Projects and partners

Merchant and agency responsibilities during a checkout change

The business the provider will review keeps the payment relationship, and a person at that business keeps the authority to approve content and to approve deployment. An implementer can receive a WordPress role or, where the provider allows it, a limited role on the payment account. Holding a login does not make the implementer the merchant. You can name the owner of each row from your own agreements. The provider decides eligibility and account status. Do not share the merchant's password, hand over a secret API key, or open an account in the implementer's name to stand in for the business. Describe the work you need. Prism will confirm scope, responsibilities, fees, and terms before work begins.

For: An owner of a research-use-only peptide business, or that owner's authorized representative, who is assigning work for one checkout change.

Updated 2026-09-21

The business being reviewed stays the payment customer

Stripe's setup documentation says the account is verified with information about the business, the product, and the person's relationship to that business. After a live Stripe service is activated, the business origin country cannot be changed. Public business information, including the business name, website, support contacts, and statement descriptor, is what customers see. That information has to identify the business. An implementer's company is a different fact from the merchant's legal entity.

Stripe also says that a new account does not inherit a special status from an existing account, and that each account is associated with the tax ID and legal entity of one business. Creating an account in an agency's name would describe the agency, not the merchant. This page does not say an agency can never receive a delegated role. It says the role is access to the merchant's account, not a transfer of the underwriting relationship. If the provider is not Stripe, ask that provider in writing who must be the contracting party. Do not copy Stripe's account model onto a contract you have not read.

Give WordPress the capability the task needs

On a single-site WordPress install, an Administrator can install and update plugins, switch themes, manage settings, and manage users. An Editor can publish and manage content, including other users' pages, and cannot install plugins. WooCommerce shows orders to Administrator and Shop Manager users. A checkout change that installs or updates a payment extension needs someone who can perform that installation. Order follow-up during the change does not require the same person to be able to install plugins or edit users.

You decide who receives which role. The implementer can be a user on the merchant's site for the tasks in the contract. The merchant should keep at least one Administrator the business controls. A shared password hides which person made a change. It is not a substitute for a role.

Payment access is an invitation, not a key in a message

Stripe lets the account invite a team member by email and assign a role. The documentation says to grant the lowest permission the job needs, and to review what that role can and cannot do before sending the invite. The account-setup page says not to share the password and to keep secret API keys confidential. The API-key page says not to share secret or restricted keys by email or chat.

A checkout implementer may need a limited payment-account role to place a test configuration. That need is written down before the invitation is sent. It is not a reason to give the implementer the account owner's password, and it does not let the implementer decide whether the provider will keep the account. Another provider may not offer the same roles. If you cannot find a delegated-access document for that provider, leave the access method unknown and ask the provider.

Content approval and deployment approval are different people or the same person on purpose

Product descriptions, policies, and the public business name are content. Installing a plugin, switching a checkout block to the classic shortcode, or updating WordPress is deployment. WordPress already separates edit and publish capabilities from install-plugin and update capabilities. Name the person who may approve each one. They can be the same person. The sheet should say so, rather than leaving both boxes with the agency's name by default.

You can fill the owner of every row you know and leave the others blank. The implementer owns only the tasks the contract assigns. The provider owns eligibility, price, reserves, and account status. A Prism consultation can discuss the storefront and the provider's website questions. Confirm the authorized account role and any checkout implementation responsibilities; agree fees and scope before work. A review is not a compliance certification.

Checkout-change responsibility worksheet

Write the name of a real person or firm in the last column, or leave it blank if the agreement does not name them. Do not enter passwords or API keys. Worksheet entries are not submitted by this worksheet or saved by this site. Use only non-sensitive summaries; do not enter credentials, government identifiers, card or bank-account numbers, private receipt links, or customer details.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Checkout-change responsibility worksheet. The last column is for temporary notes.
ResponsibilityWhy it stays separateWhere that authority is recordedNamed owner
Business the provider reviewsThe provider verifies a business. An implementer's legal entity is not that business unless the contract and the provider both say so, which this page does not assume.The formation document and the provider account's business details.
Payment-account accessAccess is a role on the merchant's account. For Stripe, the account owner invites a team member and is told to grant the lowest permission required.The provider's team or user list. Leave blank if that provider has no delegated-access document you have read.
WordPress administratorA single-site Administrator can install plugins, switch themes, manage settings, and manage users. The business should keep one Administrator it controls.The WordPress Users screen.
Order support during the changeWooCommerce shows orders to Administrator and Shop Manager users. Seeing orders does not require permission to install plugins.The WordPress role assigned to the support user.
Content approverProduct descriptions, policies, and the public business name are what a provider can compare with the application. Someone at the business approves them.The contract, or a written note of who may publish content.
Deployment approverInstalling a plugin, changing the checkout type, or updating WordPress is a separate capability from editing a page.The contract, or a written note of who may make those changes on the live site.
Implementer tasksThe implementer owns the tasks the proposal lists, such as a named plugin or checkout-page change. Unlisted tasks are not included.The proposal or statement of work.
Escalation contactA live checkout problem needs a named person at the business and a named person at the implementer. A shared inbox with no owner is not an escalation path.The support clause in the contract.

These are temporary notes. Leaving or reloading this page may clear them. The consultation form does not include these entries.

Limits

  • A Prism consultation can help you organize the facts and discuss the website or processing question. The payment provider decides eligibility, pricing, reserves, and whether an account is opened or closed.
  • Do not share the merchant password, impersonate the merchant, or open a replacement payment account in the agency's name.
  • Stripe's team and account rules are Stripe's. They are not a description of every provider, and they are not a processing approval.
  • Do not send credentials through the public form.

Sources checked 2026-09-21

  • Stripe account setup — checked 2026-09-21. Stripe verifies the business, product, and the person's relationship to the business. The business origin country cannot be changed after a live service is activated. Public business information identifies the business. Team invitations replace password sharing, and secret keys stay confidential.
  • Stripe multiple accounts — checked 2026-09-21. A new Stripe account does not inherit a special status from an existing account. Each account is associated with the tax ID and legal entity of one business.
  • Stripe teams — checked 2026-09-21. The account owner invites team members by email, assigns roles, and is told to grant the lowest permission the job requires.
  • Stripe API keys — checked 2026-09-21. Secret and restricted API keys must not be shared over email, chat, or other unencrypted channels.
  • WordPress roles and capabilities — checked 2026-09-21. A single-site Administrator can install and update plugins, switch themes, manage options, and manage users. An Editor can publish content and does not receive those installation capabilities.
  • WooCommerce managing orders — checked 2026-09-21. Orders are visible to users with the Administrator or Shop Manager role.
  • Prism solutions — checked 2026-09-21. The provider sets document requirements, assesses eligibility, and decides account terms. Prism discusses scope, fees, and terms before work.
  • Prism features — checked 2026-09-21. A website review is informational. It is not a legal opinion or a compliance certification, and it does not guarantee approval or continued processing.
  • Prism contact — checked 2026-09-21. A consultation request does not book an appointment, purchase a service, or submit a processing application. Card details, passwords, and customer records are left out.

Request a consultation

Describe the business and this specific question. Prism follows up by email to discuss fit and scope. An inquiry is not a processing application or an approval.