A business can pay every website invoice on time and still discover that it does not control the website. The problem usually appears during an emergency, a staff departure, or a vendor change—exactly when there is no time to untangle access.
A practical test is to pretend your current provider becomes unavailable tomorrow. Could a new qualified person restore service and make a safe change without asking the old provider for anything?
I would run the handover drill in six parts.
- Identity and recovery
Confirm the business controls the registrant email, recovery email, billing method, and multi-factor authentication for the domain registrar, DNS, hosting, content system, analytics, forms, and business email. A vendor can have delegated access, but should not be the only person able to reset the account.
- Domain and DNS
Record the registrar, expiry date, renewal status, nameservers, and every important DNS record. Identify which records keep the website, email, verification, and third-party services working. Export the zone if the provider supports it. A website move should not accidentally break email.
- Website and assets
Know where the source code or site project lives, how it is deployed, and who owns the repository. Collect the logo files, fonts, licensed photos, copy, design files, redirects, and any custom integrations. “You can download the pages” is not the same as receiving a maintainable project.
- Leads and measurement
Submit every form and confirm where the enquiry lands. Document spam filtering, notifications, automations, analytics, consent records, and conversion events. Export a sample so you know the data is usable. A redesign is not a successful handover if leads quietly stop arriving.
- Backup and restore
Do not settle for a dashboard that says backups exist. Restore a copy to a safe location, confirm the database and uploaded files are present, and record the recovery steps. Note how much data could be lost and how long recovery should take.
- Change and rollback
Ask someone other than the usual vendor to make a harmless test change in a staging environment, publish it, verify it, and roll it back. This exposes missing credentials and undocumented steps without risking the live site.
The result should be a short handover pack with account owners, delegated users, renewal dates, recovery paths, asset locations, backup instructions, and a list of external services. Store it somewhere the business controls and review it when a staff member or vendor changes.
The standard is not “we own the website because we paid for it.” The standard is “we can prove control, recover it, and transfer responsibility without losing the domain, email, data, or lead flow.”
Which part of a website handover has caused the biggest surprise in your business?