The hostage situation, one clause earlier
Every week a business discovers its website is held together by logins it does not own: the domain registered in the developer's account, email flowing through a contractor's workspace, the repository in an agency's organization, hosting billed to a card whose holder has left. Nothing is broken, until something changes. A new developer needs access; the old one is slow to reply; the business wants to move. Then "who owns what" stops being paperwork and becomes leverage. The takeover page handles the situation after it happens; this guide is the clause that prevents it, plus the honest mechanics per asset.
The four assets, and what ownership means for each
- The domain, the crown jewel. Registered in YOUR name (or the business entity's), at a registrar YOU hold login for, with YOUR card on auto-renew. The developer may configure DNS; the registration is yours. Why: the domain is the business's internet address, control it and every other hostage situation is solvable, because you can always point it somewhere new. Mechanics worth knowing: ICANN's 60-day transfer lock after registration or transfer means "we'll move it later" has a real cost, register right, first time.
- Email, the master-key risk nobody prices. Password resets flow to email. Business email living inside the developer's workspace or on hosting the developer controls means every account behind it is one careless afternoon away from compromise. Business email belongs to the business: its own tenant, its own billing, its own admin held by the owner.
- Hosting, the bill in your name. The account is yours; the developer is a named user. The reverse makes every hosting conversation a dependency and cancellation a threat.
- The repository and licenses. Code in a repository under your organization; licensed assets (themes, plugins, fonts, stock) purchased on your account. Code you paid for living in someone else's repo is code you will pay to recover, the takeover page documents that recovery.
The contract wording, in one paragraph
"All domains, hosting accounts, repositories, licensed assets and third-party services procured for the project shall be registered and held in the Client's name from the point of creation. The Developer may hold administrative access for the duration of the engagement. Upon completion or termination, the Developer will transfer all credentials, administrative roles and billing to the Client within five business days. Work product, including source code and designs, is the property of the Client upon full payment, as itemized in the handover checklist." The contract guide shows where it sits; the handover checklist is the closing artifact. A developer who resists this clause has told you something, the vetting guide covers how to listen. If the clause was skipped and things are already hostage-shaped, send the brief, "I don't control my own domain" is a workable opening line.