This is a paid sponsored post provided by Mendel Sites.
A business website may be one of the company’s most important assets, but many owners do not know where its essential accounts are held or who has access to them. The website may have been set up by an employee, an independent developer, an IT provider, or a marketing agency years ago. As long as everything continues working, there may seem to be little reason to investigate further.
The problem usually becomes visible at the worst possible time. A provider becomes unavailable, an employee leaves, a renewal fails, or the website suddenly needs urgent technical attention. The business then discovers that the domain is registered under someone else’s email address, the hosting credentials cannot be found, or no one knows where the latest backup is stored.
By documenting the following information before a problem occurs, businesses can reduce unnecessary downtime, make vendor transitions easier, and avoid becoming dependent on one person’s memory or availability.
Start With Clear Account Ownership
There is an important difference between allowing a provider to manage an account and allowing that provider to own it.
A web developer may handle hosting, update WordPress, renew software licences, or manage DNS settings on the business’s behalf. That arrangement can be efficient, particularly when the business does not have an internal technical team. However, the company should still understand where each account is held and what would happen if the relationship ended.
“Businesses do not need to manage every technical part of their website themselves, but they should know who controls their domain, hosting, administrator accounts, and backups,” explains Sam Mendelsohn of Mendel Sites. “Having that information documented makes it much easier to respond when an employee leaves, a provider changes, or an urgent website issue comes up.”
Ideally, critical accounts should use a company-controlled email address rather than an employee’s personal inbox or a vendor’s private account. Outside providers can then be granted the access they need without becoming the only people capable of managing the website.
Domain Registration and Renewal Information
The domain name is the address people use to reach the website. It may also be connected to the company’s email system, online tools, advertising accounts, and verification services. Losing control of the domain can therefore affect far more than the website itself.
Every business should document the domain registrar, the account owner, the primary login email, and the domain’s expiration date. The record should also confirm whether automatic renewal is enabled and identify the payment method used for renewals.
Recovery information matters as well. If a verification code is sent to an old phone number or an inbox that no one monitors, recovering the account can become difficult. Renewal and security notifications should go to an active company address that will remain available even when staff members change.
The domain should not be registered exclusively under an outside provider’s personal information. A developer or agency can manage it, but the business should be identifiable as the owner and should have a clear path to accessing the account.
Website Hosting Credentials
Website hosting is where the site’s files and database are stored. Without access to the hosting environment, moving the website, investigating technical problems, or restoring it after an incident can be much more complicated.
The company’s records should identify the hosting provider, account owner, login email, hosting plan, billing schedule, and support contact information. If the host uses a separate control panel or server-management dashboard, that should be documented too.
Businesses should also clarify whether they pay the hosting company directly or receive hosting as part of a maintenance package. When hosting is provided through an agency, the agreement should explain what happens if the relationship ends. The business needs to know whether the website can be transferred, how much notice is required, and whether any migration assistance is included.
Responsibility for server updates, monitoring, backups, and technical support should also be clear. When each party assumes that someone else is handling these tasks, important maintenance can easily be missed.
Content Management System Access
Most modern websites use a content management system such as WordPress. The business should know which platform its website uses and where administrators sign in.
At least one full administrator account should be connected to an email address controlled by the company. Relying entirely on an outside developer’s account creates unnecessary risk if that person becomes unavailable.
Each staff member or provider should have an individual account rather than sharing one username and password. Individual access makes it easier to assign appropriate permissions, identify account activity, and remove access when someone leaves.
The company should document the administrator login address, the primary company account, account-recovery details, and any two-factor authentication requirements. It should also periodically review the user list to remove former employees, outdated contractors, and accounts that are no longer needed.
Business Email and Contact Form Delivery
Website contact forms often depend on several systems working together. A form may appear to submit correctly even when the message never reaches the intended recipient.
Businesses should document which email addresses receive website inquiries, which form platform is being used, and whether a separate email-delivery or SMTP service is involved. Backup recipients and delivery logs should also be identified.
It is especially important to understand that website hosting and email hosting may be provided by different companies. Moving or changing one system without accounting for the other can interrupt email delivery.
Contact forms should be tested regularly from both desktop and mobile devices. The business should confirm that notifications arrive, autoresponders work as intended, and submissions are not being filtered into spam. Someone should also know where to check delivery logs, blocked messages, or suppression lists when a problem occurs.
