Insight ·

Who Has the Keys to Your Website? A Practical Handover Checklist

Know who controls your domain, hosting, email and backups. Use this practical website handover checklist to keep your business accessible when people change.

Your website is working. Orders arrive, the contact form sends messages, and someone takes care of the technical details.

Now imagine that person is unavailable for a week. Could you renew the domain, find a recent backup, or give another professional the access needed to fix a problem?

You don’t need to learn how to run a server. You need a clear record of what your business uses, who controls it, and how to get help. That’s what a useful website handover gives you.

Start with a map of your accounts

“The website login” rarely covers everything. Your domain name, hosting, website editor, business email and payment service may all have separate accounts. One company might provide several of them, but you should still know which service does what.

Make a simple list covering:

  • Domain registration: where you renew your web address.
  • DNS: where the settings connecting your domain to your website and email are managed.
  • Hosting or website platform: where the site runs.
  • Website administration: where content and settings are edited.
  • Email, forms and bookings: where customer messages go.
  • Payments and subscriptions: including tools the site depends on.
  • Backups: where copies are stored and who can restore them.

For each entry, record the provider, login address, account owner, billing contact, renewal date and support route. Include the date someone last verified access.

Keep passwords in a password manager. Your account list should tell an authorized person where access is managed without becoming a document full of passwords.

Check the domain before anything else

Your domain deserves its own check because both your website and business email may depend on it.

Sign in to the registrar account and confirm the domain is listed. Check its expiration date, renewal setting, payment method and contact email. Verify that someone in the business actually receives renewal notices.

ICANN recommends tracking expiration dates, keeping contact information current, and maintaining up-to-date payment details when using automatic renewal. Auto-renewal still needs attention when a card expires or an email address changes.

If an agency manages the registration, ask them to document who holds the account and the process for transferring management when needed.

Make account recovery part of the handover

A password is only one part of access. The next screen may ask for a code from a phone nobody else can reach.

Enable multifactor authentication on important accounts, then document the recovery options. Check who controls the recovery email, phone number, security key or backup codes. Store recovery material securely where the authorized person can reach it if the usual device is lost.

Where the service supports it, give people individual accounts and permissions appropriate to their work.

For Google Workspace specifically, Google recommends more than one super administrator, managed by separate people, and advises against sharing an administrator login. Its guidance also covers recovery details, spare security keys and backup codes.

For a solo business, check the provider’s recovery process and document a practical emergency arrangement. Also check whether recovering one account depends on another account you could lose at the same time.

Ask what the backup actually contains

“We have backups” is the start of a conversation.

Ask when the last successful backup ran, what it includes, how long copies are retained, and who can retrieve them. Confirm whether a copy remains accessible if the hosting account becomes unavailable.

For a typical WordPress site, a full restoration needs both the database and the site files. Downloading the website’s files alone does not capture its database. WordPress explains what a complete backup includes.

The WordPress Tools → Export feature creates an XML export of content. Treat that as a different deliverable from a complete site backup.

Choose the backup schedule around what your business can afford to recreate. For example, restoring yesterday’s copy of a store could leave today’s orders needing reconciliation.

Ask your provider to demonstrate a restoration in a separate test environment. Record the date, what worked, and anything the backup did not cover.

Include the things that keep the site working

List paid themes, plugins, booking tools and other subscriptions. Record who pays, who receives notices, and what happens if an agency-provided license ends.

For a custom website, ask where its source files live and how a new version gets published. For a managed platform, ask what can be exported and what would need rebuilding if you moved.

Keep a short note about important workflows: where contact forms deliver messages, how orders are checked, and who handles urgent support.

Run the handover checklist

Before calling the handover complete, verify that:

  • The business can sign in to its essential accounts.
  • Domain renewal details and billing contacts are current.
  • Recovery methods work without relying on an unavailable person.
  • Authorized people know where credentials and recovery material are stored.
  • Recent backups exist and a restoration has been demonstrated.
  • A clearly labeled test enquiry reaches the right inbox.
  • Subscription responsibilities and support contacts are documented.
  • Outgoing access is removed after replacement access is confirmed.

Revisit the list when a provider or team member changes. A brief quarterly check is also a useful habit.

If you can only do one thing today, find the domain account and verify that you can sign in. Then work through the rest with the person who manages your website.

Need help making sense of your setup? Tell me what you’re working with, and we can identify a useful next step.

Put the idea to work

Need a stronger digital presence?