Changing Website Developers: Ownership, Access, and Handover — A Decision Guide
Switching website developers is a common but risky business decision. The most costly failures aren’t broken pages—they’re lost access, stalled launches, disrupted payments, and months of recovery work. This guide helps owners evaluate scope, tradeoffs, provider questions, and when to bring Grover Web Design (GWD) in to manage the handover.
Quick decision checklist: Is this a minor handover or a full replacement?
- Minor handover: Same platform, no custom integrations, active hosting and domain control, present credentials, and a short list of straightforward tasks (point DNS, add admin user, hand off backups).
- Partial replacement: Some custom code, third-party connectors, or payment flows that likely need review; staging environment required; moderate risk to uptime or data.
- Full replacement: Legacy or undocumented code, missing credentials (domain, email, payment), custom portals or integrations, potential compliance (HIPAA, PCI), or evidence of compromise—plan for a formal project with security, QA, and data migration.
Primary assets you must own or control (and why)
Below are the canonical assets every business should control before or immediately after a developer change. If a line item is missing, treat the handover as higher risk and budget time and money to resolve it.
| Asset | Who should own/control it | Why it matters |
|---|---|---|
| Domain registrar account | Business (owned by an executive or company account) | Without it you cannot change DNS, move hosting, renew, or prevent domain loss. |
| DNS control (hosted at registrar or separate DNS provider) | Business | DNS points traffic, email, and integrations; misconfigurations cause downtime. |
| Hosting account / server root | Business or company billing owner | Where files and site configuration live; needed for backups, restores, and security. |
| CMS admin user(s) (WordPress, Shopify, etc.) | Business with at least one super-admin account | Day-to-day site edits, plugin updates, and user provisioning require CMS access. |
| Code repository (GitHub, GitLab) and SFTP/SSH | Business or company-controlled org account | Source-of-truth for code; necessary for CI/CD, audits, and rollback. |
| SSL certificate management | Business when possible | Needed for HTTPS renewals and security; tied to hosting or DNS. |
| Payment processors, merchant accounts (Stripe, Square, PayPal) | Business (business owner or finance contact) | If payments are interrupted, revenue and reputation suffer. |
| Analytics & ad accounts (Google Analytics / GA4, Google Tag Manager, Ads, Meta Business Manager) | Business with admin roles granted | Loss of access blocks attribution, retargeting, and performance audits. |
| Email provider & service accounts (Google Workspace, Microsoft 365) | Business | Email access, password resets, and user management depend on this access. |
| Third-party APIs & integrations (CRMs, fulfillment, custom APIs) | Business or authorized technical owner | Missing credentials break critical business workflows. |
| Backups and site snapshots | Business should receive copies | Essential for fast recovery and as verification of deliverables. |
| Documentation, credentials ledger, change log | Business | Reduces onboarding time for the replacement provider and limits repeated questions. |
Common hold-ups and practical remediation
- Developer controls the domain or registrar: Ask for transfer authorization or a signed escrow of EPP code. If the developer refuses, escalate with the registrar—provide proof of ownership (business incorporation docs, trademark, email history). Consider legal counsel if necessary.
- No code repository or messy file system: Require an export of the site (files and DB) and a code snapshot. If the repo is private under the developer account, ask the developer to transfer the repository to a company-owned account or invite company admins to the repo.
- Unknown custom integrations: Run an asset inventory and map each integration to a business owner. Plan a discovery sprint with the new developer to re-key or rotate credentials and test connections in staging.
- Hacked or compromised site: Do not transfer until the site is cleaned and you have clean backups. Bring in a security specialist or choose a provider with malware recovery experience.
Questions to ask any prospective new developer (and why)
- Who will hold the domain, hosting, and repository accounts after work is finished? (Avoid answers that say “I will keep them for now.”)
- Do you use company-owned or client-owned billing for hosting and third-party services? (Client-owned billing gives you control.)
- How do you handle credential handoff and documentation at project close? (Look for a checklist, vault guidance, and a mandatory handoff delivery.)
- Can you provide references for previous handovers? (Ask for one example where transfer was needed and how they solved missing credentials.)
- What is your change/rollback plan if production deployment fails? (Staging, immediate rollback, and backups are essential.)
- Will you add our team to code repositories, hosting, analytics, and ad accounts before final payment? (Insist on admin roles being granted.)
- Do you offer an SLA, monitoring, or retainers for ongoing support post-handover? (If you lack internal ops, this mitigates risk.)
Project brief template for a secure handover
Use this short project brief to get quotes and compare providers on an apples-to-apples basis.
Objective: Transfer full operational control of website assets, validate integrity, and reconfigure integrations so business retains ownership and site downtime is minimized.
Deliverables:
- Verified list of assets and current owners (domains, DNS, hosting, code repo, CMS admin, plugins, integrations).
- Transfer or documented access to domain registrar, hosting account, repository, and CMS with admin users created for business contacts.