Analytics and Marketing Platforms
Website data should remain accessible to the company even when its marketing provider changes. Historical information can be valuable for understanding traffic, leads, advertising results, and long-term performance.
The business should maintain a list of its analytics platform, search performance tools, tag-management account, advertising accounts, call-tracking software, consent platform, and any behaviour-analysis tools.
Whenever possible, these accounts should be owned by the company, with agencies and consultants receiving appropriate access. When a provider creates an isolated account that the business cannot enter, years of data may become difficult to retrieve or transfer.
The documentation should identify the primary administrator, approved users, account email addresses, and the process for removing or transferring access.
Plugins, Themes and Third-Party Software
A website may depend on numerous paid tools, even when visitors never see them directly. Plugins, themes, booking systems, security software, form builders, performance tools, and integrations can all affect how the website functions.
Businesses should document which tools are active, what each one does, who owns the licence, when it renews, and what it costs. The record should distinguish between licences purchased directly by the company and tools provided through an agency’s subscription.
This distinction becomes important when changing providers. If essential software is licensed through the previous agency, the business may need to purchase replacement licences to continue receiving updates and support.
Documenting these tools also helps identify unnecessary software. If no one knows what a plugin does or whether it is still required, it deserves closer review rather than being left indefinitely on the website.
Backups and Website Restoration
Simply being told that a website is backed up is not enough. The business should know where the backups are stored, how often they are created, how long they are retained, and who can access them.
A complete record should specify whether both the website files and database are included. It should also explain how to initiate a restoration and whom to contact during an emergency.
Backups should occasionally be tested rather than assumed to be usable. A backup that is incomplete, corrupted, or inaccessible may provide little protection when it is finally needed.
Where practical, businesses should avoid keeping their only backup inside the same hosting environment as the live website. A separate backup location provides additional protection if the hosting account itself becomes compromised or unavailable.
Most importantly, the restoration process should be documented clearly enough that it does not depend entirely on one person remembering what to do.
Security and Recovery Information
Security documentation should identify the tools protecting the website and the people receiving alerts from them. This may include a firewall, malware scanner, security plugin, SSL certificate system, or login-protection service.
Recovery codes for two-factor authentication should be stored securely and separately from ordinary passwords. The business should also know which email addresses and phone numbers are used for account recovery.
An emergency procedure should outline what happens if the website is compromised, an administrator account is taken over, an SSL certificate fails, or an unauthorized change appears. It should identify the first person to contact, which accounts may need to be secured, and where clean backups are stored.
Security alerts should never be sent exclusively to an old inbox or an outside provider without anyone inside the company also being aware of them.
Renewals, Billing and Responsibilities
A business website often relies on several recurring services, each with its own billing date and payment method. These may include the domain, hosting, software licences, security services, backups, email delivery, and maintenance.
A central renewal record should list each service, its purpose, the account owner, renewal date, expected cost, payment method, and responsible contact. Cancellation terms should also be noted where relevant.
This information can prevent downtime caused by an expired credit card or a renewal notice being sent to a former employee. It also gives the business a clearer understanding of the true ongoing cost of operating its website.
The renewal list should be reviewed whenever staff or providers change and as part of an annual website review.
Store the Information Securely
Website documentation should not become another security risk. Passwords should be stored in a reputable business password manager rather than inside email threads, spreadsheets, or shared documents.
A separate website-access record can identify the relevant accounts, owners, renewal dates, responsibilities, and storage locations without displaying every password directly.
Access should be limited according to each person’s responsibilities. Critical accounts should use two-factor authentication, and at least two trusted company representatives should be able to recover essential systems.
The goal is to balance security with continuity. Information should be protected from unauthorized access without becoming impossible for the business to retrieve during an emergency.
Keep the Record Current
Website documentation is only useful when it reflects the company’s current systems. It should be reviewed after hiring or dismissing someone with website access, changing providers, redesigning the website, moving hosting, adding software, or updating billing details.
An annual review can help identify expired accounts, former users, unnecessary tools, outdated recovery information, and unclear responsibilities.
The best time to organize this information is while the website is operating normally. Waiting until a domain expires, a provider disappears, or the website goes offline turns a straightforward administrative task into an urgent recovery effort.
A business does not need to control every technical detail personally. It does need to know what accounts exist, who owns them, where access is stored, and how essential systems can be recovered. That documentation provides continuity, supports better security, and ensures the website remains a business asset rather than an operational vulnerability.


