A business can pay for a website for years and still discover, at exactly the wrong moment, that it cannot fully control it.

The site is online. The email works. Leads are coming in. Nothing appears broken.

Then the business needs to change providers, update a DNS record, add a new administrator, investigate a security problem or recover from an outage. Someone asks for the domain registrar login.

Nobody has it.

Or the account belongs to a former employee. The verification code goes to an old phone number. The hosting is buried inside an agency account. The analytics property was created under somebody else’s email. A backup exists, apparently, but nobody knows where.

This isn’t really a website-design problem. It’s an ownership and continuity problem.

What website accounts should a small business be able to control?

At minimum, a business should know who controls its domain registration, DNS, website hosting, content-management administrator access, business email configuration, analytics/search accounts and recoverable backups. The business does not need to manage every technical setting itself. It does need a reliable way to authorize changes, regain access and move the property if circumstances change.

There is an important difference between managing an account and controlling it.

Most business owners should not spend their afternoons changing DNS records or updating server software. A trusted provider can handle that work. But outsourcing administration shouldn’t make the underlying business asset mysterious.

The Federal Trade Commission makes a similar distinction in its small-business cybersecurity guidance. When choosing hosting, the FTC recommends clarifying who will manage the website, who can make changes, whether the business can log in itself, whether multi-factor authentication is available, how data is stored and who to contact about suspicious activity. The FTC’s small-business cybersecurity guidance is a useful baseline because it treats website management as an operational responsibility, not just a hosting feature.

Start with the domain. Everything else can be perfect while this is wrong.

Your domain name is easy to overlook because, most days, it does nothing visible. It renews in the background and points people toward the website and often the business’s email services.

That quiet role is exactly why ownership matters.

The business should know which registrar holds the domain, which account controls it, which email address receives renewal and security notices, and whether multi-factor authentication is enabled. The contact information should lead to somebody the business can actually reach.

Don’t confuse a domain with hosting. They may be purchased from the same company, but they are different pieces of the infrastructure. Moving a website does not necessarily mean moving the domain. Changing a website provider should not require surrendering the business identity attached to that domain.

And be careful with renewal notices. The FTC warned small businesses in May 2026 about fake invoices that can impersonate legitimate expenses, specifically noting that scammers may send bills for things such as domain registration, tech support or SEO services. The FTC’s current small-business invoice-scam guidance recommends verifying unfamiliar invoices and vendors rather than paying based on urgency or appearance alone.

Hosting access matters, but the hosting account is not the whole website

Ask a business where its website lives and the answer is often the name of the company that built it.

That may not be the host.

A useful ownership record separates the pieces: registrar, DNS provider, web host, content-management system, email provider and any important third-party services. Sometimes several roles are handled by one provider. Sometimes they are spread across five accounts.

The number isn’t the problem. Not knowing the arrangement is.

For a WordPress site, for example, an administrator login lets someone manage much of the website but does not automatically provide access to the server, DNS or domain registration. A hosting login may provide files and databases but not the domain. DNS may sit somewhere else again.

This is why “we have the WordPress password” is not the same as “we control the website.”

Use named access instead of one password everybody knows

Shared credentials feel convenient until somebody leaves, a password changes, or nobody can tell who made a change.

Where a platform supports individual users, give appropriate people their own accounts and permissions. Keep the number of high-level administrators sensible. Remove access when it is no longer needed.

Use multi-factor authentication on important accounts when it is available. The FTC notes that MFA makes it harder for an attacker to enter an account even if a username and password have been compromised. That matters especially for the accounts capable of changing a domain, website, email or recovery settings.

There is no prize for giving everyone administrator access.

A staff member who only publishes articles usually does not need the same privileges as the person responsible for plugins, users or site configuration. A marketing partner may need analytics access without needing domain access. A developer may need technical access for a project without becoming the permanent owner of the business’s primary account.

Good access is enough access.

Don’t forget the accounts surrounding the website

The website itself is only one part of the digital property.

Search Console, analytics, tag management, business listings, form services, scheduling tools, payment accounts, email delivery services and advertising platforms can all accumulate around it. Some are easy to recreate. Others contain years of history, configuration or verification.

This is where businesses often discover an accidental dependency on an individual employee or vendor.

A practical rule is simple: if losing an account would interrupt customers, erase useful history, block an important change or force the business to prove ownership again, put it on the ownership list.

That doesn’t mean centralizing every password in a spreadsheet. It means knowing the account exists, who owns it, who has access and how recovery works.

A backup is only useful if you know what it can restore

“The website is backed up” sounds reassuring. Ask one more question.

What, exactly, is backed up—and how would we restore it?

A website backup may include files and a database. It may not include DNS configuration, email mailboxes, external form data, third-party platform settings or accounts living outside the website.

The FTC recommends keeping software current and protecting business data with backups. For a website, Grassroots would take that one step further operationally: know where the backups are, how long they are retained, who can access them and whether there is a realistic restore path.

A backup that nobody can locate during an outage is closer to a rumor than a recovery plan.

Ownership becomes most visible when a relationship changes

Most access problems don’t matter until there is pressure.

A provider relationship ends. An employee leaves. A business is sold. A redesign begins. Email suddenly stops. A security incident needs investigation. A domain-renewal message arrives on a Saturday.

Those are bad moments to reconstruct the digital infrastructure from old invoices and inbox searches.

Grassroots’ own approach is built around a digital foundation that can keep growing as the business changes. Our Services & Solutions include website development as well as hosting, maintenance, troubleshooting and ongoing support. The point of that support isn’t to make the business dependent on mystery. It is to keep the technical work manageable while the business remains clear about what exists and what it depends on.

Make a one-page digital ownership record

This does not need to become a giant technical manual.

For most small businesses, a one-page inventory is a strong start. Record:

  • the domain registrar and primary account owner;
  • where DNS is managed;
  • the website host;
  • the primary website administrator or administrative account;
  • the business email provider;
  • analytics and search-management accounts;
  • critical third-party tools connected to the website;
  • where website backups are stored and who can restore them;
  • who currently has high-level access; and
  • who should be contacted when something needs to change.

Do not put passwords directly into an unsecured document. Use an appropriate password manager or other secure credential-management method, then use the ownership record to document where control lives.

Review the list when employees or vendors change, and at least periodically even when nothing seems wrong. Quietly outdated recovery information is one of those problems that stays invisible until the day it matters.

The handoff test

Here is a useful way to judge whether the setup is healthy:

If your current website provider became unavailable tomorrow, could an authorized replacement figure out what exists and gain legitimate access without starting over?

That does not mean every vendor should hand every technical credential to every client on day one. Security and platform architecture matter. Some managed environments work differently.

But there should be an answer.

You should know how the domain remains under control, how business data can be recovered, what happens to hosting, which accounts belong to the business, and how a transition would work.

If the answer is “we would have to call one particular person and hope they respond,” the problem is not that you need more passwords. You need a clearer ownership structure.

Where should a small business start?

Start with the domain.

Find the registrar. Confirm the account owner and recovery email. Confirm renewal is current. Check multi-factor authentication. Then work outward through DNS, hosting, website administration, email, analytics and backups.

You may find that everything is already in good shape. That’s useful to know.

If not, fix the highest-consequence ownership gaps first. A forgotten analytics login can usually wait longer than a domain registered to an unreachable former employee.

If you’re not sure who controls the pieces behind your website—or you want a stronger digital foundation without becoming your own IT department—schedule a Complimentary Discovery Call with Grassroots Consulting. We can help identify what you have, what actually matters, and what should be cleaned up before the next change forces the issue.

Built in collaboration with ChatGPT.