Critical workflows
Name the journeys that must remain safe: enquiries, booking, checkout, account, publishing or integrations.
Website Access Readiness Checklist
Use the browser Print command to save or print this checklist. The page does not collect completion state.
| System | Prepare | Do not send through a public form |
|---|---|---|
| WordPress | Website address, owner, role needed, relevant environments and temporary named account. | Password, recovery code, private user export or customer data. |
| Hosting and server | Provider, account owner, support route, read-only or delegated access, maintenance window and responsibility boundary. | Root credentials, private keys, access tokens or raw configuration secrets. |
| Repository and deployment | Repository owner, branch and approval model, pipeline owner, deployment path and rollback authority. | Private access keys, deploy tokens or an unrestricted personal account. |
| Development and staging | Environment purpose, data-safety boundary, test accounts and how changes reach production. | Unredacted production data unless explicitly required and protected. |
| Backups and restore | Backup owner, frequency, storage responsibility, latest verified restore and rollback decision maker. | A private database export through email or a website form. |
| Integrations | Vendor owner, test environment, documentation, webhooks or application interfaces in scope. | Live secret keys, payment credentials or personal customer records. |
Name the journeys that must remain safe: enquiries, booking, checkout, account, publishing or integrations.
Identify who authorizes a change, when it can happen, what evidence is required and who can roll back.
Name operational contacts, provider contacts, escalation paths and the person who accepts the result.
No. Access readiness means preparing safe, authorized system access for an engagement. Website accessibility concerns how people, including people using assistive technologies, can use the website.
No. First agree which systems and roles are needed. Then use named temporary accounts and the approved secure exchange method; revoke access when the engagement ends.
No. Public evidence, exports, read-only roles, staging or a narrower system boundary may answer the question. Privilege should increase only when justified and authorized.