The takeover-safe handover template
The handover template that prevents hostage situations: every credential, account, license and decision documented, structured so the next developer (or you) is never locked out.
A complete handover is the difference between owning your website and renting it from whoever built it. This template is the artifact a finished project must include, and the checklist for auditing a handover you suspect is incomplete. It extends the handover checklist with the takeover-safety angle: every line exists because its absence has stranded a real business. Use it at project end, at agency exit, or right now as an audit of what you are missing.
The fields, with guidance
Domain and DNS
Registrar name, login location (whose account), DNS provider, all records listed, auto-renew status and card, expiry dates.
Example: Namecheap, client account, Cloudflare DNS; A/CNAME/MX/TXT records exported; renewal Jun 2027, client card on file.
Hosting and infrastructure
Host, plan, login location, billing card, server stack, staging URL, backup schedule and storage location.
Example: Kinsta, client account; staging at staging.domain; daily DB + weekly files to off-site storage.
Every mailbox, its provider, admin account holder, and where password resets flow. The master-key section.
Example: Google Workspace, admin = client owner; billing on client card; resets flow to owner + recovery mailbox.
Code and repository
Repository URL and host, who owns the org, branches of record, build/deploy command, environment variables list (names only, values in a vault).
Example: GitHub client-org/site; main deploys via platform; env vars: 6, values in client vault.
Licenses and subscriptions
Every paid theme, plugin, font, stock asset, SaaS: license holder, renewal date, cost, what breaks if it lapses.
Example: Elementor Pro $59/yr (client card, Mar); Adobe fonts (client); Akamai... etc.
Documentation and decisions
Feature decisions and why, known issues, the runbook for routine tasks (deploys, restores), and who to call for what.
Example: Checkout uses wallet-only on mobile (decision doc §3); deploy = merge to main, auto-builds.
Proof of ownership
The receipts: order confirmations, registration records, transfer acceptances, proving every asset is in the client's name. The section that makes the handover takeover-proof.
Example: WHOIS showing client registrant; hosting invoices in client name; repo org transfer accepted.
Copy this block
TAKEOVER-SAFE HANDOVER RECORD
=============================
1. DOMAIN & DNS
Registrar / account holder: ____________ Auto-renew: Y/N Expires: ____
DNS provider: ____________ Records exported: Y/N
2. HOSTING & INFRASTRUCTURE
Host / plan / account holder: ____________ Billing: ____
Staging URL: ____________ Backups: schedule + location: ____________
3. EMAIL
Provider / admin account: ____________ Password resets flow to: ____
4. CODE & REPOSITORY
Repo URL / org owner: ____________ Deploy method: ____________
Env variables (names): ____________ Values stored: ____________
5. LICENSES & SUBSCRIPTIONS
Asset / holder / renewal / cost / lapses-what: ____________
6. DOCUMENTATION
Runbook attached: Y/N Decisions log: Y/N Known issues: Y/N
7. PROOF OF OWNERSHIP
Registration records attached: Y/N Invoices in client name: Y/N
ACCEPTED BY (client): ____________ Date: ____
DELIVERED BY (developer): ____________ Date: ____ Plain text on purpose, pastes cleanly into email, docs and project tools.
The audit test for any handover: hand this document to a competent stranger with the passwords, and can they run the site? If any section is blank, the handover is not done, it is a promise. This template closes projects here without being asked; it is also the audit tool for handovers you suspect are incomplete. If the audit finds a hostage situation, that is the takeover track. Pair with the ownership-clause guide to prevent the next one.
Prefer this executed instead of self-served?
Quarterly, and only when the numbers move
Get the rate report before you negotiate.
Updated rate bands across the major stacks and regions, plus what changed and why. No other email.