Projects and partners

Before you accept the finished store

Compare the written scope you already have with what you can sign into and see. You should be able to administer the site, see orders if the store uses WooCommerce, and control the payment account through your own user rather than a shared password. Secret and restricted payment keys are not safe to leave in someone else's hands or in the page. Acceptance is your decision against that evidence. It is not a provider's decision to process the account, and a Prism review is not a certificate that the project is complete.

For: An owner or authorized representative of a research-use-only peptide business deciding whether delivered website work matches the scope already agreed with an implementer.

Updated 2026-09-21

Acceptance uses the contract you already signed

The scope is the written list of work the implementer agreed to deliver. This page cannot supply that list. Put each delivered item next to a line in that document: done and visible, done with a named defect, or not delivered. A redesign that was only proposed, or a processing change that was sequenced separately, is not part of this acceptance unless the written scope includes it.

Hiring an implementer is an earlier decision. Accepting the work is the later one. Do not treat a polished homepage as proof that checkout, accounts, and handover were finished.

You should hold the accounts, not a screenshot of them

WordPress uses roles to control what a user can do. An administrator has access to all the administration features within a single site. A lesser role does not. Confirm that a user you control has the role the site needs, and that you can sign in without asking the implementer to share a password.

WooCommerce says orders are visible to users with the administrator or shop manager role. If the scope included the store, sign in as a user you control and open the order list. A video of someone else's screen is not the same as your own access.

Stripe's team settings let the account invite members, assign roles, and send those invites by email. Invites expire after 10 days. Stripe says to grant the lowest permission the person needs. That is the handover for a Stripe account: your own user, with a role you understand, not a shared login.

Stripe's API key page says a publishable key may be used in front-end code and cannot create charges or read account data. A restricted key and a secret key are not safe to expose. A secret key has unrestricted permissions, and Stripe says it does not recommend secret keys for new use cases. Ask where live keys are stored, who can reveal or rotate them, and remove any key the implementer no longer needs. Do not paste a secret or restricted key into email or the consultation form.

Visible checkout behavior, without a fake order

For each checkout item in the written scope, record what a visitor can see and what the admin screen shows: the payment method listed, the return page if the scope uses a hosted checkout, and the order status path the platform documents. If the contract requires a test payment, use the provider's own test mode and keep the resulting payment reference. Do not invent an order, a card number, or a buyer to make the sheet look complete.

Stripe says a Checkout success URL is where the customer is sent after a successful payment or subscription creation, and also says you cannot rely on the customer reaching that page to fulfill an order. If hosted checkout is in the scope, the handover should include the success and cancel URLs that were configured and the event the integration uses to record payment. Accepting a page that says the payment succeeded, without that provider record, accepts a screen rather than the integration.

Unresolved defects stay on the list with an owner and a date. Closing them in the acceptance note, while the behavior is still wrong, does not finish the work.

What acceptance does not decide

You can decide whether the delivered items match the written scope, whether you control the site and payment users, and which defects remain open. The implementer or the host has to hand over access they still hold. The payment provider decides eligibility, price, reserves, and account status. Accepting the website does not open or keep a processing account.

Prism's public support is a consultation: a review of website content, preparation for a card-processing review, or help with a provider's website questions. Scope, fees, and terms are discussed before that work. A review is informational. It is not a legal opinion, a compliance certification, or an acceptance certificate for the implementer's project.

Whether a particular plugin, host login, or domain registrar is included in your contract is unknown until that contract says so. Leave it off the acceptance list rather than assuming the implementer transferred it.

Handover comparison

Use the written scope and the accounts you can open. Never enter passwords, secret keys, restricted keys, or other credentials in this worksheet. Record only the authorized role and the name of the secure storage system. Worksheet entries are not submitted by this worksheet or saved by this site. Use only non-sensitive summaries; do not enter credentials, government identifiers, card or bank-account numbers, private receipt links, or customer details.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Handover comparison. The last column is for temporary notes.
Handover itemWhat you are checkingWhere you can see itYour finding
Written scope lineAcceptance compares delivered work with the agreement you have. A general impression of the design is not a line in that agreement.The contract, statement of work, or change note you already signed.
Site administrator you controlWordPress gives an administrator all administration features on a single site. A lesser role, or a login only the implementer knows, is not a completed handover.Users in the site admin, signed in as your own user.
Store orders, if the scope includes the storeWooCommerce shows orders to administrator and shop manager roles. You should open that list yourself.The store order screen after you sign in.
Payment-account userStripe team invites give a named person a role. A shared password does not show who did what, and Stripe logs team-member activity.The provider's team or user list, with your own user present.
API keysStripe says restricted and secret keys are not safe to expose. The publishable key is the one that may appear in front-end code.The provider's key page and the place the site stores server-side keys. Record the key type, not the key.
Checkout behavior named in the scopeRecord the payment method, return URLs, and a real or provider-test payment reference if the contract required one. Do not create a fictional order.The live or test checkout and the provider payment it produced.
Open defectsAn item that does not match the scope stays open, with an owner. Marking the project accepted does not close it.The defect list tied to a scope line.

These are temporary notes. Leaving or reloading this page may clear them. The consultation form does not include these entries.

Limits

  • A Prism consultation can help you organize the facts and discuss the website or processing question. The payment provider decides eligibility, pricing, reserves, and whether an account is opened or closed.
  • WordPress, WooCommerce, and Stripe access rules apply to those products. Another platform's roles and keys need that platform's current document.
  • Accepting the project does not approve processing, set a fee, or certify the site.
  • Do not send passwords, secret keys, restricted keys, or customer lists through the public consultation form.

Sources checked 2026-09-21

  • WordPress roles and capabilities — checked 2026-09-21. WordPress roles control what users can do. An administrator has access to all the administration features within a single site.
  • WooCommerce managing orders — checked 2026-09-21. Orders are visible to users with the administrator or shop manager role.
  • Stripe API keys — checked 2026-09-21. A publishable key may be used in front-end code and cannot create charges or read account data. Restricted and secret keys are not safe to expose. Secret keys have unrestricted permissions.
  • Stripe teams — checked 2026-09-21. The account owner invites team members, assigns roles, and should grant the lowest permission needed. Invites expire after 10 days. Stripe logs team-member activity.
  • Checkout Session object — checked 2026-09-21. The success URL is where Stripe sends the customer after a successful payment or subscription creation. The cancel URL, when set, is where the back button sends a customer who cancels and returns.
  • Fulfill orders with Checkout — checked 2026-09-21. Stripe says fulfillment cannot rely only on the customer reaching the checkout landing page, because the customer may not visit it.
  • Prism features — checked 2026-09-21. A review reflects the agreed scope. It is informational, not a legal opinion or a compliance certification. The provider determines eligibility and account terms.
  • Prism solutions — checked 2026-09-21. Public support is a website-content review, card-processing preparation, or help with a provider's website questions. Scope, fees, and terms are discussed before work.

Request a consultation

Describe the business and this specific question. Prism follows up by email to discuss fit and scope. An inquiry is not a processing application or an approval.