Skip to content
Web Design

Website Handover Checklist: 8 Things to Get From Your Agency

Welda Team8 min read6 June 2026

A website handover checklist means asking your agency for eight complete items once your project wraps up: full access to every panel, domain and hosting account details, the source code and a backup, the licenses in use, ownership of Google Analytics and Search Console, privacy/data protection pages, a usage walkthrough, and a written handover record. If even one of these eight is missing, you can lose partial or full access to your own site the moment your relationship with the agency ends. This article walks through why you need each item, and what we've actually seen happen in the field when businesses skip them.

Why Should Full Panel Access Be the First Thing You Ask For?

Panel access is the set of keys that controls your site's day-to-day operation; without it, you stay dependent on the old agency every time you want to change content, add a page, or fix an urgent bug. The panels you should request are: admin login to the content management system (WordPress, Shopify, etc.), the hosting control panel (cPanel, Plesk, or equivalent), the email management panel, and, if used, any CDN/security service account (like Cloudflare).

What happens if you don't ask for this? The scenario we see most often in the field: a business owner wants to change a single price on a landing page for a summer campaign, but the WordPress password sits with the old agency; they reach out, file a request, the change gets made three days later, and half the campaign window is gone. If they'd had panel access themselves, the change would have taken five minutes.

When and How Should Panel Access Be Handed Over?

Panel access should be handed over in writing, before the project closes out and the final invoice is issued, complete with username/password pairs and two-factor setup details where applicable; "we'll send it once the project's done" isn't good enough, because who decides when it's "done" is left ambiguous. Good practice is to create a separate password manager entry for each panel and transfer it into the business's own password manager account, so access doesn't end up buried in a single email thread.

What happens if you don't ask for this? A business owner made the final payment believing the project was complete, but was told the panel details would follow 'in a few days' — and months went by without them arriving; during that time they couldn't fix even a small typo on the site. Tying the final payment to the date panel access is actually delivered — that is, holding back part of the payment until after handover — is a simple, effective way to prevent this kind of delay.

Should SSL and Security Settings Be Checked at Handover?

SSL certificates and basic security settings absolutely must be checked at handover, because without knowing whose name the certificate is registered under, how long it's valid, and whether it renews automatically, you could one day find your site flagged 'not secure' in the browser. What you should check: whether the SSL certificate renews automatically, whether a security plugin is in place to limit admin login attempts, and who has FTP/SFTP access to the site files.

What happens if you don't ask for this? An SSL certificate that needed manual renewal wasn't renewed after contact with the agency broke down; the site sat live with a 'not secure' warning for several days, and both visitor trust and search rankings took a hit during that window. Writing down clearly, in the handover record, who is responsible for SSL renewal — the business itself, or the agency under an ongoing maintenance contract — eliminates this risk.

Whose Name Should Domain and Hosting Accounts Be Under?

Domain and hosting accounts should, without exception, be registered in your business's own name and its own email address; a domain registered in the agency's name is legally the agency's property, not yours. What happens if you don't ask for this? A case we've seen repeatedly over the years: a business decides to switch providers, and the old agency won't share the domain renewal password or simply stops responding; the domain expires, the site goes dark for a few days, and search rankings take a serious hit during that window. We've also emphasized why domain ownership is a non-negotiable rule, and how to check it, in our website pricing article.

Why Should You Request the Source Code and a Backup?

The source code and a current backup are your site's deed of ownership; without them, moving to another agency down the road can mean starting from scratch. On a custom-built site, this means access to the code repository and a database backup; on a ready-made platform (like WordPress), it means a full backup of all files and the database.

What happens if you don't ask for this? Picture an order system built with custom software whose source code only ever lived with the agency: once that agency closes or contact is lost, even a small change to the system becomes impossible, because the only copy of the code sits on the other side. Putting who owns the source code and the handover terms into the contract in writing at the very start of the project is a particularly critical clause for any business weighing WordPress vs. custom software.

Why Should Licenses (Theme, Fonts, Stock Images) Be in Your Name?

Theme, font, and stock image licenses are the legal basis for your right to use them; if these licenses are registered under the agency's own account, you end up unknowingly using copyright-infringing content on your site the moment the agency cancels or fails to renew that license. A premium WordPress theme can require a license fee of roughly $60-$150 a year; if that license isn't in your name, it's unclear who's supposed to pay for the renewal and who actually renews it when the time comes.

