You do not need to personally manage every technical account, but your business should know where the important services live and have a recoverable route into them. That prevents one employee or web designer becoming the only person who can keep the website running.

1. Domain registrar

The business should be able to renew the domain, update contact details, manage transfer settings and change DNS when necessary. Use a business-controlled email address and enable strong account security.

2. Website hosting or control panel

For traditional hosting this may be cPanel, Plesk or another control panel. For managed/cloud systems it may be a provider dashboard. You need to know where the files/databases live and how a backup or migration would be obtained.

3. Website administrator account

For WordPress, keep at least one business-controlled administrator account rather than relying solely on the developer's login. The same principle applies to Shopify, Squarespace, Wix and other platforms: the business should hold the owner-level account wherever the platform supports it.

4. DNS and business email

Know who controls DNS and who hosts email. If you use Google Workspace, Microsoft 365 or Zoho, keep those accounts separate and business-controlled. A website migration should not require handing somebody your personal Google or Microsoft password.

5. Analytics, Search Console and advertising accounts

Google Analytics, Search Console, Google Ads, Meta Business assets and other marketing accounts should belong to the business, with agencies invited as users/partners where possible. That makes changing suppliers much easier.

6. Payment and eCommerce services

Stripe, PayPal, merchant gateways, shipping tools and marketplace accounts can affect real money and customer data. They should be controlled by the business rather than created under a developer's personal details.

7. Premium software licences and API accounts

Keep a record of premium WordPress themes/plugins, booking services, SMTP providers, maps/API accounts and other software. Where practical, the client should own paid licences directly so the website does not suddenly lose updates when an agency relationship ends.

Do not share passwords when proper user access exists

Good platforms let you add another user or manager. Use that instead of emailing a master password. Store credentials in a password manager, enable multi-factor authentication and remove old supplier access when a handover is complete.

Use company identities rather than one employee

Where possible, use accounts tied to a durable business email address rather than an employee's personal Gmail account. Then add named staff or suppliers as separate users. This makes staff changes and agency handovers much safer and gives the business a consistent recovery address.

Create a simple website asset register

You do not need a complicated IT system. A short secure record listing the domain registrar, hosting provider, CMS, email provider, analytics, payment gateways, important licences and who currently has access is enough for most small businesses. Review it when a supplier or employee leaves. The aim is to avoid discovering during an emergency that nobody knows where the website actually lives.