Start with an assessment

Why publish it

A checklist, not a sales page.

"Website management" is sold under the same name for very different things: a hosting plan with a plugin update each month, a block of developer hours, or a team that is genuinely responsible for how the property performs. Buyers usually cannot tell which one they are getting until something breaks.

This standard sets out, area by area, what professional operation of a website should mean in practice and the questions that reveal whether a provider does it. It is written to be useful whether or not you ever work with Colorbull.

It is an operating standard, not a certification, a legal compliance statement or a service-level agreement. Specific commitments, response times and scope are set in each engagement agreement.

Twelve areas of a managed website

  1. Ownership and access

    The client owns the property and can always reach it.

  2. Deployment and change control

    Changes reach production deliberately, and can be undone.

  3. Availability and technical health

    Problems are detected by monitoring, not by customers.

  4. Performance

    Speed is monitored and protected as the site changes.

  5. Accessibility

    The site is usable by people with a wide range of abilities.

  6. Search health

    Search engines can crawl, index and understand the site.

  7. Analytics and measurement integrity

    Reports describe what actually happened.

  8. Forms and lead routing

    Every inquiry reaches someone, and the visitor knows it.

  9. Security and privacy fundamentals

    Sensible, current protection proportionate to the site.

  10. Content integrity

    The site tells the truth about the business today.

  11. Operational improvement

    The site gets better over time, visibly.

  12. Transfer and handoff

    Leaving is an orderly process, not a negotiation.

What the standard does not mean   Buyer checklist

Ownership and access

A managed website should never become a hostage. The business that pays for the property owns its domain, its content, its brand assets and its data, and it should be able to prove that ownership without asking the provider for permission.

Access is documented rather than remembered. Every system the site depends on is listed with who holds the account, who has access and at what level, so ownership questions are answered before they become disputes.

The standard expects

  • The domain is registered in the client’s name, or in an account the client controls
  • An access register lists every system the site depends on: domain, DNS, hosting, repository, CMS, analytics, Search Console, forms and email delivery
  • Accounts use named, individual logins rather than shared passwords
  • The client can see who has access and remove it
  • Ownership of design and code deliverables is defined in writing before work starts

Questions to ask any provider

  • Whose name is the domain registered in?
  • Can you give us a list of every account the site depends on and who owns each one?
  • If we ended the relationship tomorrow, what would we need from you?

Deployment and change control

Most website incidents are caused by changes: an edit made directly on the live site, an update applied without review, a plugin upgrade that breaks a form. A managed property controls how change reaches production.

The appropriate level of control depends on the site. A small content edit does not need the same ceremony as a new template or a platform upgrade. What matters is that every change has a path, a reviewer where it matters, and a way back.

The standard expects

  • Changes move through a defined release path rather than ad hoc edits on the live site
  • Visible or structural changes are previewed or staged before release where the platform allows
  • Every release can be rolled back, through source control, backups or both
  • A change record notes what changed, when, why and who approved it
  • Automated checks run before release where practical: build, links, metadata and key pages

Questions to ask any provider

  • How does a change get from request to the live site?
  • If a release breaks something, how do you roll it back and how long does that usually take?
  • Where can we see what changed on the site last month?

Availability and technical health

A managed site is watched. Outages, expired certificates, broken pages and failing dependencies should be noticed by the operator, ideally before a visitor or the client does.

Technical health also means keeping the platform current. Frameworks, content systems, plugins and server software age, and unmaintained dependencies become security and stability risks.

The standard expects

  • Uptime monitoring on the site and its most important pages, with alerts to a person
  • Certificate, domain and DNS expiry tracked in advance
  • Regular checks for broken pages, broken internal links and server errors
  • Platform and dependency updates applied on a routine cadence, with security updates prioritized
  • An incident process: acknowledge, diagnose, fix or roll back, then record what happened and why
  • Response expectations for incidents agreed in the engagement, not assumed

Questions to ask any provider

  • How would you know if the site went down at night?
  • Are the platform and its dependencies being kept current?
  • What happened during the last incident, and what changed afterwards?

Performance

Fast sites are easier to use, convert better and are easier for search engines to crawl. Performance is not a one-time launch achievement; new images, scripts, embeds and features erode it gradually unless someone is watching.

The standard is awareness and protection, not a promised score. Lab scores vary by tool, device and network, and field data depends on real visitors. What a managed site should show is that performance is measured, regressions are caught and fixed, and new additions are weighed against their cost.

The standard expects

  • Core Web Vitals and page weight tracked for key templates, using field data where available
  • Images and video sized, compressed and served in modern formats
  • Caching and static-first delivery used where the site allows
  • Third-party scripts checked before they are added and periodically afterwards
  • Performance checked after significant releases, with regressions treated as defects

Questions to ask any provider

  • How fast are our key pages for real visitors, and how do you know?
  • What would you do if a new feature made the site noticeably slower?
  • Which third-party scripts load on our site, and does each one still earn its place?

