A website project frequently ends with a launch celebration and a login sent over email, with no structured handover covering how to actually operate what's been built. This gap is exactly what leaves a business unable to make even minor updates without going back to the original agency for every change, sometimes indefinitely, regardless of how simple the requested edit genuinely is.

Real, working admin access, not just a login

Full administrative access to the CMS, hosting account and domain registrar, not a restricted editor-level account that can change text but can't install a plugin, add a user, or access technical settings when genuinely needed, since that gap only becomes obvious the moment it's actually needed and isn't there. A business should own its own website infrastructure outright, not access to it at an agency's ongoing discretion.

Documentation written for the business, not for another developer

How to add a blog post, update a product, or change a phone number, written in plain language for whoever will actually be doing these tasks day to day, not technical documentation assuming a developer's background. A short video walkthrough of the most common tasks is often more genuinely useful than a written manual for this specific purpose.

A clear map of what's custom-built versus standard

Knowing which parts of a site use standard, widely-supported CMS features versus custom code that only the original developer genuinely understands changes how a business should plan future changes and who it can safely bring in to make them. Without this map, every future request risks either an unnecessary dependency on the original agency or a costly mistake made by someone unfamiliar with a custom component.

All credentials, consolidated in one place, not scattered

Hosting, domain registrar, CMS admin, any third-party tool integrations, email service, analytics, all credentials consolidated somewhere the business genuinely controls, ideally a password manager the business owns rather than the agency's own internal system. Credentials scattered across old emails or, worse, known only to the agency, create a genuine business continuity risk if that relationship ever ends.

A conversation about what happens next, not just what happened

A brief walkthrough of what routine maintenance the site genuinely needs, security updates, backups, periodic reviews, and who's responsible for each, prevents the common pattern where nobody handles basic upkeep because everyone assumed it was someone else's job after launch, a gap that often only surfaces once something has already gone wrong. This is exactly the conversation that should close out any web design project, not an afterthought squeezed in after the invoice is already settled.

A five-minute test worth running today

Try to add a simple blog post or update a piece of text on the current site without contacting anyone. If that's genuinely straightforward, the handover was likely done well. If it requires a call to the original agency for something this basic, that gap is worth closing regardless of how the rest of the relationship is going, since it only gets more expensive to fix the longer it goes unaddressed.