Storming Solutions

Digital Hub / Web Development

What Should a Website Handover Include?

Updated 23 September 2026

Jump to section

A website handover should transfer everything you need to run, edit, and move the site without the developer ever coming back. That means the domain and hosting logins, the CMS admin, a copy of the source code and database, the design files, the DNS records, and email and analytics access. Get all of it in writing at sign-off, while it costs nothing.

Chasing it a year later, from a developer who has moved on, is the expensive version.

What accounts and logins should you receive?

You should receive owner-level access to every account the site runs on, each registered in your business's name. A handover that gives you an editor login while the developer keeps the master account is not a handover.

It is continued dependence dressed up as service.

Account What you should hold Why it matters
Domain registrar The registrant login, in your company's name Whoever holds it controls whether the site stays online
Hosting or cPanel The primary account, billed to your card Access to files, databases, and email at the server level
CMS admin An administrator account You can edit content and add or remove users
DNS The panel that holds the DNS records You can repoint the domain if you change host
Business email Super-administrator, not just a mailbox You control who has an address at your domain
Analytics and Search Console Owner access Your traffic and ranking history stays with you

Two of these carry history you cannot recreate. Your Search Console and analytics accounts hold years of data, and a fresh account starts empty. The domain matters most of all, because whoever is named as its registrant is its legal owner to a registrar.

What files and assets should you get a copy of?

You should get a complete copy of the site as it exists, not just a link to the live version. A running website is not the same as a portable one, and the gap between them is exactly what locks a client in.

The copy should include:

  • The source code, as a repository or a full export.
  • A database dump, if the site runs on a CMS like WordPress.
  • The design source files (Figma, PSD, or the equivalent), not only exported images.
  • Original images, and the license details for any stock photos or fonts, so you know what you are allowed to reuse.

Ownership of that code is worth settling in writing, even though the law already leans your way. By default, Malaysian law puts the copyright of a commissioned website with the client unless the contract says otherwise, under section 26(2) of the Copyright Act 1987. Section 27(3) then requires any assignment to be in writing (retrieved August 2026). Our guide to who owns your design and code covers the nuance, and why a written line still beats relying on the default.

What documentation turns a pile of logins into a real handover?

A usable handover comes with a short document that explains how the site is put together. A folder of passwords with no map is only half the job, because the next person still cannot tell where anything lives.

Keep it to one page if you can. It should record where the site is hosted and how to publish an update. It should also list the plugins or themes and their versions, where the backups are kept, and who to call in an emergency. This is the raw material a future developer needs to take over without a discovery phase.

The same document feeds directly into website governance: the wider question of who can access and control the site if a person leaves or a dispute begins.

When should a website handover happen?

A handover should happen at project sign-off, as a condition of final payment, never as a favor to chase afterward. The moment you still owe the last invoice is the moment you have the most leverage to ask for everything, and the least friction getting it.

In our experience, clients often do not know whether they own their domain, hosting, and code until something forces the question. The check is simple, and it is easier to run at sign-off than after a relationship has cooled. Fold the handover into the contract as a deliverable, alongside the pre-launch checklist, and it stops being optional.

Common handover gaps

The gaps we see most often are quiet at first and expensive later:

  • The domain sits under the developer's registrar account, so you cannot move it without them.
  • The client gets an editor CMS login, never the administrator account.
  • There is no database export, so the content lives only on the live server.
  • Nobody documents the hosting login, and it surfaces only when the site breaks.
  • The site was handed over with no care plan, so updates lapse and it eventually breaks or gets hacked.

A pattern we repeatedly see is that the missing item is never noticed on launch day. It is noticed the day you need it, which is usually the worst possible day.

Frequently asked questions

Is a login to my website the same as owning it?

No. An editor or author login lets you change content, but the administrator account controls users, plugins, and the site's settings. Ownership lives in the accounts underneath: the domain registration, the hosting account, and the source code. If your developer holds those and you hold only a content login, you can edit the site but you cannot move it or lock anyone out. Ask for owner-level access to all three.

Do I really need the source code if the site works fine?

Yes, because a working site and a portable site are different things. Without the source code and a database export, your only copy of the site lives on the developer's server. Moving to a new host or developer then means rebuilding from scratch. Getting an export at handover costs nothing. Recreating a site you already paid for, because you never received a copy, costs the build price twice.

What if my developer already finished and I got none of this?

Ask for it in writing while the relationship is still workable, because that is when it costs nothing. Request the domain access, a full site export, and the account logins as a simple list. If the domain is the sticking point, our guide to transferring a domain covers the mechanics. A cooperative developer will hand it over; an uncooperative one has told you something useful about who you hired.

Should the handover include a maintenance plan?

Not necessarily in the same document, but the two belong together. A site handed over with no plan for updates, backups, and security tends to break or get hacked within a year or two. Whether your own team or a provider handles it, someone must own the ongoing work. Our guide to keeping a working backup is the single most important piece to settle before you sign off.

Who legally owns the website my agency built?

Usually you, if you commissioned it. Malaysian copyright law transfers the copyright of a commissioned work to the client by default, unless the contract says otherwise, under section 26(2) of the Copyright Act 1987. That is the opposite of the US and UK position. A written clause in your contract removes any doubt and covers the code, design, and content in one line. Settling it on paper is always less expensive than arguing it later.

Get the keys, not just the car

Storming Solutions builds and maintains websites for businesses across Kuala Lumpur and the rest of Malaysia. Every project ends with a full handover in the client's name: domain, hosting, code, and accounts, plus a one-page map of how it all fits. We build for a clean exit, because a client who cannot leave is one we trapped rather than earned.

Not sure what you actually hold from your last build, or planning a new one and want the handover written into the contract? Talk to us about a handover check, or see how we set projects up on our web development page. It is far easier to secure the keys now than to recover them in a dispute.

WhatsAppCall 011-2333 6888