What happens if you don't ask for this? In one case, the stock photo license used on a clinic's site was registered under the agency's personal account; a year after the relationship with the agency ended, the license wasn't renewed, and the copyright holder sent the business a warning notice — leaving the business to deal with a licensing problem it had no contract governing. Ask in writing, at handover, that all license documentation (including purchase receipts) be transferred to you.

Why Does Google Analytics and Search Console Ownership Matter?

Owning Google Analytics and Search Console lets you keep your site's search history and visitor data in your own hands; if these accounts are tied to the agency's Google account, your entire data history stays with the agency, and you effectively start from zero. The correct setup is verifying the Search Console property under your own Google account and granting the agency only user-level access; that way you keep control while the agency still has the access it needs.

What happens if you don't ask for this? A business that stopped working with its agency, and then started with a new SEO agency, requested Search Console access and got no response from the old agency; two years of click and impression data — along with the record of how rankings had evolved — was gone. The new agency essentially started in the dark, unable to show which keywords had made progress and by how much. We cover this in more depth in our Search Console guide.

Why Should Privacy Pages Be Requested at Handover?

Privacy pages (privacy policy, a data processing notice, cookie policy) should be requested at handover in their complete, current form, because they're the proof that your site meets its legal obligations under applicable data protection law — such as the GDPR or, where relevant, Türkiye's KVKK. What happens if you don't ask for this? On one e-commerce site, no data processing notice was ever published for the personal data collected through the contact form; the business unknowingly gathered form data for months, and the gap surfaced only once a complaint was filed. At handover, check both that these pages exist and that their content genuinely reflects your site's actual data flow — a copy-pasted template that doesn't match your real data handling still carries risk.

Why Should a Usage Walkthrough Be Part of the Handover?

A usage walkthrough is what lets your own team make day-to-day content updates once you've taken over the site; skip it, and every small text change keeps you dependent on the agency, which shows up on your invoice as extra support fees. In a good handover process, the agency should give you at least an hour of screen-share training and leave you a short written guide to refer back to afterward.

What happens if you don't ask for this? A café owner called the agency every time they needed to update a menu price and paid a $10-$15 support fee each time; a ten-minute walkthrough would have let them make that change themselves. Adding the training request as a written line item in the handover record heads off this kind of unnecessary cost.

How Should Maintenance and Support Be Defined After Handover?

Maintenance and support terms should be defined in writing right after handover, because 'the project is done' and 'the business can use the site smoothly day to day' are not the same thing. The contract should clearly answer: how many days of free bug-fixing are covered after delivery, what the hourly or monthly maintenance fee is once that period ends, and who to contact — and how — if something goes down urgently.

What happens if you don't ask for this? A business noticed two weeks after handover that its contact form wasn't working; when they reached out to the agency, they got the response 'the project's closed, let's draw up a new quote,' and ended up paying extra for what was a simple form bug. Defining at least a 30-day free-support window in the handover record heads off this kind of dispute before it starts.

Why Should the Handover Record Always Be Signed?

The handover record is the written document proving what was delivered, with what details, on what date, for every item listed above; without it, you have no evidence later if a 'we already gave that to you' / 'we never received it' dispute comes up. A good handover record itemizes the list of panel access delivered, domain and hosting account details, how the source code was handed over, license documentation, and the training date, and is signed by both parties, or confirmed in writing over email.

What happens if you don't ask for this? When one business ran into a dispute with its agency over the claim 'we gave you the domain details,' it had no written proof to point to and spent weeks digging through old email threads. Making clear at the start of the project that the handover record is part of the contract is the simplest guarantee that a corporate website project ends on solid footing.

When Should You Use This Checklist?

Put this checklist on the table no later than before the contract is signed, ideally at the proposal stage; asking for it after handover just gives the agency an opening to call it an extra paid service. When getting a quote for a new project, ask for each of these eight items to be written into the contract as a clause, spelled out under a heading like 'the following will be provided at handover.'

If you already have a site, sit down today and check this list item by item for your own site: which panels do you actually have access to, whose name is the domain under, do you have a copy of the source code? For every item that comes up missing, requesting it in writing from your current agency — even while the relationship is going well — is a healthy step worth taking now, because these requests get much harder to satisfy once the relationship sours.

In short, these eight items may each look small on their own, but together they determine whether you truly own your site. If you're starting a new project, we recommend adding this list as a contract clause; if you already have a site, we recommend closing any gaps now. If you'd like us to walk through your handover process together, or set this list up correctly from the start on your new project, get in touch; in a free initial consultation, we'll identify together which of these items your site is currently missing.

Experience Welda in your own business.

Related posts