Ownership

The ownership register

Most website disputes are not about design. They are about who holds the keys when the relationship ends. This is the register I use, and every line of it is in your name from day one.

Every account, who owns it, how it is set up and what happens if the engagement ends
AssetOwnerWho paysHow it is set upIf we stop
Domain name You You, direct to the registrar Registered in your business name, in a registrar account you control, with your billing card and your recovery email. Nothing to transfer. It was never mine.
DNS You Included with the domain or the host Managed in your account. I get delegated access, and the record of what points where is written down. Remove my access. Every record stays exactly as it is.
Source code You Free on the plans you need Your Git repository, your account, full commit history. Not a copy handed over at the end, the real one throughout. Remove my access. Any competent developer can pick it up.
Hosting You You, direct to the host Your Netlify team, connected to your repository, deploying from your main branch. Remove my access. The site keeps deploying.
Business email You You, direct to Microsoft or Google Your Google Workspace or Microsoft 365 tenant, with you as the super admin, not me. Remove my access. Nothing about your mail changes.
Analytics and Search Console You Free Your accounts, verified against your property, with the historical data attached to you. Remove my access. You keep the history.
Google Business Profile You Free Your profile, your primary owner, my access as a manager only. Remove my access. Google never had to be involved.
Social accounts You Free Created by you in your business name. I am added, never the owner. Remove my access.
The design and content of your site You Included in the build price The project-specific deliverables are yours on final payment, set out in the IP schedule. Yours to keep, change or throw away.
My reusable components and tooling Me Included in the build price The underlying build system and component library are licensed to you for your site, not assigned. This is stated up front rather than discovered later. Your site keeps working. You do not get to resell my toolkit, and I do not get to hold your site hostage.

The part nobody mentions

You pay for your own accounts, directly, and that is deliberate

Your domain, your hosting, your mailboxes and any subscription your site depends on are bought on your card, in your account, by you. I do not buy them and bill them back to you.

It is what makes the ownership real. An account paid on my card is an account in my billing relationship, whatever the name on it says. Yours is not, and that is the difference between owning something and being told you own it.

It means I can be removed in an afternoon. Take my access away and every account keeps running, because nothing is renewing through me. There is no billing to transfer and nothing to hand back.

There is no markup, because there is no invoice. You pay the registrar and the host what they charge. I have never seen a reason to add a margin to somebody else’s bill and then have to defend it.

You can see what it actually costs. The direct-cost register in your scope lists every account, what it is for and what it costs a year, before you agree to anything. No surprises at renewal.

What I do

Set them up with you, or take delegated access to accounts you already have, and make them work. Half an hour on a call, usually less.

What I do not do

Hold the card, take the renewal, or stand between you and the company you are actually buying from.

The step by step for setting each one up, or for adding me to accounts you already have, is on the getting started page. It takes about 15 minutes in total and none of it involves sending me a password.

The two arrangements

Drawn, because it is the whole argument

Both diagrams show the same six accounts. The only difference is where the lines meet, and that difference is worth more than any design decision on this site.

Two ways a website’s accounts can be arranged On the left, the usual arrangement: six accounts all connect to the web builder, and the owner is joined to the builder by a single dashed line labelled goodwill. If that line breaks, the owner is connected to nothing. On the right, this arrangement: all six accounts connect directly to the owner, and the studio is joined to each by a removable dashed line labelled delegated access. Removing the studio changes nothing. THE USUAL ARRANGEMENT HERE DOMAINDNSHOSTING CODEEMAILANALYTICS THE WEB GUY holds every key GOODWILL YOU ONE LINE BREAKS AND YOU ARE CONNECTED TO NOTHING. RECOVERY IS THE PLATFORM’S PROCESS, ON ITS TIMETABLE, AND IT OFTEN FAILS. DOMAINDNSHOSTING CODEEMAILANALYTICS YOU hold every key INVITED THE STUDIO removable REMOVE THE DASHED BOX AND NOTHING CHANGES. THE SITE KEEPS DEPLOYING, THE MAIL KEEPS ARRIVING, AND THE HISTORY STAYS WITH YOU.
The same six accounts, arranged two ways. On the left, a single relationship is load bearing. On the right, nothing is. That is the entire difference, and it costs nothing to set up correctly on day one.

Remove my access and everything keeps working exactly as it is. Apply that test to any web builder, including me.

The only ownership question that matters

Credentials

What I will never ask you for

Access is always by named invitation to an account you created. If someone building your website asks you to email a password, that is the moment to stop.

  • Passwords
  • Multi-factor authentication codes
  • Card or bank details
  • Customer records, medical, financial or identity documents

Every platform worth using supports named invitations and role-based access. There is no legitimate reason for a website builder to hold your password, and there are several bad ones.

Why this matters

The failure this prevents

A business rings a web designer to change the trading hours on their site. The designer has moved interstate, changed businesses or simply stopped answering.

The domain is registered to an address nobody can access. The hosting is on an account with someone else’s card on it. The code, if there is any, exists only on a laptop.

Recovering a domain in that state is a formal process run by the registrar and the registry, on their timetable, and it frequently does not work. Rebuilding is often faster than recovering, which is how a 15 minute change becomes a rebuild.

None of that is possible here, because none of it depends on me. Your domain sits in your registrar account, on your card, with your recovery email. Your code sits in your repository. Your hosting deploys from it.

That is the whole of it. Nothing on the right hand side depends on me still answering the phone.