Domain registration
The business should know the registrar, registrant identity, renewal date, payment method, recovery contacts, transfer lock, and multifactor-authentication status. A vendor can manage a domain, but the agreement should state ownership and what happens at separation. Never let an unknown personal email become the only recovery path.
DNS and email
DNS connects the domain to the website, email, verification records, and other services. Record the provider and administrators. A website migration must preserve email-related records; an incomplete DNS change can make the site or mail unavailable.
Hosting and platform
Know where the files and database live, who pays, who administers the account, what the backups contain, and how restoration works. For WordPress, Shopify, or another platform, document the primary owner and separate staff/vendor roles instead of sharing one password.
Creative and source assets
Clarify rights to logos, photographs, video, fonts, stock licenses, copy, design files, code, plugins, themes, and third-party components. “It appears on our website” does not automatically mean the business has unrestricted rights to reuse or transfer it.
Customer data and integrations
Inventory forms, CRM, booking, email, SMS, payment, chat, call tracking, and analytics. Identify where data is stored, who can export it, which privacy terms apply, and how access will be removed when a vendor relationship ends. Payment providers should use authorized roles; card credentials should not be shared casually.
Analytics and search accounts
The business should retain appropriate access to analytics, Search Console, Tag Manager, advertising, Merchant Center, and local business profiles. Vendors can be delegated access. Do not create a fresh measurement property every time a vendor changes if a usable business-owned history already exists.
Minimum handoff package
- Account inventory with owner and administrator roles
- Current backup and restoration instructions
- Domain, DNS, hosting, CMS, and integration locations
- Repository or source-file location when included in the agreement
- License and recurring-cost inventory
- Form destinations and notification rules
- Analytics and conversion definitions
- Removal of former vendor access after confirmed handoff
Security rule: use a password manager and individual roles. Do not put passwords, recovery codes, secret keys, or payment credentials into an ordinary project document or email thread.
This checklist is operational guidance, not a substitute for reviewing the signed contract. Use it together with the redesign checklist and cost guide.
