A website design package can cover planning, page design, development, mobile layouts, content setup, enquiry forms, testing and launch support. Copywriting, hosting, booking tools, tracking and ongoing maintenance depend on the agreed scope. Ask what you receive, what your team supplies and who makes the purchased functions work after launch.
The most useful way to judge what is included is to ask what you will be able to do when the work is finished. Can a customer find the right service and send an enquiry that reaches your team? Can you update the information yourself? Who handles the first problem after launch?
A package should make those answers clear before design starts.
What the scope should explain
Use this as a guide to the work you need defined. It is not a list of features automatically included in every package.
| Area | What the finished work should make clear | Question to ask |
|---|---|---|
| Pages and design | The pages, layouts and mobile versions being created | Are these separate pages, sections on one page or reusable layouts? |
| Development | The approved designs become working pages on the chosen platform | Does the package include building and launching the site, or design files only? |
| Content | Text and images are supplied, reviewed and placed on the right pages | Who writes the copy, sources images and approves business facts? |
| Enquiries and transactions | The agreed contact, booking or purchase journey works | What happens after a visitor submits the form or clicks the button? |
| Search and measurement | The agreed search setup and tracking are implemented | Which pages and actions are covered, and how will they be checked? |
| Testing and launch | Agreed layouts, browsers/devices, broken links, forms, usability and performance are checked before publication | What must pass, who connects the domain and who fixes launch defects? |
| Editing and access | Your business has the agreed accounts, permissions and guidance | Can our team make the changes we expect to make? |
| Ongoing operation | Platform setup, hosting, renewals, backups, recovery and maintenance have clear owners | What continues after handover, and what requires a separate service? |
Design files and a working website are different deliverables
Treat completion as four separate milestones: designed means the layouts are approved; built means they have been implemented; launched means the site is live on its intended domain; operational means its agreed customer journeys work and ongoing responsibilities have owners.
The definition of done should match what you purchased. Visually finished pages alone do not demonstrate that enquiries arrive or bookings work.
Agree which designs you will review before the build starts, who approves them and how feedback is handled. A homepage approval should not leave the rest of the site undefined. Service pages, contact forms, navigation and mobile layouts also need attention.
Be specific about the page allowance. A long homepage with several sections is not several separate service pages. Likewise, a reusable product layout does not tell you how many products the agency will prepare and upload.
You do not need every page designed from scratch. You do need to know which pages are being delivered, what content they contain and whether your team can maintain them.
Content needs its own responsibility list
“Content included” can mean writing new copy, editing material you supply or simply placing your existing text into the website. These are different amounts of work.
Ask who handles the service descriptions, team information, frequently asked questions, images and any product information. If new photography or video is needed, define that production separately from adding the finished assets to a page.
Your team should approve factual information such as service areas, addresses, opening hours, prices and booking conditions. An agency can help present the information, but it needs an accurate starting point.
If the website needs Arabic as well as English, define who prepares and reviews the language, adapts the layout and checks menus, forms and messages. Do not treat the second language as finished because a language switch has appeared in the header.
For personal-information collection or marketing tools, define who supplies approved privacy and business-policy wording, who publishes it and who configures any commissioned consent controls. Include that approved content in the launch review; publishing a policy is not providing legal advice.
Test the customer task from beginning to end
A form that appears on the page is only part of an enquiry system. The customer needs to understand it, submit it successfully and know what happens next. Your business needs to receive enough information to respond.
For example, imagine a Dubai training company launching a course-enquiry page. Before accepting the work as complete, walk through this sequence:
- View the course, venue and session information on representative mobile and desktop layouts.
- Complete the form. Check clear field labels, required-field instructions and useful validation. Try an omitted or invalid entry and read the error message.
- Submit a test enquiry, check the success message and confirm delivery to the intended staff member or system.
- Follow any included WhatsApp or contact links and check their destination.
- If submission tracking is commissioned, verify that the agreed event is recorded.
- Ask the staff member to update session information using the promised CMS access.
This is an acceptance test: evidence that the purchased task works across the page, form, handoff and everyday editing. Agree who fixes failed checks before launch. Add other journeys only when they are part of the project.
