Skip to content

Insights · Strategy · Feb 5, 2026 · 8 min read

How to evaluate a web development agency before you sign

Most agency selections are decided by the proposal that reads best, not the team that builds best. Here is how to test real capability, and the ownership and handover terms worth insisting on.

oldevs.com1.8s · 100
Request a quote

Evaluating a development agency comes down to three tests: can they show you working software they built, will they tell you exactly how you will see progress week to week, and do the contract terms leave you owning everything at the end. Decks, logo walls and awards pages answer none of those. What follows is the set of questions, the proposal checklist and the handover clauses to use before you sign anything.

Key takeaways

  • Ask to see running software and meet the people who wrote it, not case study screenshots and a sales lead.
  • A proposal worth signing names the scope, the assumptions, the named team, the delivery rhythm and what happens when scope changes.
  • Get it in writing that you own the code, designs, accounts, domains and data, and that handover includes the repository, the credentials and a runbook.
  • No discovery, no demos, vague scope and a platform you cannot leave are four reasons to walk away.
  • Reference calls only pay off when you ask about the hard weeks, not the launch announcement.

Run the evaluation in a fixed order

Most selection processes go wrong because they start with price and end with capability. Reverse it. A price is only meaningful once you know what the work actually is, and you only know that after a proper discovery conversation. Run the same sequence with every shortlisted firm so you are comparing like with like.

  1. Write a one page problem statement: who the users are, what they need to do, what already exists, and what a successful first release looks like.
  2. Send it to three or four agencies. Not ten. A long list produces generic responses, because nobody invests real thought in a lottery.
  3. Hold a working session with each, sixty to ninety minutes, with the people who would actually do the work in the room.
  4. Ask for a proposal that responds to what surfaced in that session, not a template with your logo on the cover.
  5. Take references after the proposals arrive, so you can ask reference clients about the specific promises being made to you.
  6. Compare, then negotiate terms. Ownership and handover language is far easier to fix before a number is agreed than after.

The questions that reveal real capability

Capability questions have one thing in common: a firm that has done the work answers with specifics, and a firm that has not answers with adjectives. Listen for named systems, named trade-offs and named mistakes.

  • Show me something you built that is live right now, and walk me through a part of it that was difficult. The difficulty is the point. Anyone can demo a happy path.
  • Who exactly will write this code, and what else are they on? You want names, roles and honest availability. If the answer is a resourcing abstraction, the people you meet are not the people you get.
  • How will I see progress between now and launch? A weekly working demo is the only answer that removes the guesswork. A status report describes progress; a demo proves it.
  • What would you cut from my brief, and why? A studio that will not push back during a sales conversation certainly will not push back six weeks in, when the budget is tight and the deadline is close.
  • How do you handle accessibility, and to what standard? WCAG 2.2 AA should be a normal part of the build, not a line item you buy separately after launch.
  • What happens when something breaks at two in the morning? Ask about logging, alerting, on-call and rollback. Vague answers here predict a rough first month in production.
  • Tell me about a project that went badly. Everyone has one. The useful signal is whether they can describe the cause without blaming the client.
A demo you can click beats a deck you can only nod at.

What a good proposal actually contains

A proposal is a working document, not a brochure. Yours should be readable by your finance lead and your future developer with equal ease. Check it against this list.

  • A restatement of your problem in their words, so you can tell whether they listened.
  • Scope split into what is included and what is explicitly excluded. The exclusions matter more. Ambiguity always resolves in favour of whoever wrote the document.
  • Assumptions written down: content supplied by you, third party integrations, access to systems, approval turnaround. Each one is a future delay if it goes unstated.
  • The architecture in plain language, including the stack and the hosting, and why those choices suit your case rather than their habits.
  • A named team with roles, plus the one person accountable to you when something goes wrong.
  • A delivery rhythm: what you see each week, how your feedback is captured, and how long you have to give it.
  • A change process with a defined path for new requests, so a change becomes a decision rather than an argument.
  • Testing, accessibility and performance commitments written as acceptance criteria, not aspirations.
  • Handover and support after launch, including the training you get and what happens if you take the work in house.

If a proposal is mostly timeline graphics and team photos, ask for a version that answers the list above. How a firm responds to that request is itself a data point. Our own approach to scoping and weekly demos is set out under how we work, and the same structure applies whether the engagement is a marketing site or a full-stack build.

Ownership and handover terms to insist on

This is where a selection decision quietly becomes a commitment that outlasts the build. Ownership is not one clause, it is five, and each has to be checked separately.