Accessibility

Accessibility is part of building and operating a website properly. It improves usability for everyone and is expected by a growing number of buyers, partners and regulators.

The standard is sensible, continuing practice guided by the Web Content Accessibility Guidelines (WCAG) as a reference. It is not a claim of formal conformance or legal compliance, which requires a specific audit against a defined scope. Where a client needs a formal audit or conformance statement, that is scoped as separate work.

The standard expects

  • Semantic HTML: real headings, lists, landmarks, buttons and links
  • Everything usable with a keyboard, with visible focus states
  • Text and interface contrast checked against recognized guidelines
  • Form fields with proper labels, clear errors and instructions
  • Meaningful alternative text for informative images
  • Reduced-motion preferences respected for animation
  • Automated checks plus periodic manual testing of key journeys, including keyboard use

Questions to ask any provider

  • Can every part of the site, including menus and forms, be used without a mouse?
  • How do you check accessibility after changes?
  • What would a formal accessibility audit involve, and is it included?

Search health

Technical search health is part of operating a website responsibly. It does not grow visibility on its own, but without it, every other search investment is undermined.

Most search-health failures are silent: a staging setting that blocks indexing, canonical tags pointing to the wrong page, redirects lost in a migration, structured data that no longer matches the page. A managed site checks for them routinely.

The standard expects

  • Correct canonical URLs on every indexable page
  • An XML sitemap listing only indexable, canonical URLs, kept current automatically
  • A robots configuration that allows what should be crawled and nothing that should not
  • Monitoring of indexing and crawl errors through Search Console or equivalent tools
  • Redirects maintained for every retired URL, and protected during redesigns and migrations
  • Unique titles and descriptions on indexable pages, and one clear main heading
  • Structured data that describes content actually visible on the page
  • Important content delivered as crawlable text, not only inside images or scripts
  • Non-production environments excluded from indexing

Questions to ask any provider

  • Is anything on our site currently blocked from search by mistake?
  • What happens to our old URLs when pages move or the site is rebuilt?
  • Does our structured data match what visitors actually see?

Analytics and measurement integrity

Decisions about budget, content and design are only as good as the data behind them. Measurement breaks more often than most businesses realize, usually after a site change nobody connected to tracking.

Integrity means the core measurement is configured deliberately, verified in the live environment, and checked again whenever the site changes. It also means respecting the choices visitors make about tracking and explaining the effect of those choices on the numbers.

The standard expects

  • Conversions defined and documented: what counts as an inquiry, booking or sale
  • Key events verified in the live environment, firing once and on the right action
  • Consistent campaign tagging conventions so traffic sources are not fragmented
  • Measurement re-checked after releases that touch forms, templates or scripts
  • Tracking implemented in a consent-aware way where consent is required
  • Spam, internal and test traffic kept out of reported results where possible

Questions to ask any provider

  • Which conversions are we tracking, and when were they last verified?
  • Would you notice if a form stopped reporting conversions?
  • How do visitor consent choices affect the numbers we see?

Forms and lead routing

For many businesses the most expensive website failure is a form that looks like it works and does not. The visitor sees a success message, the submission never arrives, and nobody finds out until a customer mentions it weeks later.

A managed site treats forms as critical infrastructure: tested end to end, monitored, and honest with the visitor about whether their submission was received.

The standard expects

  • Success messages shown only when a submission has actually been accepted
  • Clear, accessible error states, with an alternative contact route when sending fails
  • Delivery and routing tested end to end, from the form to the person or system that receives it
  • Spam protection that does not block real people, such as honeypots and server-side validation
  • Forms tested after every change that could affect them
  • Submission data handled in line with the privacy notice, with only necessary fields collected

Questions to ask any provider

  • When did someone last test that our forms reach the right inbox or CRM?
  • What does a visitor see if a submission fails?
  • Where does form data go, and who can see it?

Security and privacy fundamentals

No website can be made perfectly secure, and a managed service should not claim otherwise. What it should do is apply sound fundamentals consistently, reduce the attack surface, keep software current and be ready to recover.

Privacy follows the same principle: collect only what is needed, be clear about what is collected, respect consent where it is required and keep third-party data sharing to what the site genuinely needs. Specific legal obligations depend on the business and its markets and are the client’s to determine with their own advisers; the standard supports them, it does not replace legal advice.

The standard expects

  • HTTPS everywhere, with certificates renewed automatically
  • Least-privilege access and multi-factor authentication on administrative accounts where the platform supports it
  • Security updates applied promptly
  • Credentials and secrets kept out of code repositories
  • Regular backups, with restoration tested rather than assumed
  • Unused plugins, accounts and integrations removed
  • Third-party scripts and data collection kept to what the site needs
  • Access removed promptly when people leave a project

Questions to ask any provider

  • Who has administrative access to our site today?
  • When was a backup last restored successfully?
  • What data does our site collect, and where is it sent?

