Skip to contentLaunch price30% off every kit for the first 250 buyers155 left
DirectoryLab

Loading the guides…

Job LabGuides
Start here

A tour of the admin

What the Control Panel tells you, what every item in the sidebar is for, who is allowed to open what and the General settings field by field.

Updated 9 Oct 2026 · written for Job Lab 1.1.0

On this page

Go to /admin and sign in, or choose Admin Panel from the menu under your name at the top of the site. Every screen is opened from the sidebar on the left, which has fourteen groups. The first screen is the Control Panel, and it is where you find out what needs you today.

The Job Lab admin Control Panel: a Needs your attention box listing jobs awaiting moderation, reported jobs, company reviews and paid ad orders to review, beside a Health: Healthy badge, then tiles for monthly recurring revenue, revenue this month, AI spend against a 40 dollar budget, 98 users and 420 jobs
The admin control panel.

A group in the sidebar opens when you click it and closes when you open another. The group that holds the screen you are on stays open. At the foot are Back to App, which returns to the public site, and Sign Out. The guides name a screen by its group and its item: "Plans under Monetization".

The Control Panel#

What needs you#

The box at the top gathers every queue in the admin that is waiting for a decision. Its heading is one of four:

HeadingIt means
Action neededSomething is broken: a health check is critical, or there is an incident in the list.
Needs your attentionSomething is waiting for you, or a health check is on a warning.
All systems healthyNothing is waiting and every check passes.
Not checked yetThe health check has not run on this install.

Underneath, the waiting items are grouped as Incidents, Approvals and Triage, each with a count. There are seventeen kinds, among them Jobs awaiting moderation, Reported jobs, Company reviews to moderate and Paid orders awaiting review. A kind with nothing waiting is left out. Click a line to open the screen where you deal with it. With nothing waiting, the box reads "You're all caught up".

The six tiles#

TileWhat it showsOpens
MRRWhat your active subscriptions pay each month, and how many there are.Monetization, Overview
Revenue this monthPayments taken this month.Monetization, Overview
AI spend (MTD)What AI calls have cost this month, against your monthly budget if you set one.Cost & Usage under AI
AI projectedWhere the month will end at the current rate of spending.Cost & Usage under AI
Total UsersEvery account, with how many joined this week.All Users
JobsEvery job, with how many are published.All Jobs

Until Stripe is connected the first two tiles read Connect Stripe, and until an AI key is saved the next two read Set up AI.

The launch checklist#

Once the setup wizard has been finished, a Launch checklist sits under the top box, with a count such as "3/8". Each line ticks itself when the thing is done, and clicking a line opens the screen where you do it.

The Launch checklist on the Control Panel: a count of lines done out of eight, with ticked and open lines for indexing, the real domain, job sources, email, AI, Stripe, a support email and legal details, and links to re-run the setup wizard or dismiss the list
The checklist ticks itself off as you get ready to launch.
LineTicked when
Turn on search-engine indexing at go-liveIndexing is switched on under SEO, Settings.
Point the site at its real domainThe site's address, NEXT_PUBLIC_APP_URL in .env, no longer contains "localhost".
Job sources fetching on scheduleAt least one source is switched on and the scheduler can be reached.
Connect email (SMTP)An SMTP host is saved.
Add an AI providerAn AI key is connected.
Connect StripeA Stripe secret key is saved.
Set a support emailSupport Email is filled in under Settings, General.
Fill in your legal detailsCompany or legal name is filled in under Settings, Legal Pages.

Email, AI and Stripe are marked optional on the list. Re-run setup wizard opens the wizard again.

The rest of the page#

The lower half of the Control Panel: Latest Syncs listing each fetch with how many jobs were new and how many were already on the board, a bar chart of jobs ingested per day over the last 14 days, and the next scheduled tasks under Automation
Jobs arriving from feeds and company hiring systems, fetch by fetch.
  • Five counters: Companies, Applications, Ingestion Sources, Pending Raw Jobs and New Jobs (7d).

  • Latest Syncs: the last eight lines of the ingestion log.

  • Jobs Ingested: new jobs for each of the last 14 days.

  • Automation: the next five scheduled tasks, with the runs and failures of the last 24 hours.

  • Source Health: up to ten sources, each with its status and when it last ran.

  • Quick Actions: five shortcuts.

System Health#

Open System Health under Overview. A banner reads "All systems go", "Attention needed" or "Action required", above six cards of checks: Infrastructure, Automation, Job pipeline, Search integrity, Content engines and Comms & integrations. Re-run checks runs them again on the spot. The same checks run by themselves every 30 minutes, and their result is the Health badge on the Control Panel. Backups, scheduled tasks and health goes through each check and the thresholds at the foot of the page.

