OWNERSHIP & ACCESS

Keep control where control belongs.

A project should not require unnecessary transfer of domains, hosting, billing accounts, recovery methods or unrelated access.

OWNERSHIP

Your domain. Your hosting. Your business accounts.

Domains

Where practical, the domain stays registered to the organisation or agency intended to own it. Technical DNS access can be delegated.

Hosting

Where practical, hosting is contracted directly by the intended owner. Billing and recovery remain with that owner.

Third-party services

The client should normally enter billing, identity and recovery information directly with the provider.

ACCESS HIERARCHY

Use the least access necessary for the work.

  1. 01
    Collaborator

    A provider role scoped to the project is normally the cleanest option.

  2. 02
    Limited account

    A temporary or technical user can avoid sharing owner credentials.

  3. 03
    Attended remote session

    The client stays present and can type sensitive credentials when direct account access is unnecessary.

  4. 04
    Broader access

    Only when the work genuinely requires it and the responsibility boundary is explicit.

REMOTE WORK

Remote assistance is task-specific.

When an attended session is appropriate, the account owner remains present and can keep sensitive credentials under their control.

Good practice:
Close unrelated information, open the relevant provider page, type sensitive credentials yourself where practical, and do not enable unattended access by default.
HANDOVER

Existing production deserves a deliberate exit path.

Before destructive changes, identify what is live, preserve what matters and understand the available backup or recovery path where possible and within scope.

  • At handover: know what has been delivered and where it lives.
  • Access: remove or reduce temporary access that is no longer needed.
  • Third-party costs: know which provider charges or renewals continue.
  • Support: know whether any responsibility continues after completion.
NEXT STEP

Prepare the project context.

Tell us what exists first. Access instructions should come only when the project actually requires them.