Most clients don’t know what they’re supposed to receive at the end of a web project. Agencies know this — and some of them use that knowledge to deliver less.
A web agency engagement has a defined set of outputs. Knowing what they are before the project starts is the best way to make sure you actually get them.
The Categories of Deliverables
A complete web project produces four types of deliverables: the live site itself, the assets behind the site, the accounts that control it, and the documentation that makes it maintainable. All four categories matter.
The live URL is the most visible thing, but it’s also the thing that disappears if you don’t have everything in the other three categories.
Category 1: The Live Site
The obvious one. But “live site” has components worth enumerating:
All pages included in scope. Not “we’ll add those remaining pages in the next phase” — completed pages. If the scope said 20 pages, 20 pages should be live at final delivery.
Mobile optimization. Every page, tested on at minimum iOS Safari and Android Chrome. Not “it looks okay” — specifically tested, with layout verified and tap targets confirmed.
Functional components. Contact forms that send email. E-commerce checkouts that process transactions. Search functionality that returns relevant results. Every interactive element should be tested and confirmed functional at handoff.
Performance baseline. A PageSpeed Insights report at launch. This is your benchmark. If performance degrades later, you have a baseline to reference. Good agencies provide this automatically. Others will if you ask.
Cross-browser testing. Confirmed functionality in current Chrome, Firefox, Safari, and Edge. Not exhaustive legacy browser support — current versions of the main browsers.
Category 2: Files and Assets
This is where deliverables get thin with agencies that aren’t thinking about client ownership.
Code repository access. For custom builds, a Git repository with the complete project code, including commit history. Not a zip file of the final code — a repository you can hand to any future developer with full context. If the agency won’t provide this, ask why.
Design source files. The editable originals — Figma, Sketch, or Adobe XD files. Not just the exported JPGs or PNGs. If you need to change the layout in two years, you want the file, not a screenshot.
Image originals. Full-resolution original images used on the site. Not the web-optimized versions — the originals. These are your assets.
Brand assets created for the project. Custom icons, illustrations, fonts, color palettes. Anything created specifically for this project belongs to you.
Plugin and theme license documentation. A list of every premium plugin or theme used, the license keys, and where to renew them. This prevents you from being in a situation where a plugin auto-renews to an email address you don’t have access to.
James received a full website handoff from his previous agency — or thought he did. When he moved to a new developer, he discovered the design files had never been transferred, the custom icon set existed only on the agency’s server, and the premium plugin licenses were under the agency’s agency account. Getting everything transferred took six weeks and two rounds of increasingly terse emails.
Category 3: Account Access
Accounts are often the most contested part of a web project handoff. Establish this at contract signing, not after launch.
Hosting account. Your name, your payment method, your login credentials. Either set up in your name from the start or formally transferred before final payment is released.
Domain registrar account. Domain registered under your name with your email. DNS control should be yours.
WordPress admin access. Administrator-level access to the CMS, with the agency’s accounts removed or downgraded at handoff. You should be the only administrator unless you’ve explicitly granted that access to someone else.
Google Analytics and Search Console. Verified ownership of GA4 property and GSC site, with the agency’s access removed or reduced to viewer level unless ongoing SEO work is contracted.
All third-party platform accounts. Email marketing platforms, CRM integrations, payment processors, social media business accounts — any platform the site integrates with should have accounts in your name.
SSL certificate. Usually managed at the hosting level, but worth confirming. You should receive the SSL certificate details and renewal schedule.
Category 4: Documentation
This category is almost never offered proactively and is the most underrated part of the handoff.
Content editor documentation. How to use the CMS to edit your specific site. Not a link to the generic WordPress documentation — site-specific instructions for the custom admin setup. This matters most if you’ll be editing content yourself.
Plugin inventory and function list. What each installed plugin does. This prevents you (or a future developer) from deactivating something critical because you didn’t know what it was for.
Hosting and server configuration notes. The server setup, any custom configurations, PHP version, memory limits, server-side caching setup. Future developers will ask for this.
