AW Prod

26 September 2026 · AW Prod

Small-Business Website Maintenance Handoff: What the Owner Needs to Keep

Paper-textured illustration of an ownership checklist, teal access key, maintenance calendar and backup archive box linked by a coral dotted route.

A website can be ready to launch yet difficult to maintain. The domain renewal notice may go to a former employee, the owner may be locked out of hosting, or nobody may have tested the backups. A maintenance handoff identifies who controls each service, who does routine work and how the business recovers from a failure. The owner needs control and a clear process, even when a specialist performs the technical tasks.

Start with an ownership register

Make one register for the services the site depends on. For each, record the provider, business account holder, administrator, renewal or review date, support route and location of access instructions. Keep passwords and recovery codes in a secure credential store, separate from the handoff document.

The distinction between a domain and its website is especially important. The registrar manages the domain registration, while DNS settings direct traffic to services such as the website and email. Those settings may be managed through the registrar or another provider. ICANN explains that registrants manage domain settings through their registrar and have a right to information about managing, renewing, transferring and restoring a registration. The owner should know which business-controlled account holds the registration and which account controls DNS.

Include these entries where they apply:

Add any other dependency whose failure would stop the site operating or delay recovery. If one provider supplies several services, keep separate entries so a problem does not hide behind a single provider name.

Keep owner access separate from working access

The business should retain an account it can recover for the registrar, hosting and other essential services. A developer needs enough access to do agreed work, but that access should be assigned to a named role or individual and reviewed when the work ends. Avoid making a shared developer login the business’s only way into an account.

For each service, write down who can add users, change billing or renewal settings, edit production configuration and request support. These are different powers. A content editor may need to update a page without being able to alter DNS. A developer may need deployment access without owning the domain registration. The FTC’s small-business cybersecurity guidance recommends controlling access, limiting sensitive access to people who need it, using multifactor authentication and keeping software updated.

Test owner access during the handoff. Ask the owner to sign in through the normal route, confirm that recovery messages reach a business-controlled address, and locate the provider’s support path. Do not place passwords in an email or a shared project file to make the test convenient. Record that access was verified, by whom and when.

Also document the exit procedure: who removes a departing contractor’s role, who rotates any shared secret that cannot be assigned individually, and who checks that scheduled jobs still work afterward. An access list that is accurate only on launch day will not protect continuity.

Put renewals and support within reach

For every recurring service, record the renewal date or billing review date, the business person who receives notices, and a second person who can act if that person is away. Confirm these details inside the provider account rather than relying on an old invoice. The register should say where the owner can find the provider’s support channel and what account information support may require; it need not reproduce private account data.

Include dependencies that are easy to overlook: domain registration, hosting, form delivery, licensed software and any service used to build or deploy the site. Where a service renews automatically, record that setting and the person responsible for checking the resulting notice. Where it does not, give the owner enough lead time to decide whether to renew. A calendar reminder is useful only when it has a named recipient and a clear action.

Agree on a monthly health check

A monthly review can be short, provided somebody owns it and records the result. Use a dated checklist with a space for findings, the person assigned to each fix and a follow-up date. A practical pass includes:

Assign the checklist to a person, even if a provider performs some of the underlying tasks. “The host handles it” does not tell the owner who checks a failed backup notice or approves an update. After a significant content or structural change, add a targeted check of the affected pages rather than waiting for the next monthly review. Google recommends verifying site ownership in Search Console and checking it around once a month or after site content changes.

Keep the maintenance record distinct from launch acceptance. It tracks updates, incidents, access changes and checks after launch.

Prove the backup can become a working site

A backup entry is incomplete if it says only “automatic.” The handoff should identify what is copied: site files or deployable code, database content, uploaded media and any configuration needed to rebuild the service. Some elements, such as provider settings or credentials, may require separate secure documentation. The UK National Cyber Security Centre’s small-organisation guidance includes websites among the data a business may need to back up and advises checking that a backup contains the important data and can be restored.

Have the maintainer perform a restore test in an isolated environment, using the documented procedure. Check that the restored pages open, essential media appears and an authorized person can reach the administrative area. Test forms carefully so a restored copy does not send real enquiries or messages. Record the backup used, the test date, who performed it, what worked and what remains unresolved. Repeat the test after material changes to the site or its backup method, and set a recurring review date.

The restore instructions should also tell the owner where the backup is held, who can authorize its use and which provider can help if the usual maintainer is unavailable. They should be detailed enough for a replacement professional to begin, without exposing live secrets in a widely shared document.

Write an escalation path before there is an outage

Give the owner a short incident sheet: the symptoms that trigger a call, the first person to contact, the provider support route, the person who can approve a restore or DNS change, and where to find the last backup verified as restorable. Name a business decision-maker and a technical responder. If one person fills both roles, state who covers an absence.

Separate urgent failures from ordinary maintenance. A site that is unreachable, a form that silently loses enquiries or signs of unauthorized access needs prompt investigation. A routine copy correction can follow the normal change process. The owner should know how to report what they observed, when it began and which pages or messages were affected. The responder should record the action taken and what was verified afterward.

Put monthly checks, renewal reviews, access reviews and restore exercises on a calendar with a named owner and place to record completion.

For a SaaS subscription in the handoff, retain the supplier source, billing period and plan conditions alongside the renewal owner. A dated pricing record from verifiedpricing.com can be a reference; confirm the applicable terms with the supplier before changing a subscription.

More website planning guides

A Small-Business Website Brief Developers Can Use

Website Content Acceptance Checklist Before a Small-Business Launch