A website access handoff checklist helps a business keep control when an employee leaves, a marketing contractor changes, a web agency relationship ends, or responsibility moves to a new internal team. Website ownership is rarely a single username. It can include the domain registrar, DNS, hosting, WordPress, analytics, form services, email delivery, search tools, backups, and third-party accounts. A clean handoff identifies those systems, confirms who owns them, and changes access without accidentally breaking the site.
Map control before changing passwords or removing users
Start with an access inventory. Write down each system that can affect whether the website loads, where it points, what it measures, or where customer information goes. For every system, record the account owner, billing owner, recovery method, current administrators, and what the account controls. This prevents a common mistake: removing a former vendor from WordPress while leaving the domain, hosting, DNS, or analytics under an account the business cannot recover.
Tie the inventory to an ongoing small-business website maintenance plan. Access should not be documented only during a stressful transition. A quarterly or scheduled review can identify old administrators, expired recovery addresses, and tools nobody remembers authorizing.
Use the website access handoff checklist in dependency order
Change access in an order that protects recovery. Confirm the business controls its primary email accounts and password recovery methods before changing the systems that depend on them. Confirm domain ownership before editing DNS. Confirm hosting access before removing the only person who knows how backups are restored. Confirm there is another WordPress administrator before deleting or downgrading the departing user’s account.
Avoid doing every change at once without a record. If the site fails afterward, the team needs to know which action may have caused it. Use a change log with time, system, action, old owner, new owner, and verification result. A transition becomes far easier to troubleshoot when the sequence is visible.
- Confirm business-controlled recovery email and multi-factor authentication methods.
- Verify ownership and billing access for the domain registrar and hosting account.
- Document DNS, CDN, security, and backup services that can affect availability.
- Confirm at least one current WordPress administrator controlled by the business.
- Review analytics, search, form, scheduling, payment, and marketing integrations for administrator access.
- Remove or reduce former-user permissions only after replacement access has been tested.
Protect measurement and customer-routing accounts during the transfer
Analytics and form systems are easy to overlook because the public site can keep working even when the business loses administrative access. Verify that the business can reach its analytics properties, tag management if used, search tools, form destinations, and any system that receives website leads. The guide on website analytics for small businesses is useful because measurement access should remain part of the company’s operating knowledge, not an orphaned account owned by a past contractor.
For contact paths, test after permissions change. A form can submit successfully while routing to an old inbox, former employee, or third-party account nobody monitors. Confirm delivery, reply-to behavior, notifications, spam controls, and who can edit the destination. If the site includes local pages such as the Lakeville website design service-area page, verify that their calls to action still lead into the same current contact system after the handoff.
Separate business ownership from vendor permissions
Where possible, the business should own the master accounts and grant vendors the level of access required to do their work. That arrangement makes future transitions less disruptive because changing a vendor does not require transferring the core identity of the account. It also reduces confusion over billing, recovery, and legal control. A vendor can still be an administrator where necessary without being the only person capable of recovering the account.
Do not remove a vendor before collecting information the business legitimately needs to operate the site. That can include hosting configuration, backup locations, plugin or service licenses, renewal dates, deployment instructions, and a list of external services connected to the website. If a redesign or migration is part of the transition, the article about website redesign content migration can help keep content and URL responsibilities visible while access is changing.
Be careful with licensed software and accounts that are genuinely owned by the vendor rather than the client. The objective is not to seize credentials that were never part of the agreement. The objective is to identify what the site depends on, determine which subscriptions need replacement, and ensure the business has a lawful, documented path to continue operating.
Verify recovery and continuity after the handoff
After permissions are changed, test recovery rather than assuming the new names in the user list mean control is secure. Confirm the business can reset passwords, receive multi-factor prompts, contact support, renew critical services, and restore from backup. Check whether any recovery email still points to a former employee or vendor. Confirm that billing notices go to an address somebody monitors.
Schedule a second review after the transition has settled. Some dependencies reveal themselves only when a monthly report arrives, a plugin license renews, a form notification fails, or a hosting notice is sent. A follow-up review catches those delayed signals while the handoff is still fresh enough to fix cleanly. Keep the updated inventory somewhere the responsible people can find without searching an old project thread.
Access handoff questions
Should a business change every website password when a vendor leaves?
Change credentials and permissions according to actual access and risk. Shared passwords should generally be replaced because there is no reliable way to revoke one person’s knowledge of them. Individual accounts can often be disabled or removed. The key is to preserve recovery access and avoid locking out the current team while permissions are being tightened.
Who should own the domain name account?
The business should have durable control of the domain account or a clearly documented ownership arrangement that survives staff and vendor changes. Domain control affects where the site and email point, so it should not depend on one temporary relationship. Keep recovery methods and billing information current.
What if a plugin or service license belongs to the old agency?
Identify whether the license was sold to the business, included as part of an agency service, or owned entirely by the agency. If the business does not own it, plan a replacement license or tool before the old access ends. Do not assume a copied license key gives the business a continuing right to use the service.
How often should website access be reviewed?
Review it whenever responsibility changes and on a regular schedule afterward. The exact cadence can match the size and complexity of the site, but the review should be frequent enough to catch former users, obsolete recovery methods, and unused integrations before an emergency exposes them.
Make control independent of any one person
A resilient handoff leaves the business able to operate, recover, measure, and update the website without depending on the memory or goodwill of one former employee or vendor. Inventory the systems first, change access in dependency order, protect analytics and customer routing, distinguish ownership from temporary permission, and verify recovery afterward. The result is not just better security. It is clearer operational ownership, which makes future maintenance, redesigns, and vendor transitions much easier to manage.

Leave a Reply