Enterprise and governance features
Everything documented elsewhere in this guide was verified in the self-serve portal. This page covers the capabilities that come with Professional and Enterprise engagements, which are configured with your Zylyn contact rather than switched on from the billing screen.
The three engagement tiers#
Alongside the self-serve plans in credits and plans, Zylyn sells three engagement tiers for larger estates:
| Tier | For | Includes |
|---|---|---|
| Starter | A single site, proving the case internally | Automated scanning for one property, 100+ WCAG 2.2 automated checks, monthly scan cadence, AI-prioritised issue queue, developer fix guidance, PDF and CSV export, score history |
| Professional | Multi-property estates with an active remediation programme | Everything in Starter, plus multiple properties and environments, browser extension for authenticated pages, weekly monitoring and regression alerts, PDF and document accessibility, historical trend reporting, role-based access for delivery teams, scheduled email reporting |
| Enterprise | Regulated organisations answerable to auditors and procurement | Everything in Professional, plus expert manual audits, VPAT and conformance reports, managed remediation by Zylyn engineers, governance policies and thresholds, executive and board reporting, a named accessibility lead |
Enterprise is priced per estate rather than per seat or per site.
AI prioritisation#
Rather than handing you a flat list of findings, the platform can rank them so the order of work is decided before it reaches a developer. Findings are ranked by:
- User impact — how many people the barrier actually blocks
- Legal exposure — how likely the finding is to appear in a complaint
- Page value — traffic and commercial importance of the affected page
- Repair effort — how much work the fix represents
The practical effect: a team of four learns which twelve issues matter this sprint instead of triaging several hundred.
Duplicate findings that repeat across templates are clustered, so one template-level defect appears as one item rather than once per page.
Where humans still decide: judgement calls on alternative text, cognitive load, assistive technology behaviour, and any formal conformance claim. See AI fix suggestions for the same principle applied to individual fixes.
Assignment and ownership#
Findings can carry an owner and a due date, so the queue behaves like a work tracker rather than a report. Severity maps onto standard priority fields, which means findings can be triaged into an existing sprint process without re-writing them.
Resolved findings are verified automatically on the next scan rather than closed on trust.
Role-based access#
Permissions can be scoped by role and by property, covering:
- Executives — score, coverage and trend
- Accessibility managers — the full programme
- Developers — the ranked queue and the fix detail
- External auditors — read access to the evidence trail
This matters if your account spans teams who should not all see everything. On the self-serve plans there is no per-member visibility control — every member of an account sees every report — so if segregation is a requirement, raise it during onboarding.
Estate management#
Properties can be grouped by brand, region or business unit, each with its own conformance target, owner and reporting cadence. Multi-property rollup gives one view across the group.
Useful when "our website" is really forty sites with different owners and different levels of maturity.
Policy thresholds and drift alerts#
Define the minimum score and the maximum critical-issue count a property is allowed to carry, then get alerted when either drifts past the line.
This is the difference between monitoring and governance: a threshold turns "the score went down" into an event someone owns.
Scheduled reporting#
Two cadences, delivered without anyone assembling a deck:
- Weekly engineering digests — the ranked queue, what moved, what regressed
- Monthly executive summaries — written in outcomes rather than error codes
What gets reported to whom#
| Audience | Reported |
|---|---|
| Leadership | Accessibility score by property, open issues against threshold, quarter-on-quarter trend, conformance posture per regulation, and the age of the oldest unresolved critical finding |
| Delivery teams | Ranked queue with owner and due date, failing selector and criterion per finding, fix guidance, verification status on re-test, and regressions introduced by the most recent release |
That last leadership metric — age of the oldest unresolved critical finding — is worth adopting whatever tier you are on. It is the single number that exposes a programme quietly stalling.
Manual audits#
Certified specialists test with assistive technology and record findings against the same criteria as the scanner, so manual results sit alongside automated ones rather than arriving as a separate PDF.
This is the part that covers what automation cannot reach — see what automated scanning cannot find.
VPAT and conformance reports#
Conformance documentation produced from live platform data and reviewed by an accessibility specialist before release, intended for RFP responses and security reviews.
Evidence retention#
Scan history, audit records and conformance claims are retained for the life of the account and are exportable at any time.
The point is defensibility: a conformance claim supported by a dated record of continuous testing is a stronger position than a single audit from two quarters ago.
Managed remediation#
Zylyn engineers fix findings in your codebase when your own team has no capacity. Fixes go into your source — no overlay, no runtime patching.
If you are considering this, note the practical questions in teams and agencies about code access and vetting.
Related#
- Rollout plan — how a programme typically sequences
- Credits and plans — the self-serve plans
- Teams and agencies — seats, shared credits, white-label
- Reading your report — what the findings mean

