Ownership and access
A managed website should never become a hostage. The business that pays for the property owns its domain, its content, its brand assets and its data, and it should be able to prove that ownership without asking the provider for permission.
Access is documented rather than remembered. Every system the site depends on is listed with who holds the account, who has access and at what level, so ownership questions are answered before they become disputes.
The standard expects
- The domain is registered in the client’s name, or in an account the client controls
- An access register lists every system the site depends on: domain, DNS, hosting, repository, CMS, analytics, Search Console, forms and email delivery
- Accounts use named, individual logins rather than shared passwords
- The client can see who has access and remove it
- Ownership of design and code deliverables is defined in writing before work starts
Questions to ask any provider
- Whose name is the domain registered in?
- Can you give us a list of every account the site depends on and who owns each one?
- If we ended the relationship tomorrow, what would we need from you?