The sidebar, group by group#

Overview, Users & Auth and Security#

ItemWhat it is forGuide
Control PanelThe page above.
System HealthEvery check on the services, the tasks and the job pipeline.Backups, scheduled tasks and health
All UsersEvery account, with its role.Users and roles, below
Security: Overview, Sessions, Event Log, SettingsSign-ins, signed-in devices, the audit trail and the lockout rules.Security, below

Job Board and Blog#

ItemWhat it is forGuide
CompaniesEvery company on the board, whether an employer made it or a source brought it in.Employers, applications and moderation
All JobsSearch, filter and manage every job.Employers, applications and moderation
ApplicationsEvery application made through the site.Employers, applications and moderation
Skills, Roles, LocationsThe lists that jobs are sorted by, with their other names and groupings.Skills, roles and locations
All Posts, Categories, TagsThe blog.Market stats, tools, blog and embeds

Ingestion and Tools#

ItemWhat it is forGuide
SourcesThe feeds your jobs come from, with their health and schedules.Add job sources
Board ScopeThe filter that decides which incoming jobs belong.Board scope and the raw jobs queue
Raw Jobs QueueJobs as they arrive, and why any were rejected.Board scope and the raw jobs queue
LogsWhat every fetch did.Add job sources
Search IndexThe state of the job search index, with a button to rebuild it.
TaggingHow jobs get their skills and role, and a place to fix them by hand.Skills, roles and locations
Scheduled TasksEvery recurring task: when it last ran, when it runs next and how often.Backups, scheduled tasks and health
Email ManagerDelivery status, templates, test sends and the log of what was sent.Email that arrives
ModerationJobs held for review, jobs visitors reported and the rules.Employers, applications and moderation
ReviewsCompany reviews waiting for approval.Employers, applications and moderation
TelegramA bot that sends you alerts.Telegram alerts and Google sign-in

Insights, Analytics and AI#

ItemWhat it is forGuide
Insights: Overview, Stat Pages, Reports, Tools Usage, Compute Runs, Data Export, SettingsThe market statistics: when they were last worked out, which pages are published and how much data a page needs.Market stats, tools, blog and embeds
NewsletterWhat went out, what goes out next and how subscribers responded.The weekly newsletter
DistributionNewsletter subscribers and a log.The weekly newsletter
Analytics: OverviewTraffic figures from Google Analytics.
Analytics: Search ConsoleWhat people search for to find the board, and which pages rank.SEO: landing pages, indexing and Search Console
Cost & UsageEvery AI call the board makes and what it cost.AI: providers, curation and cost

Monetization#

ItemWhat it is forGuide
OverviewRevenue at a glance, and whether Stripe is connected.Connect Stripe
PlansWhat each employer plan costs and includes.Sell employer plans
Featured JobsThe price of a featured job and the credit bundles.Featured jobs and credit bundles
Advertising OrdersWhat the advertising shop sells, and the orders waiting for you.The advertising shop
Sponsors, AdvertisingSponsors you add by hand, banners and ad network code.Sponsors, banners and AdSense

Appearance, SEO and Settings#

ItemWhat it is forGuide
Appearance: Theme & Fonts, Branding, Homepage, Sidebars, Feeds, Navigation & FooterColours, logo, the sections of the home page, the sidebars, how lists are laid out, the menu and the footer.Make it your niche
SEO: Overview, Landing Pages, Generation, Metadata Audit, SettingsGenerated landing pages, page titles and the switch that lets search engines in.SEO: landing pages, indexing and Search Console
GeneralCurrency, limits and how long things are kept.Settings, General, below
Integrations & SecretsThe keys for Stripe, email, AI, Google and error tracking.Connect Stripe, Email that arrives
Legal PagesYour Terms of Service, Privacy Policy and Cookie Policy.
API KeysCreates keys that nothing accepts yet.What is not in it
Setup WizardOpens the wizard again.The setup wizard, step by step

Users and roles#

Open All Users under Users & Auth. It counts Total Users, Employers and Seekers, and lists accounts 50 to a page, newest first, with a search by name or email.

The All Users page: 98 users, of whom 25 are employers and 72 job seekers, a search box, and a list giving the role of each person and when they joined or were last active
Admin, Users

Every account has one of four roles:

RoleWhat it can do
Job SeekerBrowse and apply, and keep résumés, saved jobs and alerts.
EmployerPost jobs and manage companies and applicants.
Guest Admin (read-only)See the admin and change nothing.
AdministratorEverything, settings and keys included.

People choose Job Seeker or Employer themselves when they register. The two admin roles are given by you. There is no "add user" button, so to make a second admin the person registers first.

  1. Step 1: Have them create an account

    They register on your site in the ordinary way.

  2. Step 2: Find them in All Users

    Search for their name or email.

  3. Step 3: Change the role

    Click Actions on their row and, under Change role, choose Make Administrator.

  4. Step 4: Have them sign out and in again

    The new role applies the next time they sign in.

The Actions menu also has View profile, Log out everywhere and Delete user. The rest is on the account's own page, which opens when you click the name:

  • Access & Role: the same change of role, with Save Role.

