Changing a digital agency affects access to websites, domains, advertising accounts, analytics platforms, source files, software subscriptions, and customer data. An agency transition therefore requires an inventory of digital assets, verification of ownership, transfer of administrative access, backups, and removal of obsolete permissions.
A documented exit plan establishes which accounts belong to the business, who controls them, what information must be exported, and when the former agency’s access can be revoked.
Table of contents
Confirm Ownership of the Domain
A domain is separate from the website hosted on it. The domain registrar controls registration, renewal settings, registrant information, nameservers, and the authorization process required for transfers between registrars.
Before ending an agency relationship, the business should verify:
- The registrar where each domain is registered.
- The registered name holder and contact information.
- The email address receiving renewal and security notifications.
- The domain expiration date and automatic-renewal status.
- Whether two-factor authentication is enabled.
- Which employees have access to the registrar account.
- Whether the agency controls the account or only has delegated access.
For generic top-level domains covered by ICANN rules, an authorization code is used when moving a domain between registrars, and certain transfer restrictions can apply after registration, a previous transfer, or a change of registrant.
If the registrar account is controlled by the outgoing agency, ownership should be addressed before the agency loses access. A business that needs to move the registration to another registrar can transfer domain after satisfying the applicable transfer requirements.
Changing a web-hosting provider does not automatically require transferring the domain registration. DNS records or nameservers can instead be changed to direct the domain to a different hosting environment.
Create an Inventory of Digital Accounts
An agency may have access to more systems than those listed on its monthly invoice. A complete inventory should identify the platform, account owner, billing owner, administrator, recovery email, authentication method, and current users.
The inventory should cover:
- Domain registrar and DNS provider.
- Website hosting and content management system.
- Content delivery network and security services.
- Google Analytics and Google Search Console.
- Advertising platforms and merchant accounts.
- Email marketing and CRM systems.
- Social media accounts.
- Design and prototyping platforms.
- Cloud storage and file-sharing services.
- Scheduling, chatbot, automation, and integration platforms.
- Source-code repositories.
- E-commerce, payment, and product-feed systems.
Accounts created with an agency-owned email address require particular attention because password resets and security notifications may continue to go to that address after the contract ends.
Secure Administrator-Level Access
Receiving a password does not prove that the business controls an account. The business should hold an administrator or owner role through an email address controlled by the business.
Google Analytics, for example, supports account- and property-level access management, and administrator permissions allow users to manage other users and their roles. It distinguishes owners from users; owners can add and remove users, while verified ownership depends on an ownership-verification token.
Google Ads also separates an individual advertising account from a manager account. When a manager relationship is unlinked, the individual account retains its campaign history.
Back Up the Website and Source Files
A website handover requires more than a copy of visible pages. The transfer package should include the files and data needed to reproduce and maintain the site.
Depending on the technology stack, the package can include:
- Website files and database exports.
- CMS configuration and administrator access.
- Theme and plugin information.
- Custom source code.
- Repository access and deployment instructions.
- DNS records.
- Redirect rules.
- Tracking scripts and tag manager configurations.
- Image, video, font, and design source files.
- API and integration documentation.
- Records identifying third-party licenses and subscriptions.
A team should test each backup independently. A database export that cannot be imported or a repository that lacks the required environment configuration does not provide a complete recovery path.
Preserve Marketing and Analytics Data
Historical marketing data is required for year-over-year comparisons, attribution analysis, advertising optimization, and performance reporting. Export requirements depend on the platform and the business’s data-retention obligations.
The transition inventory should identify advertising accounts, analytics properties, conversion events, pixels, audiences, product feeds, dashboards, reports, and tag-management containers.
Automated customer-facing systems require separate documentation. Organizations using AI-based customer interactions may connect agents to CRM records, support systems, knowledge bases, or transaction tools. The preparation involved in deploying AI agents for customer interactions makes access to those integrations part of an agency handover when such systems are managed by the agency.
Rotate Credentials and Remove Agency Access
Agency access should not remain active indefinitely after a contract ends.
The process should include rotating shared passwords, replacing API keys where appropriate, reviewing OAuth connections, updating recovery addresses, checking administrator lists, and confirming multi-factor authentication settings.
Replace shared credentials with named user accounts when the platform supports them. Named accounts create a direct record of which user has access and allow teams to revoke individual access without changing credentials for every authorized employee.
Record the Final Handover
The exit process should end with a written handover record. It should identify every transferred asset, its current owner, its administrator, the location of backups, unresolved technical issues, subscription responsibilities, renewal dates, and remaining third-party dependencies.
The final verification should confirm that the business can independently access its domain, hosting, website, analytics, advertising accounts, repositories, customer-data systems, and essential integrations.
A completed exit record converts the agency transition from an informal exchange of passwords into a documented transfer of digital assets and administrative control.










