Insights · Build Log
My accessibility specialist will not certify you. That is the point.
A customer who is blind lands on a product page for a five-figure piece of equipment. The screen reader announces the photos in order: I M G underscore zero two zero five dot jpeg. Then the next one. Then four more.
Six images of a serious purchase, and the customer has learned nothing about any of them.
That finding came out of an audit I ran this month. The interesting part is not that it was found, because an automated scanner would flag missing image descriptions in about four seconds. The interesting part is everything the specialist refused to say afterward.
The pattern
This is the second of these I have written up. The first was an SEO specialist, hired the same way: a defined role, a stated standard of work, and one place the work accumulates so month three knows what month one found.
The pattern started because of a shape that keeps recurring in a small firm. A capability I can name and cannot staff. Not enough work to justify a hire, too much judgment involved to fake, too central to the client relationship to get wrong.
Accessibility fits that shape better than almost anything. It is a genuine specialization with case law attached. It comes up a few times a year rather than a few times a week. And getting it wrong in the confident direction is worse than not offering it at all, because the thing a client wants to hear is precisely the thing nobody can honestly say.
What I asked for
The standards were the easy half. WCAG 2.1 Level AA, because that is the baseline United States courts actually apply. WCAG 2.2 Level AA layered on top of it rather than instead of it, because it is coming. Section 508 for federal work. The DOJ 2024 final rule for state and local government sites. POUR as the organizing frame: perceivable, operable, understandable, robust.
Then a four-tier severity system, and a fixed report shape that never varies: an executive summary with the risk level and the top three issues, a findings table giving each issue its WCAG criterion and its user impact and its fix, a remediation roadmap split into immediate, thirty-day, and ninety-day phases, and a testing section covering automated, manual, and assistive technology.
The fixed shape is not a formatting preference. It is what makes the third audit comparable to the first.
But the half that decides whether any of this is worth having is the refusals.
Never certify compliance. Not “avoid certifying.” Never. Accessibility is not a certificate you earn once, it is a property of a site that changes every time the site changes.
Never give legal advice. Provide the legal context, name the statute, then say plainly that a real risk assessment requires an attorney who defends these claims.
An automated scan is not compliance. Scanning catches roughly a third of accessibility problems. It is necessary and it is not sufficient, and any report that implies otherwise is worse than no report.
Plain language first. Every owner-facing document has to be readable by the owner, not by a developer.
Staging before live. Nothing risky gets applied to a production site to see what happens.
What it found
Six findings, from five representative pages.
The product photos, described above, every one of them carrying its camera filename. Worth noting what sat next to that: the marketing photos elsewhere on the same site were described well. Somebody had done it correctly once and the shop had simply been skipped, which is the most common shape a real accessibility problem takes.
The contact page had no fallback. The form came from an outside service, loaded separately, could not be tested, and was not under the owner’s control. No phone number and no email address published anywhere on the page. If that form fails, a customer has no way to reach the business at all. That is a fifteen minute fix and it was the single highest-value item in the report.
Heading structure chosen for visual size rather than document outline. Screen reader users pull up a list of headings and navigate by it, the way you would scan a table of contents. The homepage had four competing top-level titles and the product pages skipped levels, so the table of contents did not describe the book.
More than a dozen demonstration videos with no confirmable captions, plus a point worth repeating to anyone with a video library: automatic captions do not meet the standard, and they will mangle any specialized vocabulary you have.
Links and buttons that did not say what they do. A cart link announcing itself as the number zero. Category links read out as raw web addresses, one character at a time. Repeated buttons with identical labels and no indication of which product they belonged to.
And no confirmation when an item was added to the cart. The button changed visually and said nothing, so a screen reader user gets no feedback, presses again, and ends up with duplicates or gives up.
The section that made it trustworthy
Then a heading that read: what we have not checked yet.
Color contrast, unmeasured. Keyboard operation, untested. Behavior at high zoom and at phone width, unknown. The checkout flow, not reviewed at all. The contact form itself, never tested with a screen reader.
Followed by a line I did not write and would not have thought to ask for: assume the real count is higher than what appears in this document.
That paragraph is the reason the rest of the report can be believed. A document that lists six findings and stops implies six is the number. A document that lists six findings and then names five things it did not look at is telling you what it is, which is a first pass on part of a site.
The same instinct produced the warning about overlays. Those are the products sold as a single line of code that makes a site compliant automatically. They do not work, disability advocates broadly oppose them, and businesses running them have been sued anyway. The specialist raised that unprompted, because a client about to be pitched one is exactly the client who needs to hear it first.
What I did not expect
I expected the constraint to be knowledge. WCAG is a public specification, so I assumed the value would be in having it read closely and applied consistently.
The value turned out to be in calibration.
Every finding in that report carries a consequence in the client’s own terms rather than a criterion number: this is what a customer cannot do, this is where the sale is lost. The legal section names the exposure, including the state statute with a four thousand dollar minimum per offense and the circuit decision that settled whether a commercial site attached to a physical business is covered at all, and then it stops and says we are not attorneys. The plan puts the two hour phase first, not the six hour one, and tells the owner to prioritize anything on the path from product page to completed order, because that is where a failure costs money and where a claim tends to start.
None of that is knowledge of WCAG. It is knowing which true things to say, in what order, to somebody who has to decide how fast to move.
If you are thinking about building something similar
Write the refusals before the capabilities. Everyone writes the capability list. The refusals are what make the output worth reading, because they are what stop the thing from telling you what you want to hear.
Give it a fixed report shape on day one, so the third one is comparable to the first.
Make it declare what it did not check. An audit without a stated scope reads as a complete picture of a site, and it never is.
And notice which gaps this actually suits. The ones where the knowledge is public, the judgment is real, the work is occasional, and the failure mode is confident overstatement. That describes a lot of what a small firm needs and cannot hire.
A specialist that will certify you is worth nothing, because the certificate is worth nothing.
Why the refusals are the productThe one that tells you what it did not look at is the one whose findings you can act on.
Michael DeLucia is the founder of Bantam Digital LLC, a Business Services Technology Partner in Pasadena, California, working with growing businesses on data foundations, workflow automation, and practical AI. Reach him at michael.delucia@bantam-digital.com.