  • Intellectual property. Code, designs and content transfer to you. Watch for language that grants you a licence to use software the agency continues to own.
  • Accounts in your name. Domain registrar, DNS, hosting, cloud, analytics, ad accounts and app store listings should be registered to your organisation, with the agency added as a user. Reversing this later is tedious and occasionally impossible.
  • Repository access from day one. Not a zip file at the end. Continuous visibility of the code is the cheapest insurance available to you.
  • Data portability. You can export your content and your database in a documented, usable format without asking permission.
  • A handover package defined in the contract: repository, environment configuration, credentials in a password manager, a deployment runbook and a short recorded walkthrough.

One test cuts through all of it. Ask directly: if we part ways in twelve months, what exactly do we walk away with, and how long would it take another team to run this? A confident firm answers in a minute. A firm that depends on lock-in starts explaining why you would never want to leave.

Warning signs, and what to ask instead

Most bad engagements were visible during the sales process. The signals below are common, and each one has a question that either resolves it or confirms it.

Warning signWhy it mattersAsk this
No discovery before a price appearsA number produced without understanding the work is a guess you will pay to correctWhat did you assume in order to produce this figure?
No live demos, only static case studiesScreenshots outlive projects that never shipped or never worked properlyCan we open something you built and click through it now?
Scope written in adjectivesVague scope resolves in the writer's favour once deadlines pressWhat is explicitly out of scope at this price?
Proprietary platform you cannot export fromYour site becomes a subscription you cannot cancel without rebuildingShow me the export, and what a migration away would involve
The pitch team is not the build teamThe quality you evaluated is not the quality you receiveWhich people in this meeting will write our code?
Accessibility described as an add-onRetrofitting accessibility costs more than building it in, and often fails anywayWhat standard do you test against, and how?

Reference checks that are worth making

Agencies supply references who will be positive, so treat the call as a source of texture rather than a verdict. Ask about process, not satisfaction. Useful prompts: what surprised you during the build; what did you end up doing yourself that you had not planned for; how were disagreements handled; what happened the first time a deadline was at risk; how quickly did they reply when something broke after launch; would the same team be available to you again.

Two further moves are worth the effort. Ask for a reference from a project that has ended, not only from a current client, because how a firm behaves on the way out tells you what handover really looks like. And inspect the agency's public work directly rather than through a case study: open the sites on a phone, run a page through a performance tool, tab through a form with the keyboard. Ten minutes of that beats an hour of testimonials. If you want to see how we present our own, our project examples are there to be poked at the same way.

How OlDevs approaches this, and what to do next

We have been building web, mobile and AI products from Vancouver since 2014, and we run engagements so that the questions above are easy to answer. One accountable team, so the people who scope the work are the people who build it. A working demo every week, so progress is something you see rather than something you are told about. Clients own all code, designs, accounts and IP, with handover assumed from the start rather than negotiated at the end. Accessibility to WCAG 2.2 AA is part of the build, and we work bilingually in English and French where that is needed. Clients outside Vancouver get video calls in their own time zone, and on-site visits when the work calls for it.

Use this guide on whoever you shortlist, including us. If you would like a scoped, plain-language proposal written against your problem statement, request a quote and we will reply within one business day.

FAQ

Questions on this topic.

Three or four is usually right. A short list gets you considered responses because each firm is investing real time, while a list of ten produces templates. Give every firm the same one page problem statement and the same working session so the proposals are genuinely comparable.

Five things: intellectual property in code, designs and content transfers to you; domains, hosting, cloud and analytics accounts are registered in your name; you get repository access from day one; your data is exportable in a documented format; and the contract defines a handover package with credentials and a runbook.

A price arriving before any discovery. A figure produced without understanding your users, your existing systems and your definition of done is a guess, and you pay to correct it later through change requests. Ask what was assumed to produce the number, then watch how specific the answer is.

Still have a question? Ask us when you request a quote

Let’s connect

Want this applied to your business?

Tell us what you’re building. We’ll reply within one business day with next steps and a tailored quote.

We’ll only use your details to prepare your quote. No lists, no spam.

Call us Request a quote
We use cookies for personalized content and ads, social features, and analytics. We share site usage data with our partners.
Cookies settings
Accept
Decline
Privacy & Cookie policy
Privacy & Cookies policy
Cookie name Active

Privacy Policy

What information do we collect?

We collect information from you when you register on our site or place an order. When ordering or registering on our site, as appropriate, you may be asked to enter your: name, e-mail address or mailing address.

What do we use your information for?

