Website handover: what an agency should hand over and how to check - Zephyra Studio
A website handover is the moment everything that makes up the site moves into your hands, and it works best as a written record with a list of what was handed over and a test that every access works. The goal is that after the handover you can change the passwords, restore the site from a backup and carry on without the agency if you need to. Below is what gets handed over, what to check yourself on the same day and what the record should contain.
What gets handed over: six groups
- Domain and DNS: your company is the registrant, and the list of DNS records (A, CNAME, MX, TXT) is delivered in a document. For .rs domains, a transfer between accredited registrars uses an authorisation code that RNIDS sends to the registrant or administrative contact.
- Hosting: an account in your name, with your own access, and details of when it is paid until and how it renews.
- The site: source code in a repository you control, the database and the media files. For WordPress that means the files and the database together.
- Admin accounts: your own administrator account in the content management system, not the agency's shared one.
- Licences and third parties: a list of themes, plugins, fonts and images with the licence and whose account it is under.
- Google tools: Search Console, Analytics and Business Profile where you hold the owner or administrator role, not only access.
Documentation that should arrive with the site
- A list of technologies with versions (content management system, theme, plugins, PHP or other runtime version).
- A short guide to how the site is published and updated, and where the settings are.
- A list of accounts and third-party services (form email, anti-spam, maps, payments) with the name of the account holder.
- Expiry dates: domain, hosting, SSL certificate and plugin licences.
- A support contact and how to report a problem after the handover.
The backup and a restore test
According to the WordPress documentation a full backup has two parts: the files (core, themes, plugins, uploads, wp-config.php) and the database. It recommends keeping several recent backups in different places, for example on the host, in the cloud and on your computer.
The same documentation advises making a manual backup now and then to check that the automatic ones really work. So put a real test into the handover: have the agency show that the site can be restored from a backup, or do it on a staging copy. More in the guide on backing up a website.
What you check yourself on the same day
- Log in to the hosting, the content management system and the Google tools with your own account, and change the passwords you were sent.
- Send a test message through every form and check that it arrives at your address.
- Open the site on a phone, outside your home network, and go through the main pages.
- In Search Console check whether you are a verified owner, and add your own DNS verification if the agency's is the only one.
- Check that the sitemap and robots.txt exist and that the site is not accidentally blocked from search. The full pre-launch list is in the launch checklist guide.
- Put the expiry dates of the domain, hosting and SSL certificate in your calendar.
What the handover record should contain
- The date, who hands over and who receives, and the name of the site.
- A list of everything handed over from the six groups above, marked "handed over and checked".
- A list of the agency's remaining obligations, if any, with a deadline.
- What is included after the handover (support, bug fixes) and for how long, exactly as agreed. Do not assume, agree it.
- Signatures of both parties.
How passwords are handed over
Passwords should not be sent in plain email. It is better to open the accounts in your own name and invite the agency as a user, or to use a password manager that supports secure sharing, and then change everything you received after the handover.
If the agency will not hand something over
Start from the contract and a written request with a list and a deadline. Transfer the domain and Search Console access first, because they are the hardest to get back. What belongs to you depends on the contract, which the guide on website ownership covers.
The order of a handover
- A few days earlier the agency sends a list of everything it is handing over, so you have time to review it.
- On a shared call or meeting you go through the list and try every access live.
- You change the passwords and remove shared accounts. The agency stays on as a user only if that is agreed.
- A trial restore of the site from a backup is done.
- A record with the list of what was handed over is signed.
- A few days later, check that forms, email and backups work without the agency.
Who should take part
The handover needs the person who decides in the company, the person who will actually edit the site content and a technical person from the agency. The first signs the record, the second checks that they can do what they need, and the third answers questions while the access is still in their hands.
The most common handover mistakes
- The domain is still in the agency's or the developer's name.
- There is one shared admin account that everyone uses.
- Backups of the site exist only on a host the agency pays for.
- Paid plugin licences are tied to the agency's account.
- Nobody wrote down the expiry dates of the domain, hosting and SSL certificate.
- Search Console is verified only with the agency's token.
When maintenance stays with the agency
A handover does not have to mean the end of the relationship. If the agency keeps maintaining the site, everything above still applies: the accounts stay in your name and the agency works as a user with agreed access. That way you can change or remove access at any time without negotiating.
Deadlines and support after the handover
Agree in writing how long the period lasts in which the agency fixes errors that came from its work, and what counts as an error as opposed to a new change that is paid separately. Do not assume the number of days, write it into the record.
Also agree how a problem is reported (email, a dedicated channel or a ticket system), who answers and within what time, so that after the handover you are not hunting for the right person through old correspondence.
Related guides
Sources
Key takeaways
- A handover is a written record with a list of what was handed over and a test that every access works.
- Six groups are handed over: domain and DNS, hosting, the site with its database, admin accounts, licences and Google tools.
- A full backup holds both the files and the database, and must be test-restored.
- Passwords are not sent in plain email, and everything received is changed on the same day.
Conclusion
The costliest mistake in a handover is assuming everything already works. Set aside a day after the handover to test every access yourself, while the agency is still available to fix whatever does not.
Frequently asked questions
A website handover is the moment everything that makes up the site moves into your hands, and it works best as a written record with a list of what was handed over and a test that every access works. The goal is that after the handover you can change the passwords, restore the site from a backup and carry on without the agency if you need to. Below is what gets handed over, what to check yourself on the same day and what the record should contain.