Control is more than having an editor login

An editor account may let somebody change text or replace an image, but it does not necessarily provide control over the website as a business asset. The domain may sit in one account, hosting in another, and analytics, forms or email services somewhere else. If those accounts belong only to a supplier, the business can become dependent on that supplier for routine changes, renewals and recovery.

A clear setup gives the business appropriate access to the important accounts, explains which third-party services are involved and records what happens when the working relationship ends. That does not mean every owner needs to administer a server. It means the business can identify the services, make informed decisions and appoint somebody else without starting again unnecessarily.

1. Put the domain in a business-controlled account

The domain is the address customers use to find the website and may also support business email. It should normally be registered using accurate business details in an account the business can recover. The owner should know the registrar, renewal date, billing method and which email address receives security and renewal notices.

A designer or technical supplier can help configure the domain without being its only account holder. Before work begins, agree who will buy it, who will manage technical records and how access will be handed back. If the domain already exists, confirm the business can sign in and receive recovery messages before making changes.

  • Registrar and account name recorded
  • Recovery email and telephone number controlled by the business
  • Renewal date, price basis and payment responsibility understood
  • Two-step verification or a passkey enabled where available

2. Know where the website is hosted and who pays for it

Hosting is the service that makes the website available online. A business should know the provider, plan, renewal cycle and account owner. It should also understand whether email, backups, security certificates or other services are bundled with that plan, because moving one part may affect another.

Client-controlled hosting does not mean the client must handle every technical task. A supplier can be granted suitable access while the subscription and recovery route remain with the business. This makes responsibilities clearer and reduces the risk that the website disappears because a supplier account closes or an invoice reaches the wrong person.

3. Ask what files, content and licences will be handed over

A useful handover identifies what the finished website consists of and supplies the agreed materials in a usable form. That may include source files, exported site files, images, written copy, deployment notes and a record of known limitations. For a platform-managed website, it may instead mean administrator access, an export and clear instructions for the services that cannot be transferred directly.

Not every component can simply be owned outright. Fonts, stock images, plugins, themes and software may be licensed under separate terms. The proposal or contract should distinguish original work being handed over from third-party items that remain subject to a licence, subscription or provider account. The aim is a clear record, not a vague promise that everything is included.

  • The agreed website source or platform export
  • Original supplied copy, images and brand assets
  • A list of third-party themes, plugins, fonts and stock assets
  • The relevant licence or renewal responsibility for each paid item
  • Deployment instructions and any known technical limitations

4. Map the services connected to the site

A modern website may depend on more than its visible pages. Contact forms can use a delivery service, analytics can belong to a separate account, and maps, booking tools, payment links or consent tools may each have their own access and billing arrangements. If nobody records those connections, a later change can break something that appeared unrelated.

Keep a simple service register showing the provider, purpose, account owner, renewal terms and person responsible for it. Record identifiers and recovery routes securely rather than placing passwords in the document. Remove supplier or former-staff access when it is no longer required.

5. Protect access and recovery

The National Cyber Security Centre includes company websites and domain-hosting accounts among the important online accounts a small organisation should protect. It recommends strong, unique passwords and two-step verification where passkeys are not available, as well as removing accounts that are no longer needed.

A handover should therefore cover more than usernames. Confirm the business controls the recovery address, has current backup codes where relevant and knows who has administrator access. Store recovery information in an appropriate password manager or other controlled system, not in ordinary email threads or a public project document.

6. Agree backups, maintenance and renewals

Ownership does not remove ongoing costs or maintenance. Domains and hosting still renew, software may need updates, and business information can become inaccurate. Decide who monitors these tasks, what support is included and what will be quoted separately after launch.

The NCSC advises organisations to back up the data they need to operate, including websites, and to know how that data can be restored. For a website, clarify what is backed up, how often, where copies are kept, how long they are retained and who has tested the restoration process. A provider saying that backups exist is not the same as a recovery plan the business understands.

  • Domain and hosting renewal dates
  • Software, content and security maintenance responsibility
  • Backup frequency, location, retention and restoration route
  • Support boundaries and response expectations
  • A named owner for keeping the record current

7. Complete the handover before the project closes

The best time to test control is while the supplier is still available and the project details are fresh. Ask the business owner to sign in to the important accounts, confirm recovery details and check that the supplied files open. A short walkthrough can reveal missing permissions or undocumented dependencies before they become urgent.

The final handover record does not need to be complicated. It needs to be specific enough that a competent replacement supplier can understand the setup without guessing.

  • Business owner has successfully signed in to the domain and hosting accounts
  • Administrator access and recovery routes have been tested
  • Website files or platform exports have been supplied as agreed
  • Connected services, licences and renewals are documented
  • Backups and restoration responsibilities are clear
  • Temporary supplier access has been removed or reduced
  • Future support arrangements are recorded in writing

If you are changing supplier

Start by making an inventory rather than immediately changing passwords or moving services. Identify the domain registrar, hosting provider, website platform, DNS settings, email dependencies, analytics and form delivery. Confirm which accounts the business already controls and ask the current supplier for the missing information in writing.

Plan changes in an order that protects the live website and email. A new supplier may need temporary access to assess the setup before recommending a transfer. Avoid cancelling the old service until the replacement has been verified, and keep a recoverable record of the previous configuration.

A clear handover protects both sides

A sensible ownership arrangement is not about distrusting a web designer. It gives the client, supplier and any future maintainer the same understanding of the accounts, responsibilities and boundaries. That makes renewals easier, security decisions clearer and future changes less disruptive.

Norse Pantheon Productions uses client-owned domain and hosting accounts, provides the agreed source and practical notes, and explains what is and is not included after launch. Whatever supplier you choose, ask these questions before the website becomes business-critical.