Any of the information we collect from you may be used in one of the following ways: To personalize your experience (your information helps us to better respond to your individual needs) To improve our website (we continually strive to improve our website offerings based on the information and feedback we receive from you) To improve customer service (your information helps us to more effectively respond to your customer service requests and support needs) To process transactions Your information, whether public or private, will not be sold, exchanged, transferred, or given to any other company for any reason whatsoever, without your consent, other than for the express purpose of delivering the purchased product or service requested. To administer a contest, promotion, survey or other site feature To send periodic emails The email address you provide for order processing, will only be used to send you information and updates pertaining to your order.

How do we protect your information?

We implement a variety of security measures to maintain the safety of your personal information when you place an order or enter, submit, or access your personal information. We offer the use of a secure server. All supplied sensitive/credit information is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our Payment gateway providers database only to be accessible by those authorized with special access rights to such systems, and are required to?keep the information confidential. After a transaction, your private information (credit cards, social security numbers, financials, etc.) will not be kept on file for more than 60 days.

Do we use cookies?

Yes (Cookies are small files that a site or its service provider transfers to your computers hard drive through your Web browser (if you allow) that enables the sites or service providers systems to recognize your browser and capture and remember certain information We use cookies to help us remember and process the items in your shopping cart, understand and save your preferences for future visits, keep track of advertisements and compile aggregate data about site traffic and site interaction so that we can offer better site experiences and tools in the future. We may contract with third-party service providers to assist us in better understanding our site visitors. These service providers are not permitted to use the information collected on our behalf except to help us conduct and improve our business. If you prefer, you can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies via your browser settings. Like most websites, if you turn your cookies off, some of our services may not function properly. However, you can still place orders by contacting customer service. Google Analytics We use Google Analytics on our sites for anonymous reporting of site usage and for advertising on the site. If you would like to opt-out of Google Analytics monitoring your behaviour on our sites please use this link (https://tools.google.com/dlpage/gaoptout/)

Do we disclose any information to outside parties?

We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information. This does not include trusted third parties who assist us in operating our website, conducting our business, or servicing you, so long as those parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.

Registration

The minimum information we need to register you is your name, email address and a password. We will ask you more questions for different services, including sales promotions. Unless we say otherwise, you have to answer all the registration questions. We may also ask some other, voluntary questions during registration for certain services (for example, professional networks) so we can gain a clearer understanding of who you are. This also allows us to personalise services for you. To assist us in our marketing, in addition to the data that you provide to us if you register, we may also obtain data from trusted third parties to help us understand what you might be interested in. This ‘profiling’ information is produced from a variety of sources, including publicly available data (such as the electoral roll) or from sources such as surveys and polls where you have given your permission for your data to be shared. You can choose not to have such data shared with the Guardian from these sources by logging into your account and changing the settings in the privacy section. After you have registered, and with your permission, we may send you emails we think may interest you. Newsletters may be personalised based on what you have been reading on theguardian.com. At any time you can decide not to receive these emails and will be able to ‘unsubscribe’. Logging in using social networking credentials If you log-in to our sites using a Facebook log-in, you are granting permission to Facebook to share your user details with us. This will include your name, email address, date of birth and location which will then be used to form a Guardian identity. You can also use your picture from Facebook as part of your profile. This will also allow us and Facebook to share your, networks, user ID and any other information you choose to share according to your Facebook account settings. If you remove the Guardian app from your Facebook settings, we will no longer have access to this information. If you log-in to our sites using a Google log-in, you grant permission to Google to share your user details with us. This will include your name, email address, date of birth, sex and location which we will then use to form a Guardian identity. You may use your picture from Google as part of your profile. This also allows us to share your networks, user ID and any other information you choose to share according to your Google account settings. If you remove the Guardian from your Google settings, we will no longer have access to this information. If you log-in to our sites using a twitter log-in, we receive your avatar (the small picture that appears next to your tweets) and twitter username.

Children’s Online Privacy Protection Act Compliance

We are in compliance with the requirements of COPPA (Childrens Online Privacy Protection Act), we do not collect any information from anyone under 13 years of age. Our website, products and services are all directed to people who are at least 13 years old or older.

Updating your personal information

We offer a ‘My details’ page (also known as Dashboard), where you can update your personal information at any time, and change your marketing preferences. You can get to this page from most pages on the site – simply click on the ‘My details’ link at the top of the screen when you are signed in.

Online Privacy Policy Only

This online privacy policy applies only to information collected through our website and not to information collected offline.

Your Consent

By using our site, you consent to our privacy policy.

Changes to our Privacy Policy

If we decide to change our privacy policy, we will post those changes on this page.
Save settings
Cookies settings