Who on the team can view, refund, or export payments
Assign access from the task, separately in the store and the payment account. A person who answers order questions needs access to the relevant orders; that need alone does not justify gateway settings, exports, refunds or team administration. WooCommerce documents order visibility for Administrator and Shop Manager users, while a single-site WordPress Administrator also has broad site powers. Stripe directs account owners to assign the lowest permission a team member needs. Verify each role's actual capabilities before granting it, and record any excess permission instead of treating a familiar role name as proof of a safe fit.
For: Research-only merchants assigning routine store and payment-account duties to employees or authorized contractors.
Write the recurring task in terms of what the person must do: read an order, edit its operational details, execute an approved refund, investigate a provider payment or prepare a particular report. Then write what the person must not do as part of that assignment. Someone preparing a refund request and someone authorized to execute it may be different people, even if the business has previously treated both as support.
Keep business authorization separate from software permission. The refund policy determines who may approve a refund; the application role determines who can perform an action. A button available to a staff member does not establish that the business authorized its use. If the system grants more power than the assignment needs, record that excess and the owner's decision about how to address it.
Use individual accounts with documented responsibilities. A shared owner's login prevents the access matrix from meaningfully distinguishing one person's duties from another's. This worksheet prepares a grant or change for the authorized account administrator; filling it does not itself change access.
Order visibility does not establish every store capability
WooCommerce's managing-orders documentation says orders are visible to Administrator and Shop Manager users. That supports considering those roles when assessing order access. It does not, by itself, establish the precise refund, export or gateway-setting permissions of the installation in front of you. Separate view and edit duties in your notes even when the installed role bundles them.
WordPress documents broad powers for an Administrator on a single site: installing plugins, switching themes, managing options and managing users. Its default Editor role does not receive those capabilities. Giving a content or order-support worker Administrator access therefore carries powers beyond answering an order question. Do not choose Administrator just because it makes a missing screen appear.
Record the installed role and the capability evidence relevant to each requested task. Customized roles, extensions and a multisite arrangement need their own confirmation; the single-site Administrator description does not settle those configurations. If no documented available role fits, keep the proposed grant unresolved and ask the authorized maintainer to identify a supported narrower arrangement. Do not claim a custom role already exists.
Map the provider account as a separate system
Stripe's teams documentation lets an account owner invite team members by email and assign roles, with instructions to grant the lowest permission the job requires. Read the role's documented powers for the account before choosing it. A store role does not grant a Stripe team role, and a provider role does not establish WordPress access.
Separate viewing payments from issuing provider-side refunds, handling disputes and inviting or removing members. These are different duties to verify, not a claim that every provider offers one matching role per duty. For each person, record the role actually assigned, the relevant documented capabilities, and which responsibilities the business approved.
Check both refund routes if staff can work in the store and directly in the provider. Restricting one route does not answer what the same person can do through the other. The access matrix should reveal that combined authority before a second person approves what they assume is a limited role. Keep the investigation read-only; do not issue a refund or alter a live dispute merely to discover whether permission exists.
Define what an export may contain
An export request must name the dataset, purpose, recipients and approved storage destination. Product data, orders, payment reports and stored payment credentials are not one export. Give a reporting worker access only to the data needed for the approved reporting duty, and document whether the available role grants broader access than that duty requires.
Stripe's payment-data export documentation describes a processor-to-processor transfer of card data to another PCI DSS Level 1 processor through Stripe's process. That export excludes payment history and other objects. It is not an ordinary order CSV and is not a reason to let an employee download full card numbers to a spreadsheet.
Do not treat permission to export an order report as permission to arrange credential migration, or assume a credential migration preserves the payment history needed by support. Record those as different responsibilities with different owners. No credential values, customer lists or report contents belong in this access worksheet.
Resolve the exceptions before the next routine grant
For each row, choose grant proposed, keep as documented, reduce proposed or unresolved. Give any proposed change to the person authorized to administer that system, with the task and capability evidence attached. Where a broader role must be considered, the merchant should explicitly record the excess powers and the operating oversight it will use; do not silently describe that access as least privilege.
Record a review date and an owner for changes in daily responsibilities. The useful result is a named person, a task, a system and a documented role whose limits the merchant understands. Unknown permissions remain a reason to withhold a new grant until clarified, not a reason to share the owner's password.
A Prism checkout consultation can start with the task that lacks a clear access arrangement and the systems involved. Confirm any access-review or implementation scope, responsibilities, fees and terms before work. Bring a summary to the inquiry, not credentials, customer exports or the full internal staff-access list.
Access matrix
Complete each row for the people who actually perform it. In the blank column record person, system, assigned or proposed role, capability evidence, business approval and any excess access. Leave unresolved permissions explicit. This is a decision record; do not change live access while filling it.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Access matrix. The last column is for temporary notes.
Payment-related task
Permission evidence to inspect
Boundary to record
Person, role and decision
View and edit store orders
Permission evidence to inspectInstalled role and actual documented order capabilities. WooCommerce documents order visibility for Administrator and Shop Manager.
Boundary to recordDistinguish reading an order from changing it; neither duty alone justifies site administration.
Refund through the store
Permission evidence to inspectThe installed gateway and store role's documented refund capabilities, plus the merchant's refund authorization.
Boundary to recordIdentify the approver and executor. Do not assume order visibility proves refund permission.
Manage gateway settings and keys
Permission evidence to inspectThe role/capability documentation for the installed integration and the authorized technical owner.
Boundary to recordState exactly which maintenance duty needs this access. Do not enter or share key values.
Export products or order data
Permission evidence to inspectNamed export tool, dataset, assigned role, recipient and approved destination.
Boundary to recordA product report, order export and provider payment report have different contents; record excess access.
View the provider dashboard
Permission evidence to inspectAssigned provider team role and its documented payment-viewing scope.
Boundary to recordStore access does not establish provider access. Avoid a shared owner login.
Refund or handle disputes inside the provider
Permission evidence to inspectProvider role documentation and written business authority for each action.
Boundary to recordAssess both duties and the person's store-side authority; one restricted route may leave another available.
Invite or remove team members
Permission evidence to inspectThe system's documented member-management capability and authorized account administrator.
Boundary to recordDelegating payment investigation does not itself justify changing other people's access.
Arrange payment-credential migration
Permission evidence to inspectThe provider's migration process and the named migration owner.
Boundary to recordStripe's card-data transfer goes to another PCI DSS Level 1 processor and excludes payment history; it is not a staff CSV export.
These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.
Limits
The WordPress role facts describe default single-site capabilities; customized roles, extensions and networks require separate verification.
No specific Stripe role's refund, dispute or export capability is asserted here. Match the actual role documentation to the task.
Access does not establish merchant eligibility or legal approval. Do not place credentials or customer datasets in the worksheet or public form.
Stripe teams — checked 2026-09-21. An account owner invites members by email, assigns roles and is instructed to grant the lowest permission needed for the job.
WooCommerce managing orders — checked 2026-09-21. Orders are visible to Administrator and Shop Manager users. This fact alone does not specify every refund or export capability.
WordPress roles and capabilities — checked 2026-09-21. A single-site Administrator can install plugins, switch themes, manage options and manage users; an Editor does not receive those default capabilities.
Stripe payment data export — checked 2026-09-21. Stripe transfers card data through its process only to another PCI DSS Level 1 processor; the export excludes payment history and other objects.
Prism solutions — checked 2026-09-21. Scope, fees and terms are discussed before work; the provider decides account terms and eligibility.