A website handover is more than receiving a login and a few files. Your business should know who owns each essential account, how to regain access, when services renew and who is responsible for future support.
You do not need to manage every technical task yourself. A designer, developer or hosting provider can handle day-to-day work on your behalf. However, the business should retain clear ownership and recovery access so that a staff change, missed renewal or supplier change does not leave you locked out.
Use the checklist below when a new website launches, when an employee leaves or when you move to a different provider.
First, understand ownership, access and billing
These three things are related but not identical:
- Ownership means the account is registered to your business, with business-controlled contact details and recovery options.
- Access means you or an authorised team member can sign in and use the account.
- Billing responsibility means someone receives invoices and manages payment or renewal.
For example, an agency may build and manage your website, while your business owns the domain account. Alternatively, a former employee may have created the account using a personal email address. In that case, you might have a working website but not have practical control of a vital service.
For every account, record the business owner, authorised users, billing contact and recovery method. Where possible, use a business email address rather than an individual’s personal address.
Domain and DNS details
Your domain is your website address, such as yourbusiness.co.uk. DNS, or Domain Name System settings, connect that address to services such as your website hosting and business email.
Confirm the following:
- The domain registrar or provider where the domain is registered
- The account email address and business owner details
- The domain renewal date and renewal payment method
- Who receives renewal reminders
- How to access the domain account
- Where DNS settings are managed
- Whether automatic renewal is enabled
- Any additional domains or common variations owned by the business
Check that the registrant details identify the business where appropriate. A domain registered in a former employee’s name can create difficulties if that person leaves or cannot be contacted.
You do not need to change DNS settings yourself. The important point is knowing where they are managed and who can recover access. This is particularly useful if you need to move hosting, restore email or work with a new website provider.
Hosting and website access
Hosting is the service that stores and delivers your website online. Ask for a record of the hosting provider, the plan in use and the relevant access arrangements.
Your handover notes should include:
- Hosting provider and plan name, if applicable
- Account owner and billing contact
- Renewal date and payment method
- Hosting control-panel access, if your setup uses one
- Website administrator access, where relevant
- Details of who handles support requests
- Backup arrangements and how backups can be restored, if applicable
- Any separate services used for deployment, monitoring or security
The type of access you need depends on how the website was built. A hand-coded website may use a hosting account and a separate deployment or file-management process. A platform-based website may use an administrator account within that platform. Neither approach automatically requires the same handover materials.
You may not need source code, server access or developer tools to run the site day to day. However, your business should know what exists, who controls it and how a suitably qualified provider could take over if necessary. Ask your current provider what can be supplied, exported or transferred without assuming that every technical file is needed.
Accounts connected to the website
Websites often depend on more accounts than are visible on the pages themselves. Make a list of the services used by your business and confirm access to each one.
Common examples include:
- Business email and the inboxes used for website enquiries
- Google Analytics or another analytics service
- Google Search Console, which helps monitor how a site appears in Google Search
- Tag managers or advertising-related tools
- Contact-form delivery services
- Booking, appointment or customer-management tools
- Payment providers
- Newsletter and email marketing services
- Social accounts used to sign in or publish website content
- Review, chat, map or other embedded services
Test important accounts rather than relying on an old list of usernames. For example, send a test enquiry through the website and confirm that it reaches an inbox the business can access. Forms may still be sending messages to a former employee’s mailbox or an agency-managed address.
If the website includes online sales, also confirm access to the store platform, payment accounts, order notifications, fulfilment tools and relevant app subscriptions. Check who can see orders and refunds, and which email addresses receive customer notifications.
Website files, content and licences
Gather the records that help you maintain or replace the website in future. The exact list will vary, but may include:
- Logo files, brand guidelines and approved colour references
- Website text and other content owned by the business
- Original images and information about image licences
- Product data, downloadable documents and customer-facing resources
- A list of third-party integrations
- Plugin, theme, platform or software licences where applicable
- Privacy, cookie and consent-management tools
- Documentation for forms, bookings, payments and other connections
- A simple description of how key website features work
Not every business needs every technical file. For example, a platform-based website may keep much of its content within the platform, while a hand-coded site may use a different process for storing and updating content. Ask your provider what records are relevant to your setup and what export options are available.
The goal is continuity: another authorised person should be able to understand what the website relies on, where the important records are stored and which services may need to be renewed.
Protect access during the handover
Avoid creating a new security problem while solving an access problem. Use individual user accounts where a service supports them, rather than sharing one administrator login with everyone.
As part of the handover:
- Use a password manager to store account credentials securely.
- Enable multi-factor authentication, which requires an additional verification step at sign-in.
- Save recovery codes in a secure business-controlled location.
- Check that recovery email addresses and phone numbers still belong to the business.
- Review active users, administrator roles and connected applications.
- Remove former staff or suppliers when their access is no longer required.
- Do not send passwords in ordinary email or place them in an unprotected document.
If a supplier continues to maintain the website, you can keep their access where appropriate. The key is to make sure the business can recover the account and can remove or change access when circumstances change.
Create a renewal calendar
A renewal date that only one person knows about is easy to miss. Create a shared business record or calendar covering services such as:
- Domain registration
- Website hosting
- Business email
- Software, plugin or platform licences
- Privacy, cookie or form services
- SSL certificates or separately billed security services
- Booking, payment, marketing or other key integrations
Record the provider, renewal date, billing contact, payment method and the person responsible for checking the service. Some services renew automatically, but automatic payment does not replace the need to review whether the service is still needed or whether the payment details are current.
Hold a final handover meeting
A short meeting can resolve gaps that are easy to miss in a document. Before the handover is considered complete, ask the provider to walk through the accounts and responsibilities with you.
Use this copyable checklist:
WEBSITE HANDOVER CHECKLIST
Ownership and contacts
[ ] Domain and key service accounts are registered to the business
[ ] Business owner, authorised users and billing contacts are recorded
[ ] Recovery email addresses and phone numbers are current
Domain and hosting
[ ] Registrar and domain renewal date are recorded
[ ] DNS management location is recorded
[ ] Hosting provider, plan and renewal date are recorded
[ ] Relevant website or hosting access has been tested
[ ] Backup and restore arrangements are documented, where applicable
Connected accounts
[ ] Business email and form inboxes have been tested
[ ] Analytics and Search Console access is available
[ ] Booking, payment and marketing tools are recorded
[ ] Social sign-in and other integrations are documented
[ ] E-commerce store, payments, orders and notifications are covered
Files and records
[ ] Brand assets and business content are stored securely
[ ] Image and software licences are recorded, where relevant
[ ] Key integrations and website features are documented
[ ] Export or transfer options have been discussed
Security and continuity
[ ] Individual user accounts are used where possible
[ ] Multi-factor authentication is enabled
[ ] Recovery codes are stored securely
[ ] Former staff and suppliers no longer have unnecessary access
[ ] Renewal dates are in a business-controlled calendar
Final checks
[ ] Important logins have been tested
[ ] Billing and payment details have been verified
[ ] Future editing and support responsibilities are clear
[ ] Records are saved in a secure business-controlled location
Once the checklist is complete, keep it updated whenever a provider, payment method, employee or connected service changes. If you need help organising a handover or reviewing the practical controls around your website, SiteRook can help with website support and maintenance. See current plans and pricing for more information.

