VANKPA
Start a project

Website development

Keep control of your website.

Who should own your website domain and hosting accounts?

Founder checking account access at a modern oak desk

The decision

The business should retain administrative control of its domain and essential website accounts. A provider can manage operations through delegated access, but ownership should survive a staff change or the end of an engagement. Account control belongs in the project brief.

In practice

A clinic that cannot access its registrar may be unable to change DNS or recover a renewal failure. Establish the owner before a redesign starts. Separate domain registration, DNS, hosting, email, and website administration because they may be managed by different organizations.

Put it into practiceYour next checks
  1. Create an account register showing the service, business owner, billing contact, renewal date, and recovery method.
  2. Store credentials securely rather than in a shared spreadsheet.
  3. Confirm delegated access and a handover checklist before a provider begins making changes.

When to take the next step

Review ownership before changing providers or renewing a major engagement. Confirm that a business-controlled account can recover access without depending on one outside contact.

Questions clients ask

Should the agency register the domain for us?

It can assist, but the business should be the account owner and retain recovery access.

What should a handover include?

An account map, access confirmation, billing responsibilities, and instructions for routine administration.

A worked scenario

Consider a growing contractor changing web agencies. The useful outcome is to keep business-controlled access to critical accounts. This is a planning example, not a reported client result. The team needs a decision that can be checked against real work, rather than a feature list that looks complete during a presentation. The starting question is whether the proposed approach changes that particular task in a way the people doing it can recognize.

In this situation, a former supplier being the only person able to renew the domain is the failure to guard against. Ask the responsible person to demonstrate an ordinary case and one difficult case using current records or safe test data. Record what they expect to happen, what actually happens, and where they need another person to intervene. Those observations establish the scope for this example; they do not justify an assumed improvement percentage or a guaranteed business result.

Decision checkpoints

Evidence to collect for this scenario
CheckpointPractical actionEvidence to retain
PrepareIdentify the domain registrant and renewal contact.The approved scope, relevant source records, and unresolved questions.
VerifyMove billing and administrator access into company-controlled accounts.The test case, expected result, observed result, and correction needed.
OperateTest recovery using an authorized backup administrator.The responsible owner, completion record, and next review trigger.

Use these checkpoints to keep business-controlled access to critical accounts; they are a sequence of decisions, not a promise of a particular schedule. A completed document or screen is not enough if the underlying action still fails. Keep unresolved items visible and describe which ones prevent progression. The evidence can be a small test record, an approved mapping, or a reviewed example. It should be understandable to someone who was not present when the work happened.

Measure the useful result

A useful check for this topic is critical accounts with two authorized administrators divided by all critical accounts. The numerator is critical accounts with two authorized administrators; the denominator is all critical accounts. Define the sampling window, exclusions, and source of each count before interpreting the result. If only selected examples can be reviewed, describe them as a sample. Do not present a small reviewed group as a complete picture of the business, and do not assign a target simply because a round number looks persuasive.

The measure helps reveal whether the team can keep business-controlled access to critical accounts, but it does not explain every cause of success or failure. Inspect the underlying cases alongside the summary. If the count changes after move billing and administrator access into company-controlled accounts, check whether the operating result changed or the counting method changed. Retain enough context to explain the difference. When records are incomplete, state the limitation and use a direct task review instead of manufacturing a precise-looking estimate.

Step 1: Prepare the evidence

The first practical move is to identify the domain registrant and renewal contact. Start with the smallest set of examples that covers the important variation in this scenario. Include an ordinary case, a case with missing information, and a case that requires intervention. Describe the intended result before reviewing the current behavior. This keeps the preparation focused on the outcome: keep business-controlled access to critical accounts.

For a growing contractor changing web agencies, the person responsible for the source information should take part in preparation. Ask that person to confirm which information is authoritative and which points still need a decision. Record those uncertainties beside the scope instead of hiding them in a general assumption. Preparation is complete when another team member can follow the agreed example and explain what evidence would allow the work to continue.

Step 2: Test the difficult case

The next move is to move billing and administrator access into company-controlled accounts. Compare expected behavior with observed behavior in the same test, rather than comparing two descriptions written at different times. Pay particular attention to a former supplier being the only person able to renew the domain. A demonstration that works only for its author does not establish that the intended user can complete the task. Let the reviewer attempt the work with the instructions they would normally receive.

For this check, retain the input, the relevant condition, and the final disposition. A screenshot can illustrate the state, but the record also needs to explain what the team expected and why the result matters. If ownership cannot be established before a transfer, hold the decision open and send it to someone with the authority to resolve it. Retest the changed case after correction; an agreement to fix something is different from evidence that the correction works.

Step 3: Assign operating ownership

The operating move is to test recovery using an authorized backup administrator. A successful initial test should lead to a repeatable responsibility, not a permanent dependency on the person who built the solution. Name the person who reviews the result, the person who can change the rule, and the person who responds when the task fails. In this scenario, each responsibility contributes to the same outcome: keep business-controlled access to critical accounts.

Give the operator a short record of what healthy work looks like and what requires intervention. Include the warning case of a former supplier being the only person able to renew the domain, together with the relevant records and support route. The procedure should be usable during normal work, not only during a formal review meeting. Check that an authorized backup person can follow it before treating the approach as ready for broader use.

Handle exceptions deliberately

The specific pause condition is that ownership cannot be established before a transfer. Make the pause visible to the person doing the work and to the person responsible for resolving it. Preserve the relevant context so investigation does not depend on memory. A stopped case is still part of the process; it needs a status, an owner, and a safe route back into ordinary work after the uncertainty is resolved.

Before restarting, establish whether a former supplier being the only person able to renew the domain affected only this case or indicates a wider rule problem. Correcting one record may be appropriate for an isolated exception. A recurring pattern may require changing the definition, interface, routing, or review procedure. Test the restart against the original case and one related variation. Record the reason for the change so later reviewers can distinguish a deliberate decision from an unexplained workaround.

Plan your next step.

Discuss your projectBrowse all insights