Accounts the business must hold when a website contractor leaves
List the accounts the business can already sign in to, and treat every other login as unresolved. On a single-site WordPress install, an Administrator can manage users, plugins, themes, and settings. A contractor with that role can change the store, but the role is not proof that the contractor's email address owns the business. WooCommerce REST API keys belong to a WordPress user and can be revoked in the store. A Stripe account is a different login: team members are invited from the Stripe Dashboard, and an invite expires after 10 days. If the business cannot sign in, use that service's own recovery process. This page does not provide password resets or a way around a lockout, and replacing the contractor does not move the payment account. Describe the work you need. Prism will confirm scope, responsibilities, fees, and terms before work begins.
For: An owner or authorized representative of a research-use-only peptide business replacing a website contractor while the store platform itself stays in place.
Updated 2026-09-21
The website login and the payment login are different
WordPress assigns capabilities by role. An Administrator on a single site has the administration features for that site, including plugins, themes, users, and options. An Editor can publish and manage content but does not, by the default role, manage plugins or users. Upon installation, WordPress creates an Administrator account. The business should know which email addresses still have that role.
The WooCommerce Stripe extension connects a Stripe.com account to the store. WooCommerce's own documentation says its support covers the extension on the site, and that Stripe account questions, including onboarding, verification, and Dashboard settings, go to Stripe. A contractor who can edit the website cannot, on that fact alone, administer the Stripe account.
Changing contractors while staying on the same store is not a platform migration. The database, orders, and payment connection can remain where they are only if someone the business authorizes can still open them.
Keys and team invites are revocable access, not ownership
A WooCommerce REST API key is created for a selected WordPress user, with Read, Write, or Read/Write permission. The consumer secret is shown once. The key list includes Revoke. Revoking a key stops that integration. It does not transfer a domain or a Stripe account. Someone who already has legitimate WooCommerce settings access can do it. Someone who does not should not try to reach those screens another way.
Stripe team access starts from the Team tab. An existing member who can manage the team adds an email address, chooses roles, and sends an invite. Stripe says to grant the lowest permission the person needs, and that invites expire after 10 days. After acceptance, the role can be edited. That invite is not the contractor's WordPress password, and the WordPress password is not a Stripe invite.
Paid extensions downloaded from a WooCommerce.com account, such as the checkout add-ons extension's documented download path, stay with the WooCommerce.com account that can open them. The free Stripe extension can instead be installed from the WordPress plugin screen. Record which pattern each plugin actually uses instead of assuming one owner for all of them.
Unresolved access stays unresolved
If the business already has an Administrator, the practical work is a user list: who can manage options, who holds API keys, and which of those people will remain. Removing a former contractor is ordinary user administration by someone who already has that authority.
If nobody at the business can sign in, stop. This page does not describe password resets, database edits, or other ways to enter an account. Use the recovery process published by the host, the registrar, or the payment provider for an account the business legitimately owns, and record the request as unresolved until that process finishes.
Domain and hosting logins are part of the inventory, but their transfer rules are whatever that registrar or host publishes. They are not WordPress roles, and they are not restated here.
What the consultation can and cannot take over
You can decide which accounts the business must hold in its own name before the contractor's access ends, and which rows are still blocked. You can bring the public site and that access question to a Prism consultation. Prism's public work is a storefront review, preparation for a processing conversation, or help with a provider's website questions. Scope, fees, and terms are discussed before work.
The payment provider decides who may be a team member and whether the account remains open. Use each service’s authorized access and recovery process. Confirm any assistance and the business’s account ownership before work.
Unknown until the screens are opened: which email is the WordPress administrator, which WooCommerce.com account can update paid plugins, and which Stripe user can send a team invite. A contractor's statement that they will send it later is not the same as access you have tested.
Account-ownership inventory
Enter only accounts the business can open or that a written agreement names. Write unresolved where a login is missing. Do not store passwords in this table. Worksheet entries are not submitted by this worksheet or saved by this site. Use only non-sensitive summaries; do not enter credentials, government identifiers, card or bank-account numbers, private receipt links, or customer details.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Account-ownership inventory. The last column is for temporary notes.
