Handover is often an email saying the site is live and a login. That is not a handover. Here is the full list, and the right moment to ask for it is before the final invoice is paid.
At handover you should receive admin access to every system, the code and design source files, documentation of anything custom, a walkthrough recording, all licences and credentials, and confirmation that the domain and hosting are in your name. Check each item before making final payment, because leverage disappears afterwards.
Access
- CMS or website admin, with an administrator account in your name.
- Hosting control panel.
- Domain registrar.
- DNS management, if separate.
- Analytics, with ownership rather than view access.
- Search Console, as an owner.
- Any third-party services: email tools, CDN, forms, chat, booking.
- Code repository, if one exists.
Ownership, not access. An account someone else can revoke is not ownership.
Files
- Full website code, or repository access.
- Database export.
- Design source files, not only exported images.
- Original image assets at full resolution.
- Logo files in vector format.
- Font files and their licences.
- Any custom scripts or integrations.
Documentation
| Item | Why it matters |
|---|---|
| How to edit content | So routine changes do not need an agency |
| How to add a new page | The most common request after launch |
| Where custom functionality lives | So the next developer is not guessing |
| Integration details | What connects to what, and how |
| Backup arrangements | What is backed up, where, how to restore |
| Known issues | Anything deliberately left, and why |
| Recorded walkthrough | More useful than any written guide |
Licences and credentials
Every paid plugin, theme, font, stock image and service should be documented with what it is, whose name it is licensed in, when it renews and what it costs.
This is the item most often skipped and the one that causes trouble a year later, when a licence expires in the name of an agency you no longer work with.
Verify before final payment
- Log in to every system yourself, from your own device.
- Download the code and database and confirm the files open.
- Open the design source files.
- Change your own password on every account.
- Remove the agency's access if the relationship is ending, or agree what they keep.
- Check the domain WHOIS shows your company.
A good agency will have no problem with any of this. It is the standard they should hold themselves to anyway.
Frequently asked questions
What should I get when my website is finished?
Admin access to every system in your name, the full code and database, design source files, documentation, a recorded walkthrough, and a list of every licence with whose name it is in. Verify all of it before paying the final invoice.
Should I get the design files?
Yes, the source files rather than exported images. Without them any future designer has to recreate your assets from scratch, which costs you money for work already done once.
What if my agency will not hand things over?
Check your contract for a transfer clause. If the domain is in your name you always have a route out. This is why verification should happen before final payment, since leverage largely disappears once the invoice is settled.
Should the agency keep access after handover?
Only if they are continuing to support you, and then with their own named accounts you can revoke. If the engagement is finished, remove their access and change passwords as a matter of routine hygiene.
What documentation should I expect?
How to edit content and add pages, where custom functionality lives, how integrations work, backup arrangements, and any known issues. A recorded walkthrough is worth more than a written manual and takes less time to produce.