  • Send password reset: emails the person a link to set a new password. With no email set up you see "SMTP is not configured — the reset link was written to the server log."

  • Mark email verified: shown only for an account that is not verified. Use it when the verification email never arrived. Until an address is verified, an employer cannot post and a job seeker cannot apply.

  • Suspend account: type a reason if you want one, then Confirm suspension. The person is signed out everywhere and cannot sign in. Lift suspension undoes it.

  • Delete User, under Danger Zone: removes the account and everything attached to it, and cannot be undone.

You cannot change your own role, suspend yourself or delete yourself, so a site always keeps one administrator.

The read-only guest admin#

A guest admin is for showing the admin to someone, such as a person thinking of buying the site, without letting them change it. Their sidebar says Read-only under the site's name, and email addresses are masked, for example j•••@e•••.com.

A guest does not see Security, Monetization or Settings at all, nor Tagging, Scheduled Tasks, Email Manager and Telegram under Tools. Opening one of those screens by its address sends them to the home page, with the one exception in the note below. Whatever a guest presses anywhere else, nothing is saved.

Make one from Actions, Make Guest Admin (read-only), or create the account from the terminal in the Job Lab folder:

Terminal
DATABASE_URL=postgres://joblab:joblab@localhost:5433/joblab pnpm tsx scripts/make-guest-admin.ts [email protected] a-strong-password

If the email already has an account, that account becomes a guest admin and the password is ignored. Never give it your own email: your administrator account would become a guest. The address in front is the database on your own computer. On a server, use the DATABASE_URL from that server's .env.

Security#

Open Overview under Security.

The Security page with a green No security incidents banner: tiles for active sessions, logins, failed logins, lockouts, signups and password resets in the last 24 hours, a list of security checks all passing, and the addresses and accounts with the most failed logins
Admin, Security
  • Overview has a banner, "No security incidents", "Worth a look" or "Attention required", then counters for the last 24 hours and a list of Security checks. One of them, Guest (read-only) admin access, stays on a warning for as long as any guest admin exists.

  • Sessions lists every signed-in device. Actions on a row offers Revoke session and Log out user everywhere. Log out all users signs out everyone on every device except the one you are using.

  • Event Log is the record of every sign-in, failed sign-in, lockout and admin action. Filter it by Logins, Account, Admin actions or Incidents, or search by email or IP address.

  • Settings holds the numbers:

SettingStarts as
Lock after … failed logins, …counted within … minutes5 within 15 minutes
Lock for15 minutes
Spike alert at … failed logins per hour20. Type 0 for off.
Re-check every … seconds60. This is how long a revoked session can go on working.
“Online now” within15 minutes
Keep events90 days
Keep old sessions30 days

Telegram me when an admin signs in is off to begin with. The lockout and the rate limits are counted in Redis: while Redis cannot be reached, sign-in still works and neither is applied.

Settings, General#

Open General under Settings. Feature Status at the top is four read-only lines saying whether an AI provider, Google sign-in, email and error tracking are set up. Platform Settings is the form:

FieldStarts asWhat it does
Support EmailEmptyShown on the advertising page as the contact address, and told when an advertising order is paid.
Site CurrencyUSDThe one currency for every price you sell: plans, featured jobs and advertising.
Max Jobs Per Company50An employer cannot add a job to a company that already has this many, closed jobs included.
Imported Job Expiry (days)45How long an imported job stays up. 0 means it never expires.
Applications Per Job Limit500Nothing. See the note below.
Raw Job Retention (days)90How long processed records from sources are kept, so that the same job is not imported twice.
Log Retention (days)30Older ingestion and distribution logs are deleted.
Job View Retention (days)180Older records of job page views are deleted. 0 keeps them for ever.
Feed Grouping: Max Cards Per Company3On each page of results, further jobs from the same company fold away behind a "more roles" link. 0 shows everything.

Click Save Settings and you see "Settings saved successfully." A box you empty goes back to its starting value when you save. The site's name is not here: it is under SEO, Settings.

Danger Zone at the foot has two buttons. Reindex rebuilds the job search index from the database. Clear Queue deletes every raw job that is still waiting to be processed, and cannot be undone.

The admin keeps sending me to the setup wizard

Opening /admin does that until the wizard has been finished or skipped. Finish it, or click Skip setup for now at the foot of any step from 2 to 8.

I dismissed the launch checklist. How do I get it back?

You cannot. The eight lines and where each is done are in the table above.

I changed someone's role and nothing happened

The account's page says it when you save: "Saved. The new role applies the next time this user signs in." Ask them to sign out and in again.

A guest admin was sent to the home page

They opened a screen that is locked to administrators, or pressed a button that saves. Nothing was changed.

Someone sees "Too many failed attempts — this account is temporarily locked."

Five wrong passwords in 15 minutes lock an account for 15 minutes, unless you changed the numbers under Security, Settings. The lock lifts by itself when the time is up.

Stuck on a step? Send a message.