Content integrity

Websites decay in plain sight. Former staff remain on the team page, discontinued services are still described, prices and hours are out of date, a campaign page from last year is still linked from the homepage, and a claim that was true at launch no longer is.

A managed site keeps its content current, removes what is no longer accurate and makes sure every call to action still leads somewhere useful.

The standard expects

  • Business information such as contact details, hours, locations and team kept current
  • Outdated offers, prices, claims and expired campaigns removed or updated
  • Broken or misleading calls to action corrected
  • Key pages checked on a regular cadence for accuracy
  • Claims about results, clients and credentials supported by evidence the business can stand behind

Questions to ask any provider

  • When was each of our main pages last checked for accuracy?
  • Is there anything on our site today that is no longer true?
  • How quickly can a change to our business be reflected on the site?

Operational improvement

Keeping a site running is the floor. A managed site should also improve: small usability fixes, clearer paths to inquiry, faster templates, better internal links, corrections prompted by what real visitors do.

Improvement should be visible. The client should be able to see what was found, what was prioritized, what shipped and what happened afterwards, without having to ask.

The standard expects

  • Issues detected through monitoring, analytics and reviews, not only through complaints
  • A prioritized list of improvements, visible to the client
  • Small improvements shipped routinely within the agreed scope
  • Regular reporting of what changed, what was found and what is recommended next
  • Results of changes assessed, including when a change did not help

Questions to ask any provider

  • What did you improve on our site last quarter, and why?
  • What is on the list to improve next?
  • How do you decide what to fix first?

Transfer and handoff

A good managed relationship is one the client could leave. That is not pessimism; it is what keeps the relationship honest. The path out should be documented at the start, not negotiated at the end.

Transfer means the client, or a new provider, can take over the property with the access, documentation and assets needed to operate or migrate it.

The standard expects

  • A documented transfer path agreed at the start of the engagement
  • Handover of domain and account access, content, assets and data the client owns
  • Documentation of hosting, deployment, integrations and configuration
  • Code and infrastructure transfer handled as defined in the agreement
  • Reasonable cooperation during transition, as agreed in the engagement

Questions to ask any provider

  • What exactly would we receive if we moved to another provider?
  • Is the transfer process written down today?
  • Are there any parts of our site we could not take with us?

Scope

What the standard does not mean.

A managed website keeps the property healthy, current, measurable and improving. It is not a promise of unlimited work, and it is not a marketing program.

Technical search health is included. Search growth is an additional capability. The same distinction applies across the areas below: each is a scoped project or growth capability added when it is part of the business objective.

  1. Unlimited redesigns

    Routine changes and minor UX corrections are included. New templates, redesigned sections and new features are scoped as defined work.

  2. Unlimited content production

    Routine business and content updates are included. A structured content program is a separate capability.

  3. Full SEO growth

    Technical search health is included. Search growth, with research, new content and authority work, is added separately.

  4. Paid media

    Campaign management is a separate capability, and media spend is always billed separately.

  5. Social media

    Planning, producing and managing social channels is a separate capability.

  6. Lifecycle marketing

    Form and routing health are included. Designing and running email and lifecycle journeys is separate.

  7. Custom application development

    Bespoke application features, logged-in experiences and complex integrations are scoped as project or strategic work.

Buyer checklist

Use these statements to compare website management providers. A professional provider should be able to say yes to each of them, or explain clearly why a point does not apply to your site.

Ownership and exit

  • The domain and core accounts are in our name, or in accounts we control
  • We have a written list of every system the site depends on
  • The agreement defines who owns design, code and content
  • There is a documented transfer path if we leave

Operations

  • Changes go through a defined release process with a way to roll back
  • We can see a record of what changed and when
  • The site is monitored for uptime, errors and expiring certificates
  • Platform and security updates happen on a routine cadence
  • Backups exist and restoration has been tested

Search, speed and access

  • Indexing, sitemaps, canonicals and redirects are checked routinely
  • Structured data matches what is visible on each page
  • Performance is measured for real visitors and regressions are fixed
  • Keyboard use, contrast and form labels are checked after changes

Leads and measurement

  • Forms are tested end to end, and failures are shown honestly
  • Our conversions are defined, documented and verified after releases
  • Tracking respects visitor consent where it is required
  • Someone would notice if leads or conversions stopped arriving

Scope and reporting

  • We know exactly what the monthly fee includes and what it does not
  • Larger requests are scoped before work starts, not invoiced afterwards
  • Reports show what was found, what shipped and what is recommended next
  • The provider tells us when something did not work

How Colorbull applies it.

Every Managed Website and Strategic Digital Partnership is operated to this standard, at the service level set out in its agreement. Growth capabilities such as SEO, content, paid media and lifecycle marketing are added on top when they serve the business.

See how your site measures up.

Start with a focused assessment of the property you have now. We review it against this standard, alongside search visibility, conversion path and the opportunities that matter most, before recommending scope.