Your website is working. Your provider handles the technical stuff. Then you need to change something, and the person with the login stops replying.
Now a routine update has become a business problem. Who controls the domain? Where is the website hosted? Can anyone restore it? And will changing providers accidentally take down your email?
You do not need to become your own IT department. You do need a clear record of who controls each piece, how your business can regain access, and what you can take with you. Here is how to build that record without touching a single live setting.
Start with control, not just passwords
“We own our website” can mean several different things. Your business might own the copy and photos, license the design, rent access to a website builder, and have no direct access to the domain account.
Those arrangements are not automatically bad. The problem is discovering the limits during an outage or a difficult handover.
Account access, contractual ownership, and the ability to move your website are three separate questions. A login does not settle all three.
Make a website control record
Create a document in a restricted business folder. Record the following for each system: provider name, account holder, authorized users, billing contact, renewal date, recovery method, and support contact. Keep passwords and recovery codes in an appropriate password manager, not in this document.
Your domain registration
Your domain is the address customers type, such as yourbusiness.com. The registrar is the company where that address is registered and renewed.
- Confirm which registrar holds the domain and which account manages it.
- Check that registration details accurately reflect your business or the appropriate legal owner.
- Verify the renewal date, payment method, and renewal notifications.
- Confirm that an authorized person in your business can sign in and manage access.
An agency can manage renewals for you. But you should understand the arrangement and have a documented route to control of the domain if that relationship ends.
Your DNS and business email
DNS is the set of records that directs your domain to services, including your website and email. It may be managed somewhere other than your registrar or web host.
Record who manages DNS and who provides your email. Ask your provider to preserve a current copy of the DNS records in a restricted location.
Do not change nameservers or delete DNS records as part of this check. A website move can disrupt email if the existing email records are not carried over correctly. First document the setup. Make changes only with a reviewed plan.
Your hosting and website platform
Identify both where the site runs and how it is edited. These may be one service, as with a hosted website builder, or separate services.
- Does your business have its own account, or does the site sit inside your provider's account?
- Can the site or subscription be transferred to another account?
- What can be exported, and what would need to be rebuilt?
- Which themes, plugins, fonts, or other assets depend on your provider's licenses?
A hosted platform may export content without exporting the complete working site. A downloadable site backup may still depend on paid licenses or external services. Ask about those limits before treating an export as an exit plan.
Your connected services
Include booking tools, form services, analytics, Google Business Profile, payment services, and any system essential to serving customers. For each one, identify the business administrator and the provider's role.
Use individual user accounts and delegated access where available. Sharing one master login makes it harder to remove access cleanly or understand who changed something.
Check recovery before you need it
Ask an authorized business administrator to sign in through each provider's official website. Confirm that the account has the permissions you expect. Viewing a dashboard is not the same as being able to manage users, billing, or transfers.
Enable multifactor authentication where available and store recovery codes securely. Establish a backup authorized administrator or another documented recovery route appropriate to the service.
Watch for circular dependencies. If the only way to recover your domain account is through an email address on that same domain, a domain problem could also block account recovery. Where supported, set up a secure recovery method that does not depend solely on the affected service.
Do not remove your existing provider's access until replacement access and responsibilities are confirmed. This is a continuity check, not a surprise lockout.
Ask what a backup actually restores
“Backups included” is a starting point, not a recovery plan.
For a typical CMS website, a useful backup may need both site files and a database. A store may also need a plan for orders placed after the last backup. Connected booking or CRM data may live elsewhere entirely.
Ask your provider:
- What is backed up, how often, and for how long?
- Where are backups stored, and who can retrieve them?
- What happens if the hosting account is inaccessible?
- When was a restore last tested, and what worked?
- Who performs recovery, what might it cost, and what is the expected timeframe?
The strongest evidence is a successful restore test, not a screenshot of a backup schedule. Have a qualified provider test in an isolated environment, with outgoing messages, payments, and live integrations disabled. Never overwrite the live site just to see whether a backup works.
Put the handover terms in writing
Review your agreement for ownership, licenses, cancellation notice, export options, transfer assistance, fees, and what happens to data after cancellation. If anything important is unclear, ask for written clarification. Get legal advice if contractual ownership is disputed.
For example, imagine a plumbing company whose domain, hosting, and email are all billed through one freelancer. Moving the website does not necessarily require moving all three services. Separating those decisions can reduce disruption, provided the company knows what depends on what.
A usable handover plan names the person responsible for each transfer and keeps the old service active until the replacement has been tested. Ending billing first and asking questions second is the expensive version.
Send this request to your provider
“We are documenting website continuity for the business. Please confirm who controls our domain, DNS, hosting, website platform, and connected services; what administrator access we have; how account recovery works; and what our backups include. Please also outline the transfer or export process, license dependencies, notice periods, and any handover fees if we change providers. Please do not change live settings yet, and use a secure method for sharing access.”
Your next step: close the biggest access gap
Start with the domain account, then DNS and email, then hosting and backups. Assign one person to maintain the record. Recheck it when staff or providers change and before major renewals.
You can keep technical work delegated while retaining business control. The goal is not a drawer full of passwords. It is knowing that your website can keep operating when the people managing it change.
Need help understanding an unclear setup? Contact SolcoMedia to discuss your access and handover questions. Bring your provider list and agreement, but do not send passwords or recovery codes through a contact form.




