Website operations
Website handover checklist for small-business owners
How to confirm access, renewals, backups, editing, and support when you take over a website

Before accepting a website handover, sign in with your own account and try the tasks you expect to manage. Record what works, what access is missing, and who is responsible for each service.
List the systems you need to manage
With the provider, list the services the site uses. Depending on the setup, that may include the domain registrar, hosting or website platform, business email, content editor, forms or booking tools, and analytics. For each one, note its sign-in address, your access role, the person responsible for it, and who pays its renewal. Keep the role, responsibility, and payer as separate details.
Ask which account controls each part of the site. A single company may provide several services, so check what each account includes. Record enough information to find each service and understand who will manage it.
Check access and responsibilities
While the provider is available, sign in to each service using your own account and try a task you expect to handle. You might open the content editor, view form submissions, or find the hosting support information. Note whether the task worked, whether your role allowed it, and what invitation or permission is still needed.
Use the provider’s invitation process where available. Store passwords and recovery codes in an agreed secure location, separate from ordinary handover notes. Do not remove existing access or change live domain settings to test the handover. If access needs to change, arrange that with the provider and confirm the replacement access first.
Record who pays for each service and who will act on renewal notices. These responsibilities may belong to different people. A working login does not tell you who pays.
Write down renewal details
Open the domain account with the provider and find its renewal information and contact details. Record the next renewal date shown, who receives notices, who pays, and who will act on a notice. Check that the person expected to respond can access the relevant contact account.
For gTLD registrations, ICANN’s Expired Registration Recovery Policy requires registrars to send the Registered Name Holder at least two notices before expiration. One must arrive approximately a month before expiration and another approximately a week before. ICANN’s policy is a reason to check your domain’s contact details and notice responsibilities. Its requirements do not establish renewal arrangements for every domain type.
Make the same payer and responsibility check for hosting and other paid services. Keep the details with the account information so someone can verify them later.
Ask for backup and recovery evidence
Ask the provider to show where backups are stored, what they include, the date of a recent backup, who can restore them, and how long they are retained. Request the written recovery procedure and note whom to contact. Record any limits in the provider’s plan. This evidence describes the arrangement; it cannot guarantee a successful recovery.
For a typical WordPress site, the official backup guide says a full restoration needs both the site files and the database. WordPress backup guidance Ask for evidence that both are covered. If your site uses another platform, request its relevant export and recovery documentation.
Practice an edit and locate asset records
Use a draft or staging copy to try a routine edit. For example, change a service description, preview it, and find how to return to the earlier version. Do not publish a test change to the live site. Note whether you completed the task and where you got stuck, then ask the provider to show you any controls or steps you will use regularly.
Locate the original logo, approved photographs, and editable design files. Note where they are stored and keep any supplied license or permission documents with the relevant asset information. Having access to a file does not settle whether or how it may be reused. Ask the responsible parties to resolve unclear terms; this checklist does not determine legal ownership or usage rights.
Assign support and close the handover
Write down who handles content changes, software updates where applicable, renewals, broken forms, and urgent outages. Record the actual support contact, its availability, what the current arrangement covers, and which requests need a separate quote. Assign each missing item to a person and give it a follow-up date.
| Check | Evidence to keep |
|---|---|
| Access | Your login works, the required role is confirmed, and missing invitations are assigned. |
| Renewals | The next date, notice recipient, payer, and responsible person are recorded. |
| Backups | Coverage, recent backup date, retention details, recovery contact, and procedure are recorded. |
| Editing | A draft or staging edit and preview have been demonstrated. |
| Assets | Source files and supplied permission records are located. |
| Support | Contact, availability, scope, and unresolved work are assigned. |
Keep the handover open until agreed missing invitations, instructions, or other deliverables arrive, or have a named owner and follow-up date.