- Full site export (files + DB) and at least two point-in-time backups delivered to client storage.
- Staging environment with successful smoke tests: forms, payments, logins, APIs, and a sample SEO crawl.
- Post-handover runbook (credentials mapping, maintenance tasks, renewal dates, contact list) delivered as a PDF and in editable format.
Acceptance criteria: Client or appointed IT lead confirms access and signs acceptance. Production rollback tested and documented.
Timeline: Discovery (3 business days), Access resolution (up to 10 business days depending on registrar transfers), Staging validation (3–5 business days), Final transfer and acceptance (1–3 business days).
Security: Rotate keys and API credentials after transfer, require MFA on all admin accounts, and deliver a short security checklist.
Cost & time tradeoffs: DIY vs small agency vs full-service firm like GWD
Choose based on risk tolerance, internal bandwidth, and the value of uninterrupted business operations.
| Approach | Typical cost | Risk profile | Good for |
|---|---|---|---|
| DIY (internal IT or business owner) | Low monetary cost, high time cost | High unless you have sysadmin experience | Minor transfers: known domain & hosting, no custom integrations |
| Small independent developer | Moderate | Medium—depends on developer discipline | Small sites, clear codebase, limited integrations |
| Full-service agency (e.g., GWD) | Higher; includes process, QA, security | Lowest—structured handoff, documentation, SLA options | Custom platforms, commerce sites, payment flows, HIPAA/PCI needs |
When to hire Grover Web Design
Consider hiring GWD when any of the following apply:
- Custom integrations (CRMs, shipping, billing, internal portals) need a discovery and credential rekeying.
- There’s missing or contested ownership of domains, repos, or hosting.
- Your site handles payments, PII, or regulated data and requires secure handoff plus compliance checks.
- You need a firm SLA, monitoring, and a documented runbook so future developer changes are low-friction.
We provide a secure handover service that combines discovery, credential consolidation, staging verification, and a final acceptance sign-off. See our services overview and our custom web development page for scope and examples. If SEO continuity matters, our SEO services ensure tracking, redirects, and search health migrate correctly.
Sample negotiation and contract clauses to insist on
- Ownership clause: All project deliverables (design files, code, credentials, and documentation) become the client’s property upon final payment or upon mutually agreed milestone completion.
- Access & transfer clause: Developer will transfer or grant admin-level access to domain registrar, code repository, hosting, analytics, ad accounts, and payment processors within X business days of final invoice.
- Escrow or staged release: Use milestone-based payments or escrow to ensure the developer completes transfer obligations before final funds are released.
- Rollback & backups: Developer must supply production-ready backups and a tested rollback plan before major changes or final acceptance.
- Security & MFA: Developer will enable multi-factor authentication on all accounts and rotate credentials at handoff.
FAQ
Q: The previous developer says the domain is registered under their email—what do I do?
A: Request the EPP code and a formal transfer. If the developer refuses, gather proof of business ownership (company registration, trademark filings, billing history) and contact the registrar. As a precaution, prepare for a transfer window—some registrars impose waiting periods.
Q: I don’t have access to Google Analytics or Ads—can the new developer recreate tracking?
A: They can recreate tracking, but losing historical data hurts performance analysis. Try to regain admin access with account recovery (authorized email, documentation). If recovery isn’t possible, add new analytics and tag manager immediately and export any available historical reports from previous providers if they can be reached.
Q: How long does a secure handover typically take?
A: A straightforward transfer can take 3–10 business days. Transfers that involve registrar ownership disputes, credential recovery, or site cleanups can take 2–6 weeks. Build contingency time into your project plan.
Q: What if the site is hacked?
A: Don’t reuse credentials, take the site offline if needed, obtain clean backups, and perform a malware clean and security hardening before transfer. An agency-level recovery and hardening typically includes scans, server config changes, and a monitoring window post-transfer.
Q: Can I require the outgoing developer to document everything?
A: Yes—contractually require a credentials ledger, explanation of custom code, deployment steps, and a short security checklist. If the developer resists, use milestone-based payments or escrow to ensure delivery.
Next steps — an actionable 30-day handover plan
- Day 0–3: Run an asset inventory. Record where domains, hosting, repos, and key accounts are registered and who has access.
- Day 3–7: Request credential handover and confirm backups. Create company-owned accounts where possible and invite the outgoing developer to transfer.
- Day 7–14: Put a staging environment in place under company control. Test forms, payments, APIs, and pages. Resolve any failing integrations.
- Day 14–21: Perform security checks, rotate keys, enable MFA, and verify SSL renewals. Prepare final acceptance checklist.
- Day 21–30: Complete transfer, run a final smoke test, sign acceptance, and set up a short support window with the new provider.
Changing developers can be smooth if you treat it like a small project: inventory, ownership transfer, staging validation, and documented acceptance. If any step is unclear or you discover missing credentials, contested ownership, custom integrations, or compliance needs, that’s when hiring an experienced agency pays for itself.
