The business should own its essential digital assets

A supplier may configure and manage digital systems, but the client should remain the primary owner of the assets on which the business depends. That includes the domain, website account, analytics property, search tools, business profiles and final brand files.

Ownership does not mean every founder must administer every system. It means the business can verify access, appoint a new specialist and continue operating if a working relationship changes. This is a governance decision as much as a technical one.

The safest default is client ownership with named supplier access, documented responsibilities and a tested recovery route.

Treat the domain as a business asset

The domain controls how customers reach the website and often how business email is delivered. It should be registered in an account controlled by the business, using current organisation details and an email address that will remain available if a supplier changes.

DNS access should be limited to people who need it because incorrect changes can interrupt the site or email. Use multi-factor authentication, keep recovery methods current and document which records support the website, email and verification services.

  • Register the domain in a client controlled account.
  • Enable multi-factor authentication and renewal protection.
  • Use a durable recovery email and store recovery codes securely.
  • Document DNS changes and avoid sharing one password.
  • Confirm that billing and renewal contacts remain current.

Know what can be transferred and rebuilt

Website ownership includes more than a login. The client should know where the source, content, media, hosting configuration and deployment access live. Any licence restrictions or third-party dependencies should be explained before handover.

A managed service can still be appropriate, but the agreement should say what happens if the service ends. Export routes, backups and final asset transfer should be practical rather than implied. A website that cannot be moved creates dependency even when the client technically owns the content.

  • Record repository, hosting and content management access.
  • Identify paid themes, fonts, plugins and external services.
  • Define backup frequency and restoration responsibility.
  • Keep a copy of final brand, copy and media assets.
  • Agree the handover process before the project begins.

Build analytics around the client account

Analytics, tag management and search tools accumulate history that helps the business understand what changed. If those properties sit only inside a supplier account, the client can lose continuity when access changes.

Create the core property for the client organisation and grant the supplier the lowest appropriate role. Define which events matter, how consent is handled and who can change the configuration. Keep raw observations separate from conclusions so reports remain understandable.

  • Use a client controlled Google Analytics or tag account where selected.
  • Verify Search Console with more than one durable owner.
  • Document conversion event names and consent behaviour.
  • Remove access when a supplier or staff member no longer needs it.
  • Avoid collecting data without a clear purpose.

Keep public profiles under business control

A Google Business Profile, commerce account, booking platform or social channel may be central to daily trading. The primary owner should be the real business, with agency or contractor access added through the platform's role system where available.

Do not build a business profile around a personal email that nobody else can recover. Do not give every collaborator the highest permission. Keep a simple register of platforms, owners, administrators, billing contacts and recovery routes.

  • Name a current internal owner for every critical platform.
  • Use role based invitations instead of shared credentials.
  • Review billing, recovery and administrator access regularly.
  • Store brand verification documents in a controlled location.

Use access that survives normal change

A small business does not need a complicated governance programme, but it does need a repeatable access model. Keep an asset register, use a password manager, enable multi-factor authentication and define who approves changes that affect the website, email, payment or customer data.

At handover, test the account from the client's side rather than assuming an invitation worked. Confirm ownership, billing, recovery and documentation. A clear exit path protects both the client and the supplier because responsibility is visible.

  • Maintain a short register of critical accounts and owners.
  • Use individual logins and remove stale access.
  • Test backups and recovery rather than only creating them.
  • Review ownership during staff, supplier or company changes.
  • Include access and asset transfer in project acceptance.