Account
Why the store stops without it
Legitimate access to confirm
Your record
WordPress administrators
Why the store stops without itAn Administrator on a single site can manage users, plugins, themes, and settings. A contractor role is access, not the business.
Legitimate access to confirmUsers list. Confirm at least one administrator uses an email the business controls.
WooCommerce REST API keys
Why the store stops without itEach key belongs to a WordPress user. Revoking it stops that connection. The secret is not shown again.
Legitimate access to confirmWooCommerce, Settings, Advanced, REST API. Record the description and user, not the secret.
Stripe team, separate from WordPress
Why the store stops without itTeam members are invited in the Stripe Dashboard. Invites expire after 10 days. The website login does not grant this.
Legitimate access to confirmStripe, Settings, Team, opened by someone who can already manage members. Leave unresolved if no one can.
Stripe account questions
Why the store stops without itWooCommerce support documents that Stripe onboarding, verification, and Dashboard settings are Stripe account questions, not extension questions.
Legitimate access to confirmThe Stripe account owner, not the website contractor's inbox, unless that person is also an authorized Stripe user.
Paid extension downloads
Why the store stops without itA WooCommerce.com download path belongs to the account that can open that dashboard. Not every plugin uses it. The Stripe extension can be installed from WordPress.
Legitimate access to confirmThe purchase account for each paid plugin, tested by signing in. Do not guess from the plugin name.
Email that receives provider notices
Why the store stops without itStore emails and provider notices are useless if they arrive at a mailbox the contractor will close.
Legitimate access to confirmThe From address, admin email, and the inbox that received the last provider notice.
Domain and hosting
Why the store stops without itThe site is unreachable if the business cannot renew or recover the account. Transfer rules are the registrar's or host's, not WordPress roles.
Legitimate access to confirmThe account name shown in a session the business is authorized to open. Mark unresolved rather than attempting a bypass.
Payment account status
Why the store stops without itReplacing a contractor does not move or approve the payment account.
Legitimate access to confirmThe provider agreement and the current Dashboard status. The provider decides both.
These are temporary notes. Leaving or reloading this page may clear them. The consultation form does not include these entries.
Limits
A Prism consultation can help you organize the facts and discuss the website or processing question. The payment provider decides eligibility, pricing, reserves, and whether an account is opened or closed.
No password-reset, takeover, or lockout-bypass steps are included. Unresolved access uses the service's own recovery channel.
Do not send passwords, API secrets, or recovery codes through the public form.
WordPress roles and capabilities — checked 2026-09-21. An Administrator on a single site has the site's administration capabilities, including users, plugins, themes, and options. An Editor's default capabilities do not include those. Installing WordPress creates an Administrator account.
WooCommerce REST API — checked 2026-09-21. Each API key is linked to a WordPress user, has Read, Write, or Read/Write permission, shows the consumer secret once, and can be revoked.
Stripe teams — checked 2026-09-21. Team members are invited from the Dashboard Team tab, can hold roles, and should receive the lowest permission needed. Invites expire after 10 days. Roles can be edited after acceptance.
Connecting WooCommerce to Stripe — checked 2026-09-21. The extension connects a Stripe.com account. WooCommerce support says Stripe account onboarding, verification, and Dashboard settings are questions for Stripe, not for WooCommerce extension support.
WooCommerce Checkout Add-ons — checked 2026-09-21. That paid extension is downloaded from the purchaser's WooCommerce dashboard, which is a different ownership path from installing a plugin inside WordPress.
Prism solutions — checked 2026-09-21. Public support is a storefront review, processing preparation, or help with a provider's website questions. The provider decides account terms. Scope, fees, and terms are discussed before work.
Request a consultation
Describe the business and this specific question. Prism follows up by email to discuss fit and scope. An inquiry is not a processing application or an approval.