Search should help users find the right authorized record from the information they actually have. Start with real lookup tasks rather than a generic search box requirement.
Prepared with AI assistance. These are practical scoping recommendations; examples are illustrative, not client results.
Collect search examples
Ask staff what they know when looking for a record: a partial customer name, job reference, address, or old email. Include misspellings and incomplete information in the discussion. Rank these tasks by frequency and consequence so the first release supports the most useful paths.
Design understandable results
Show enough context to distinguish similar records, such as location, status, and reference number. Avoid exposing sensitive fields just to make the results richer. If the user cannot tell two results apart, opening every record becomes another form of manual searching.
Preserve access boundaries
Search results, counts, previews, and downloadable exports should follow the same authorization rules as the underlying records. Ask the implementation team to test with different roles. A hidden navigation link does not establish that an unauthorized record cannot appear through search.
Evaluate with a task set
Prepare representative lookups with known correct results and ask users to complete them. Record failures and ambiguity rather than judging only response speed. A fast search that frequently returns the wrong customer is not operationally effective. Use the task set again when new record types or filters are introduced.
