IOSOR Learn
Account access is not production send
Console login and sandbox keys are not Live traffic. Keep catalog honesty and day-1 runway gates in front of any production send after apply access.
Account access means you can open the console, create projects, and receive sandbox credentials. It does not mean production send is authorized. The gap is where teams burn trust: they ship sandbox keys into customer paths and call it Live.
IOSOR keeps the cutover explicit. Sandbox proves integration shape without live debit drama. Production keys, vault-backed Live catalog tiles, and Launch runway greens prove you may charge holds and leave the pilot lane.
After apply, write one sentence on the war-room wall: access ≠ Live. Every status review starts there.
Treat sandbox keys as non-production by default
Sandbox credentials exist to wire OTP flows, webhook handlers, and error paths without pretending the vault is green. Label them in secrets managers. Forbid pasting sandbox keys into production env files during the first sprint after access. If a partner demands a production key on day one of access, answer with the cutover checklist: vault items, catalog Live gate, and runway smoke. Access alone is not the checklist.
Catalog Live must still match vault
Catalog honesty does not relax because apply is done. A tile labeled Live without vault secrets is a client-facing lie. Setup and In setup stay accurate until smoke passes.
After access, audit the catalog before demos. Keep setup labels on products that fail vault checks. Sales decks that show every channel Live after login create tickets a funded wallet cannot close.
Pair catalog reviews with Launch runway language so demos and ops share one truth.
Runway greens still gate first send
Day-1 runway items — webhook heartbeat, messaging readiness, Verify and adjacent gates — remain Launch work after access. Closing KYC does not auto-green those rows.
Plan the first production send as a runway milestone, not an apply milestone. Require named owners and evidence (smoke logs, heartbeat freshness) before keys leave sandbox mode.
If runway is red, keep traffic in sandbox even when the wallet is funded. Money without green vault still is not Live.
Brief stakeholders on three different greens
Access green, wallet green, and runway green are three statuses. Collapse them and someone will announce go-live from the wrong board.
Weekly ops should show all three. Access done / wallet funded / runway red is a normal early state — celebrate configuration, not production.
When partners ask for a send date, point to runway owners and catalog Live gates, not to the apply approval email.
Related ops paths
- Sandbox vs production keys cutover
- Catalog Live gate must match vault
- What must be green on day-1 runway
Start with IOSOR
Audit your workspace console to verify that sandbox credentials are explicitly labeled and separated from production secret stores. Keep the dispatch gate held on live production runs until vault secrets pass validation and webhook endpoints report healthy status. Check that your catalog tiles retain setup status until live key verification succeeds.
IOSOR takeaway
Receiving account access after KYC approval is an operational milestone, not permission to trigger production send. Sandbox credentials exist solely to validate integrations, while live status requires verified vault secrets and explicit runway sign-offs.
Do maintain catalog honesty by keeping catalog tiles in setup until vault checks pass. Don't conflate access green with runway readiness or push live traffic based on sandbox credentials.
Was this guide helpful?
Related guides
- Short apply is not the technical launch runway
Account access and a funded wallet open the console — they do not green day-1 vault gates. Keep launch runway checks under Launch, separate from apply and KYC.
- Access, then the USD 20 prepaid floor
After apply access comes the prepaid wallet floor — a pilot start, not an entry fee and not a production-send badge. Holds still need runway truth.