List every account the site depends on, confirm each is registered to the business rather than an individual, and check you can actually log in. Access discovered during a crisis is access you do not have.

The accounts that matter

More than people expect, and each is a point at which the business can be locked out.

Six accounts, frequently created by three different people over five years, several of them registered to email addresses nobody checks.

How the problem forms

Nobody makes a bad decision. It accumulates.

A friend registers the domain during setup because you were busy. A designer creates the hosting under their own account because it was faster. An employee sets up analytics with their work address. The listing gets claimed by whoever had a phone to hand.

Each was sensible at the time and none was written down. Five years later the friend has moved, the designer is unreachable, and the employee has left.

The business is running perfectly on infrastructure it cannot administer.

When it surfaces

Always at a bad moment, because ordinary operation does not require these logins.

You want to move hosts and cannot prove you own the domain. The site goes down and nobody can open a support ticket. A designer you have parted with holds the only administrator account. The listing needs correcting and the verification code goes to somebody who left in 2018.

None of these is a technical problem. All of them are administrative, and all take weeks rather than hours to resolve.

The three questions per account

  1. Whose name is it in? The business, or a person.
  2. Which email address is on it? And does somebody read that address today.
  3. Can you log in right now? Not in theory. Actually, this afternoon.

The third is the one that matters. Businesses routinely believe they have access and discover during a crisis that the password saved in a browser belongs to a computer that was replaced.

Testing it costs ten minutes per account and is the only way to know.

A worked example

A dental practice wanting to redesign after nine years on the same site.

The hosting was straightforward. The domain was not. It had been registered by the practice manager's brother-in-law, who had built the original site as a favour, and who had since moved to another country.

The registration was in his name, at an email address that no longer existed. The practice had never paid a renewal, because he had it on his own card and had simply kept paying, unmentioned, for nine years.

Recovering it required tracking him down, and then a formal transfer process with identity documents because the contact address was dead.

It took seven weeks. The redesign, once started, took four.

Nothing had gone wrong at any point. The arrangement had worked perfectly for nine years and could not survive being changed.

Putting it right

The order that causes least disruption.

Start with the domain, because it is the one that cannot be replaced. Confirm the registrant details, update them to the business, and set the contact address to something the business controls.

Then hosting, then email, then the platform login, then the peripheral tools.

Where an account belongs to a supplier you still work with, the fix is usually not to take it over but to be added as an owner alongside them. That preserves the working relationship and removes the single point of failure.

Where a supplier resists being added, that is information worth having early rather than late.

The document nobody has

One page, kept with your insurance and your incorporation papers.

For each account: what it is, which company provides it, the login address, whose name it is in, which email address it uses, when it renews, and who to contact.

Not the passwords, which belong in a password manager. The map, which is what somebody else needs to find their way.

It takes an hour to compile and it is the difference between a two-hour recovery and a two-month one.

Review it once a year, at the same time as the renewals. Accounts get added quietly, and a map that is three years out of date is only slightly better than none.

What to ask a supplier at the start

Cheaper than fixing it afterwards, and it takes one email.

Ask who the domain will be registered to, and say you want it in the business's name in an account you control. Ask the same about hosting.

Ask what happens to your accounts if you stop working together, and get the answer in writing. A supplier who has thought about this will answer immediately.

None of that is adversarial. Most suppliers prefer it, because the alternative is being chased for access years after a project ended by somebody they no longer have a relationship with.

The ones who resist are telling you something useful before you have paid them anything.

The person who is not you

Worth designing for even in a business of one.

If you were unreachable for a month, could somebody keep the site running, renew what needs renewing, and reach support.

For a sole trader that means one trusted person knowing where the document is. For a business with staff it means a second administrator on every account.

This is not a morbid exercise. The far more common version is a two-week holiday during which a certificate expires, or a hospital stay nobody planned for.

The test is simple enough to run in your head: if you lost your phone and laptop today, which of these six accounts could you still reach, and how.

Doing it before you need to

The whole argument in one line: every account in this list is easy to fix while everything is working and difficult once it is not.

A domain transfer with a cooperative supplier is a form and a code. The same transfer during a dispute is a formal process with documents and delays.

Which makes this an afternoon worth spending on a quiet week rather than a project for the week something breaks.

The domain half of this is set out in picking a domain you will not regret.


Frequently asked questions

Which accounts control my website?

The domain registrar, the hosting account, the email provider, the site's administrator login, analytics and search tools, and the business listing.

How does the problem form?

Gradually. A friend registers the domain, a designer creates hosting under their account, an employee sets up analytics. Each is sensible and none is written down.

When does it surface?

When you want to move hosts, when the site goes down and nobody can open a ticket, or when a verification code goes to somebody who left years ago.

What should I check per account?

Whose name it is in, which email address is on it and whether anybody reads that, and whether you can actually log in this afternoon.

What if a supplier holds an account?

Usually ask to be added as an owner alongside them rather than taking it over. Resistance to that is information worth having early.

What should the document contain?

Per account: what it is, the provider, the login address, whose name, which email, when it renews, and who to contact. Not the passwords.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Not sure who holds your domain?

We map every account the site depends on, which usually turns up at least one surprise.

Start a Conversation