
Taking over a website does not end when it goes live. This website handover checklist helps your business verify the domain, hosting, source code, admin panel, backups and third-party accounts to reduce the risk of access problems later. Use this guide to plan the handover step by step.
A website handover checklisthelps your business take control not just of the website delivered by an agency or development team, but also of the accounts, data and technical decisions behind it. Being able to access a live website is not the same as being able to manage it independently.
For example, receiving an admin panel password does not mean the domain account or hosting invoice is in your business's name. This guide from KepezWeb brings together pre-handover preparation, access checks, file transfers and acceptance testing.
Why distinguish between access and ownership during handover?
Access means having permission to use an account. Ownership means controlling its registration details, billing, renewal notices, recovery email and permission settings. Having administrator access to a supplier-owned account does not necessarily mean you can manage that account on behalf of your business in every situation.
Make this distinction particularly clear for domains, hosting, source code repositories, email services, analytics tools and payment systems. Wherever possible, accounts should be registered using your business email address, with the agency or developer given the permissions they need through their own user account.
Access to DNS management alone is not enough. You should also check the domain registrar account, renewal notices, recovery contact details and multi-factor authentication settings. For a closer look at the decisions involved, see our guide to choosing a domain name .
Website handover checklist: Verify account ownership
Start by creating a single inventory of every service your website relies on. Rather than simply asking for the passwords that come to mind, record the account owner, permission level, recovery method and person responsible for renewals for each asset.
| Asset | What to take over | How to verify it |
|---|---|---|
| Domain and DNS | Registrar account, authorised contact details, DNS zone and renewal settings | Sign in with your business account and view the domain and DNS records. |
| Hosting or cloud server | Control panel access, billing permissions, server details and backup settings | Sign in with your own user account and check the management options. |
| Admin panel | Administrator account, user roles, content settings and form settings | Create a test user and review their permissions. |
| Code and data | Source code repository, database backup, media files and release notes | Access the repository, download the files and verify that the backup can be opened. |
| Third-party services | Analytics, email, CDN, security, payment and integration accounts | Check the account owner, user roles and notification addresses. |
If a service sits within an agency's business account, confirm in writing whether it can be transferred and what the alternative would be. Some services may require adding a new user for your business, or creating a new account and migrating the configuration, rather than transferring the existing account.
Test administrative and technical access individually
Listing an access point is not enough: an authorised person from your business should test it on their own device. Creating a separate user account for each person responsible, rather than sharing passwords during handover, improves security and accountability.
- Full administrator permissions in the content management system or custom admin panel
- Hosting control panel, SFTP or SSH access, and the database management tool
- Permission to view and download the source code repository, and to deploy where required
- Access to the live environment and any test environment
- The inbox that receives form notifications, plus SMTP or email service settings
- Permissions in search performance, traffic analytics and tag management accounts
- CDN, firewall, cache and SSL certificate management
API keys, email passwords and recovery codes should not be included in a plain-text document. Obtain them through your business's chosen secure password manager or a controlled sharing method. If technical teams have previously used these keys, consider rotating them under a plan that avoids disrupting live services.
Defining acceptance criteria at the start of a new project reduces uncertainty at handover. For pages, roles, content, integrations and approval responsibilities, see our guide to preparing a web design brief .
Files and technical documentation to collect
A file handover involves more than receiving a design folder on your computer. It should provide the technical materials needed to update, migrate or troubleshoot the website, with clear explanations. The files required will depend on the technology used, but most projects should consider the following.
- The complete source code and access to the repository containing any version history
- A database export and folders containing uploaded images, documents and media
- Design source files, logo files, font details and licence information
- Technical notes covering installation, deployment, rollback and restoration from backup
- Server requirements, software versions, dependencies and configuration notes
- An inventory of forms, integrations, cron jobs and notification workflows
- Notes on admin panel user roles, content updates and basic operation
A project delivered with its source code may require a different handover approach from a proprietary software service. If the website uses a closed platform, admin permissions, data export options, configuration details and service terms become more important than source code. Check the relevant provider's terms for the usage and transfer conditions of themes, plugins, images and software licences.
Run acceptance tests before going live
At the final handover stage, carry out technical and operational checks together. The aim is not just for the website to look right on screen, but for your business to manage its essential operations independently. Where possible, list each check in the handover record.
- Use your business account to sign in to all critical control panels in a different browser or private browsing session.
- Update and publish a low-risk piece of content, such as a page, menu, image or contact detail.
- Test the contact form and check that the notification reaches the correct inbox.
- Verify that the backup file exists and can be opened in a suitable test environment.
- Carry out sample checks of the mobile layout, basic browser compatibility, redirects and error pages.
- Review accessibility features such as keyboard navigation, alternative text and form fields. See our website accessibility checks .
For e-commerce websites, also review product, stock, order notification, shipping, invoicing and payment workflows. Rather than testing with live payments, use the provider's test environment where available and a safe testing method agreed within the project scope. To understand which fields are covered by the data flow in projects connected to accounting software, see our guide to e-commerce accounting integration .
Document the handover and clarify ongoing responsibilities
Once the technical handover is complete, create a concise but detailed handover record. It should make clear which access has been provided and which items still need attention. For each asset, you can record the account name, authorised user, access verification status, recovery contact details, licence or subscription notes, and the person responsible.
Separately specify who is responsible for ongoing work such as maintenance, content entry, security updates, hosting renewals and resolving faults. Read the contractual handover scope, usage rights and ongoing service terms alongside the project documentation. If anything needs interpretation, seek advice from the appropriate specialists.
Finally, review temporary user accounts and access that is no longer needed. Before removing a user or changing a password, confirm with the technical team whether any connected services still rely on that access. This helps reduce unnecessary permissions while managing the risk of service disruption.
Frequently Asked Questions
Is receiving the domain password enough to complete the handover?
No. You should also check which registrar account holds the domain, who owns that account, where renewal notices are sent and who can manage the DNS records.
Is the website fully handed over if the source code is not provided?
That depends on the project's technology and contractual scope. For custom development, source code, the database and installation notes may be important. For closed platforms, the key considerations are admin access, data export options and the extent of the configuration information provided.
How should analytics tools set up under an agency account be managed?
Ask for a user to be added for your business with the appropriate permission level. Where the platform supports it, transfer ownership and notification settings to your business account. If that is not possible, document the access model and the people responsible in the handover record.
Which access should be removed after handover?
Review temporary accounts, unused personal user accounts and permissions outside the project scope. Before removing access, check the service accounts, integrations and automated processes used by the live website.
Conclusion and Next Steps
You can adapt this checklist to the scope of a new website project or the handover of an existing site. KepezWeb can help you assess your web design and technical handover needs together. To discuss your project, contact us using the quote request form.


