
  • Every public claim has a classification, source, owner and review date.
  • Under-18 workflow uses approved consent and supervised communication.
  • International programs cannot progress without local, safeguarding and readiness approval.
  • Retention, deletion, breach and account-recovery workflows pass scenario tests.
Approval required register

Decisions the interface must not invent.

These items are intentionally visible instead of being silently filled with assumptions.

DecisionOwnerWhy requiredStatus
Volunteer classificationAustralian workplace-relations lawyerRequired before any structured role is publicly launchedBlocked
Privacy collection noticesPrivacy adviser / boardRequired before applicant accounts or submissionsBlocked
Public identity providerTechnology and privacy ownersSites starter cannot safely invent public applicant authenticationBlocked
Safeguarding reporting contactsBoard and safeguarding specialistIndependent escalation and recusal contacts are not yet approvedBlocked
Data retention scheduleLegal, safeguarding and insurance ownersRecommended periods need formal approvalBlocked
Opportunity contentProgram lead + volunteer managerDemonstration listings must be verified, dated and approvedBlocked
International program readinessCountry lead + safeguarding + boardDo not publish travel dates or accept payments before approvalBlocked
Insurance and reimbursementsOperations / insurer / boardPlain-language coverage and expense rules are neededBlocked
AI register and noticePrivacy and responsible-AI ownersControls are designed but governance owner must be namedReview
Accessibility acceptance testIndependent users and accessibility specialistRequired before public launchReview