W3C’s accessible-form guidance supports clear labels, instructions, validation feedback and completion notices. These practical checks do not amount to a full WCAG audit; commission a formal assessment separately if needed. Also ask about form-spam protection: front-end validation is not a complete security control.
Booking and ecommerce need their own checks
A link to a booking service, a request for an appointment and a confirmed booking are different features. State which one you need, where availability comes from and what the customer receives afterwards.
For an online store, agree how products, payment settings, delivery options and order messages will be prepared and tested. Shopify’s own guidance recommends test orders to check the checkout and related settings, including order processing, shipping and notifications. Shopify test-order guidance.
For UAE customers, the brief might include AED display, the delivery areas you serve and approved English or Arabic information. Include the requirements that matter to your customers, rather than assuming every store package covers them.
Define initial SEO and tracking in plain language
“SEO-friendly” should lead to a list of work, such as page titles, headings, useful URLs, internal links and checks that the pages intended for search are accessible.
Google’s technical requirements distinguish a page being eligible for indexing from a guarantee that it will be indexed. The launch check should establish that the agreed pages can be accessed and contain indexable content. Google’s technical requirements.
Ongoing keyword research, new articles, search reporting and continual optimisation are a different service from preparing the website for launch. The package should state any continuing work it includes.
Analytics has several parts: account/tool setup, installation, the actions being measured, testing those events and any reporting or analysis after launch. The package should identify which parts are included. A WhatsApp click, enquiry submission, booking and completed purchase are different actions.
Installing GA4 does not automatically implement all the events a business needs. Google states that its recommended events need implementation. Google Analytics event guidance. Ask for a successful test of the commissioned events, not just confirmation that a tag was installed.
Agree how launch will be accepted
For a substantial build, establish where you review major changes before they affect the live website, who approves launch and who connects the domain/DNS and configures hosting or the platform. Agree the device/browser and performance checks that matter to this project. PageSpeed distinguishes controlled lab tests from real-user data; one diagnostic score is not a complete account of customer experience. Google’s PageSpeed guidance.
For a replacement site, define responsibility for an inventory of important old URLs, content transfer, old-to-new mapping and permanent redirects where addresses change, removing accidental staging noindex/robots blocks, updating links/sitemaps where needed, and Search Console access and post-launch crawl, indexing and error checks. Google’s migration guidance. This is additional work to identify in the scope, not an automatic inclusion in every build.
Before switching an existing business site over, agree a usable backup or recovery route and who decides what to do if a serious launch problem appears. A simple website needs a proportionate plan, not an elaborate deployment process.
Handover should make the website usable by your team
Ask for access that matches your responsibilities. If your staff will update service information, add products or publish articles, they need the appropriate permissions and guidance for those tasks.
Keep a clear record of the domain account, hosting or platform account, website administration and analytics access. Agree who controls each account and what access remains with your business if the agency relationship ends.
For important external services, such as a booking system, CRM, payment gateway, email/SMS service or paid plugin/app, establish who owns the account, pays its fee and handles renewal. Ask what stops working if the subscription ends and whether another provider can continue managing the site if you change agencies.
Keep the same clarity for licensed fonts, images and any promised design or source files. Buying a website does not, by itself, describe the rights attached to every asset.
Launch support is not the same as ongoing maintenance
Ask which launch defects the agency will fix, for how long and how to report them. Future content changes and new features should be distinguished from correcting agreed work that does not function as promised.
If a package says “security included,” ask what that covers: HTTPS setup, platform/plugin updates, backups, restore help, form-spam protection, monitoring or security-incident response. These are possible responsibilities to define, not automatic entitlements.
A hosting subscription, a defect-support window and ongoing maintenance can cover different work. Before handover, know who will handle a failed form, an expired subscription or a restore request. Those tasks can sit with different people, provided responsibility is clear.
Build the package around your business with Lunasol
Lunasol offers custom design without templates, with WhatsApp, booking and lead-form journeys scoped around the project. Website development is quoted by scope.
Where you also need content, SEO or Meta Ads, Lunasol can coordinate those separately commissioned services with the website work. That is valuable when the person creating the page needs the same context as the people preparing its content and promoting it.
You should be able to see what will be designed, written, built, tested and handed over, alongside anything your team needs to supply. Discuss your website requirements with Lunasol and start with the customer task the finished site needs to support.
