Applications And Review
Configure Application Questions
Open Applications → Configurator. This route needs the community_application_fields feature and checks all four field keys at entry: application-fields:read, application-fields:create, application-fields:update, and application-fields:delete.
Add, change, reorder, or delete the questions applicants see. Each question uses the same field model as forms: choose a type, label, help text, required state, options where applicable, and validation rules. Changes are saved through their corresponding field action; Reset discards unsaved local edits before leaving.
Do not alter a live recruitment question casually. Agree the replacement wording, then test a submission with a non-production account.
Configure Application Statuses
Open Applications → Statuses. This route requires community_application_submission_status and application-submission-statuses:read.
| Control | Result | Permission checked by C2 |
|---|---|---|
| Create | Adds a review stage. | application-submission-statuses:create |
| Edit | Changes a stage. | application-submission-statuses:update |
| Make default | Makes a stage the starting status for new applications. | application-submission-statuses:update |
| Delete | Removes a stage. | API-derived application-submission-statuses:delete; verify with a test role because the route does not make a literal delete check. |
Create statuses before opening recruitment. The default status becomes the starting point for new applications, so make it an unambiguous intake state such as New.
Submit An Application
The applicant route loads questions with application-fields:read; it requires community_application_submissions. Complete every required question and submit. The C2 page does not expose a literal permission guard for the submit action; the generic submission API derives applications:create.
Verification required: test applicant-facing submission with the intended role and feature set. Do not grant broad staff access merely to work around a failed application form; missing questions, a required-field error, and a plan limit are separate failures.
Review An Application
Open Application Center and select a submission. C2 requires applications:read and application-submission-statuses:read to enter the centre. It loads additional sections only when the reviewer has their matching read permission.
| Control or data | Permission evidence | Notes |
|---|---|---|
| Open centre and submission | applications:read | C2 route guard. |
| View configured questions | application-fields:read | C2 loads fields only with this key. |
| Load status choices | application-submission-statuses:read | C2 loads statuses only with this key. |
| Update status | API-derived applications:update | Button is not guarded by a literal C2 can check; test before defining reviewer roles. |
| Read comments | application-comments:read | C2 loads comments only with this key. |
| Post comment | API-derived application-comments:create | Use factual internal notes for the next reviewer. |
| Delete a comment | API-derived application-comments:delete | Verify the deployed UI/action before role design. |
| Delete application | API-derived applications:delete | Permanently removes the submission and its comments after confirmation. |
| Message applicant | No application permission check identified | Creates a C2 communications thread; unavailable if there is no linked user, the applicant is the current user, or the profile cannot load. Test comms access separately. |
Write comments for the next reviewer: what was checked, what needs follow-up, and who owns it. Do not put sensitive information in a comment unless the community policy permits it.
Access Checklist
| Job | Minimum known keys |
|---|---|
| Application configurator | all four application-fields:* keys |
| Status manager | application-submission-statuses:read, :create, :update; add :delete only when authorised |
| Application reviewer | applications:read, application-fields:read, application-submission-statuses:read, applications:update, application-comments:read, application-comments:create |
| Recruitment owner | Reviewer keys plus applications:delete; add comment/status deletion only when necessary |
Related: Forms And Form Responses, Personnel Workflows, and Logs And Audit Trails.