Skip to main content
WCAGrules
Quick navigation

Services · By journey

An Account and Settings Audit Tests Where Users Live

For the product whose users log in and stay, managing profiles, plans, and payments on pages no audit has ever visited.

What We Keep Finding

Audits gravitate to the marketing site, because that is the part a crawler can reach. The industry's best dataset on how broken the web is covers home pages and nothing else, a million of them, which tells you something about where everybody has been looking. Your actual users live logged in, updating a card, changing an email, switching plans, hunting the notification toggle that finally stops the emails. Trust is built or lost on those pages, and the scanner never got past your login.

A settings page is also the clearest case for a Level AA rule nobody names. Deleting an account, changing a plan, removing a payment method, revoking a colleague's access, these all modify or delete data the user controls, and changing a card is a financial transaction. Where that is true, the standard wants one of three things. Reversible, checked with a chance to correct, or a review-and-confirm step before it goes through. That single rule covers most of what a settings audit finds and it is almost never cited.

Two things a report on these pages gets wrong in the expensive direction. A dense grid of notification toggles is not automatically a target-size failure. Small targets pass when a 24-pixel circle around each one does not touch its neighbor's, and that spacing allowance is the most misread part of the rule. And the rule about marking fields so a browser can autofill them applies only to the user's own details. A billing contact who is not the account holder, a teammate's email, an emergency contact's phone number are all outside it. Flagging those is flagging a non-requirement.

WCAG 2.2 also added a rule that bites here specifically. A flow that demands details the account already holds has to fill them in or offer them back, and the browser doing it does not count.

What We Check

  • Work the core account tasks by screen reader, so profile, billing, preferences
  • Test every toggle for a name, a state, and an announced change
  • Check the billing journey end to end, card change to confirmation
  • Measure destructive actions against 3.3.4, so reversible, checked, or confirmed
  • Verify the result after a confirmation dialog closes is announced, not just the dialog
  • Measure against 3.3.7, so saved details are not demanded twice

What You Get

Every service on this site runs the same three-pass engine: an automated scan, an expert review of all 55 WCAG 2.2 A and AA rules, and a hands-on session with a professional blind screen-reader user. You get one report with every finding screenshotted, ranked by user impact, and linked to its fix. Your team fixes, we verify: the re-audit is half price within 3 months.

The format is not a mystery either. Read the sample report before you spend anything.

The Honest Limit

Two honest limits and one request. The audit runs on test accounts, which we request by email at scope confirmation, and roles or plans we are not given stay untested and get named rather than guessed at. To test a card change end to end we also need your payment provider's test mode, or a card you are happy for us to use. There is no way to exercise that step without one. And these are the pages people most often manage from a phone. Our sessions are desktop-based, so the mobile layout of your settings screens is outside what we looked at.

What It Costs

Rapid Audit: $499, up to 10 pages you pick, report in 5 business days. Standard Audit: $1,499, up to 25 pages in 10 business days. Flat rates, no discovery calls, and a real blind screen-reader user on every engagement. Pick your pages. We bring the humans.

Worth Reading Next

Related on this site

Guides, checklists, tools, and terms that go with this service.

More in By journey

Go somewhere useful

Find tools, resources and your workspace.

29 destinations