Maintenance procedure guide. How updates should be applied, backup schedule, monitoring setup, and who to contact for what.
Launch checklist sign-off. Documentation that pre-launch quality checks were completed — mobile testing, form testing, broken link check, 301 redirects from old URLs.
Most agencies don’t produce this documentation because it takes time and isn’t included in scope unless you ask. Ask.
What to Request at Project Kickoff
The best time to secure your deliverables is before the project starts. Put this in the contract or include it as an appendix to the scope of work:
- Code repository access (Git) at project completion
- All design source files (Figma/Sketch/XD) in original format
- All image originals at full resolution
- Plugin and theme license documentation
- All accounts set up in client name from project start
- GA4 and GSC configured with client as primary owner
- Site-specific CMS documentation
- Plugin inventory with function descriptions
- PageSpeed baseline report at launch
- Post-launch QA checklist sign-off
This list takes about ten minutes to put into a contract addendum. It prevents months of frustration.
Our custom WordPress development delivers all of this by default. The handoff checklist is part of our project closure process, not something clients have to negotiate for. If you want a reference point for what comprehensive handoff looks like, our studio page describes our process.
Red Flags in Deliverable Discussions
Some agencies will resist specific requests. The resistance itself is informative.
“We keep the design files proprietary.” Translation: you can’t take the design anywhere. The design you paid for stays with them.
“Code access is on a need-to-know basis.” Translation: they’re not giving you the code. Either it’s not custom (and they don’t want you to see what it actually is), or they want to maintain dependency.
“Accounts are managed through our agency dashboard.” Translation: accounts are in their name. You’re a user of their infrastructure, not an owner.
“We’ll document that after launch.” Translation: documentation is unlikely to happen. Post-launch, the billing relationship changes and documentation becomes a favor, not a deliverable.
Any of these responses should trigger a direct conversation about whether deliverables will be contractually specified before you sign.
If you already have a live site and want to audit what you actually have access to and own, start with Honest to understand the technical setup, then work through the account access list against what’s currently in your name.
After the Handoff: What to Do With Your Deliverables
Receiving deliverables is step one. Organizing and protecting them is step two.
- Store the code repository in your own GitHub or Bitbucket account
- Save design files to your own cloud storage (Google Drive, Dropbox) — not the agency’s shared folder
- Store image originals in a dedicated folder with a clear naming structure
- Record all login credentials in a password manager in your control
- Set up billing alerts on all accounts so renewals don’t lapse
A website that’s been handed off properly is something you can rebuild from, pass to any future developer, and maintain independently. A website that wasn’t handed off properly is a dependency.
Our fixed-price packages are structured around exactly this kind of clean handoff from day one.
Frequently Asked Questions
What if my agency refuses to provide the code files? If your contract includes code delivery as a deliverable and the agency refuses, you have a contract dispute. If the contract doesn’t mention code delivery, you may not have legal grounds — which is why getting it in writing before signing matters. As a practical matter, most agencies will comply with reasonable requests framed politely as part of project closure.
Should I own my hosting account from the start of the project? Yes. Set up hosting in your name, give the agency access to build. Never allow the agency to set up hosting in their name and promise to transfer it later — the transfer is frequently delayed, incomplete, or complicated.
What design files should I ask for? Ask for the primary design tool file (Figma is standard now) with all pages and components. Confirm that it includes the working layers and assets, not just a read-only export. Also ask for font files or font stack documentation if custom or licensed fonts were used.
Do I need documentation if I have a developer managing my site? Yes. Developer turnover happens. If your developer leaves and the only documentation of your site’s setup exists in their head or a private account, you’re starting from scratch. Documentation protects you regardless of who’s managing the site.
What should I do if the agency is unresponsive about delivering assets after launch? Escalate in writing. Send a formal request listing each outstanding deliverable and a reasonable deadline (7–14 days). Keep a record of the exchange. If you’ve paid in full and the deliverables aren’t provided, you may have grounds for a chargeback or small claims dispute — consult a lawyer for specifics in your jurisdiction.