Skip to contact form
← BlogBuyer guideAugust 15, 2026 · 11 min read

What should you own after your agency finishes?

A handover checklist for domains, source, hosting, data, analytics, design files, app stores, credentials, documentation and licences.

business should not discover after launch that its agency owns the domain, the production account or the only copy of the source code. Handover is not a zip file sent on the last day. It is a chain of control: the client can access, operate, recover and appoint somebody else to maintain the product without asking a former supplier for permission.

Ownershipispracticalonlywhenthebusinesscontrolstheaccountsandcanusetheassets.

  • The domain registrar and DNS, with renewal and recovery details owned by the business.
  • Hosting, cloud, database, storage and email-delivery accounts used by production.
  • The source-code repository and its administrator access.
  • Apple Developer, App Store Connect and equivalent distribution accounts.
  • Analytics, Search Console, tag management and advertising accounts.
  • Payment, identity, support, mapping and other critical third-party services.
  • A business-controlled password manager or documented transfer process for credentials.

The agreement should identify source code, deployment configuration, database schema and exports, design files, written content, brand assets and documentation. Ask for the production runbook: how to deploy, roll back, restore a backup, rotate a secret and respond when an integration fails. A future team needs context as well as files.

An agency can transfer copyright in custom work while third-party components remain under their own licences. Fonts, photographs, icons, open-source packages, software-as-a-service tools and platform SDKs may be licensed rather than owned. The handover should list these dependencies, their terms, renewal costs and which account holds each licence. “You own everything” is not credible if it ignores the things nobody can transfer.

  1. Sign in using client-controlled credentials rather than the agency's account.
  2. Confirm at least two appropriate people can recover critical accounts.
  3. Verify the repository contains the version running in production.
  4. Run a deployment or documented release rehearsal.
  5. Export important data and test that a backup can actually be restored.
  6. Remove temporary access and record any access the agency keeps for support.

Ownership, licences, account setup, documentation, warranty and ongoing support should be visible before work begins. If a supplier says transfer will be discussed later, ask what specifically cannot be confirmed now. The cleanest arrangement is usually for the client to own core accounts from the start and grant the delivery team the least access it needs.

A contract saying the client owns the work is not enough if the repository, domain or deployment remains inside an inaccessible supplier account. Test ownership by asking whether a replacement team can obtain the source, reproduce a release and operate the product without borrowing one person's login.

  • Domain registration and DNS with current recovery contacts.
  • Source repositories and full history under the client organisation.
  • Hosting, databases, storage and backups with documented billing.
  • Analytics, Search Console, tag management and consent configuration.
  • Apple, Google, payment, email and other vendor accounts.
  • Editable design source, brand assets, fonts and licence records.
  • Environment-variable inventory, deployment steps and support contacts.

Want this kind of thinking on your project?

This is how we work through real decisions. If you're weighing a build of your own, tell us about it — we reply within one working day.