Plan a Website Handoff Without Losing Account Access

Before any website project starts, list every account the site depends on: domain, hosting, content management, design files, analytics and connected tools. Keep ownership in the business's name, grant contractors their own logins with only the access they need, never share passwords, and remove that access when the work ends. A written inventory prevents the most common lockouts.
Why handoffs fail
Many small businesses discover, years later, that their domain is registered to a former web designer, their analytics belongs to an old agency, or nobody knows the hosting login. Recovering those accounts can take weeks. A short plan at the start avoids it.
The access inventory
| Asset | Who should own it | Who needs access | Access level | How to grant |
|---|---|---|---|---|
| Domain registrar | Business | Developer (temporarily, if DNS changes needed) | DNS management only, where available | Delegated access or owner makes changes |
| Hosting or site platform | Business | Developer | Admin during build, reduced after | Individual user invite |
| Content management | Business | Developer, staff editors | Admin for developer during build; editor for staff | Individual user invites |
| Analytics | Business | Developer, marketing | Edit during setup, then read or remove | User management in the analytics tool |
| Design files and images | Business | Developer | Read and upload | Shared folder with named access |
| Forms and CRM connection | Business | Developer | Configure during build | Individual invite |
| Email sending tools | Business | Developer | Configure during setup | Individual invite |
Fill in your actual tools. If you do not know who owns something, find out before the project starts.
Least-privilege setup
Give each person the lowest level of access that lets them do their job, and only for as long as they need it. A designer uploading images does not need billing access. A developer changing DNS does not need to own the domain. Most platforms support individual user invitations with roles; use them instead of sharing one login.
Never share passwords
Sending passwords by email or text creates a permanent copy you cannot control. If a tool does not support separate users, have the owner make the change during a screen-share, or look for an alternative. Rithm asks clients to invite access rather than share passwords. Source: Google Analytics Help: Best practices to avoid sending PII.
Hypothetical example: a florist changing web designers
A fictional florist is moving to a new designer. The inventory shows the domain is registered to the old designer's personal account and analytics was created under the old designer's email. The florist contacts the old designer to transfer the domain to the florist's own registrar account and to add the florist as an owner on analytics. Only after that are new invitations sent to the new designer. At launch, the old designer's access is removed from every tool.
Access-removal checklist
When the project ends or a contractor leaves:
- Remove or downgrade their user on hosting and content management.
- Remove them from analytics and any ad accounts.
- Remove shared folder access.
- Confirm the domain registrar shows only business-controlled contacts.
- Rotate any credentials that were ever shared, even by accident.
- Record the date and who removed access.
Before you sign
Access and ownership questions belong in your first conversation with any web or marketing provider. Our list of questions to ask an AI marketing agency includes them. If you are preparing for a Rithm build, the $500 website preparation guide lists what to gather.
Frequently asked questions
Should my developer own the domain for convenience?
It is safer for the business to own it and grant access. That way you keep control if the relationship ends.
What if I have lost access to an old account?
Start with the provider's account recovery process, using business documents that prove ownership. It can take time, so begin early.
Do I need a password manager?
It helps you store your own credentials securely. It does not replace giving contractors their own logins.
Next step
Fill in the inventory table for your current website. For a new build, see our website development service.
Sources and further reading
- Google Analytics Help: Best practices to avoid sending PII, relevant when reviewing analytics setup at handoff.
Editorial note: this planning guide was drafted with AI assistance for Rithm Digital and created on September 25, 2026. Examples are hypothetical. It is general marketing-operations guidance, not legal, medical, tax or financial advice. Prices refer only to Rithm's published Small Business Launch & Growth offer.
You might also like
Discover more content related to this topic

Questions to Ask an AI Marketing Agency Before Signing
Ownership, scope, usage costs, approvals, logging, data access and success definitions, organized as a conversation guide rather than a contract.

Your $500 Business Website: What to Prepare Before the Build
What Rithm's Website Launch includes, the assets and copy to gather, how the single revision round works and what stays separate.

