A good-looking site is not much comfort if the domain, billing, and backups belong to somebody else.
Small-business owners lose control of websites in surprisingly ordinary ways. The person who built the site registered the domain under a personal account. The hosting bill goes to an old employee. The only login lives in a text message from three years ago. Nothing feels urgent until the website goes down, the card expires, or the working relationship ends.
Start with the domain name. That is the address people use to find the business, and it should be registered in an account the business controls. The legal business or owner should be the registrant where appropriate, the recovery email should still be accessible, and billing should not depend on a freelancer remembering to renew it. A designer can help manage the domain. That is different from quietly owning it.
Next is hosting. Hosting is where the website runs. You should know the provider, the plan, the renewal date, and who has administrative access. You do not need to become a server technician. You do need enough information to move the site or get help without starting an investigation.
The same rule applies to the website platform, email, analytics, payment accounts, and any tool connected to the site. The business should have its own account when the service is central to operations. Give contractors the access they need. Do not build the entire setup inside a contractor’s personal account because it was quicker on Tuesday afternoon. Quick arrangements have a habit of becoming permanent architecture.
Passwords need a system too. Use a password manager, turn on multi-factor authentication, and avoid sharing one master login among several people. Individual access makes it easier to remove one person without changing everything. It also gives you a better chance of knowing who changed what. Keep recovery codes somewhere secure and make sure recovery phone numbers and email addresses are current.
Then ask about backups. “The host probably backs it up” is not a recovery plan. Find out what is backed up, how often, how long copies are kept, and how a restore works. If the website matters to the business, somebody should test the restore process occasionally. A backup that has never been restored is a hopeful file.
You also want a basic handoff record. It does not need to be a technical manual. One page can list the domain registrar, hosting provider, website platform, important integrations, renewal dates, account owner, backup location, and the person responsible for updates. Do not put passwords in that page. Put them in the password manager and note where access is controlled.
None of this is about distrusting the person building your site. Clear ownership protects both sides. The business knows what it owns. The developer knows what they are responsible for. If the relationship changes, the website can keep operating without a fight over accounts.
Before approving a website project, ask one plain question: if the person building this disappeared next month, could I still renew, access, back up, and move the site? If the answer is no, fix that while everybody is still answering emails.