The project is done. The invoice is paid. The agency says congratulations and sends you a link to your new site. What they hand over next determines whether you actually own what you paid for — or whether you’re dependent on them for things they’ve never mentioned.
Here is the complete list of what a proper website handoff includes, and why each piece matters.
The Two Categories of Handoff Deliverables
Everything you receive at project end falls into two categories: access and documentation. Access is the credentials and files that let you control the site. Documentation is the knowledge that lets you use those credentials intelligently.
Most agencies are reasonable about access — they’ll hand over the WordPress login and call it done. Documentation is where they cut corners, because it takes time and doesn’t generate billable hours.
Both matter. An admin login without documentation means you have a car without knowing what the warning lights mean.
Code and Files
What you should receive:
- Full codebase — every theme file, plugin file, and custom script written for your project
- Database export (
.sqlfile) — the content, settings, and structure of your entire site - Any design source files — Figma, Adobe XD, Sketch, Photoshop, or Illustrator files for every page layout designed for the project
- Asset library — original resolution images, logos, icons, and graphics used in the build
- Any build tool configuration — if the developer used Webpack, Gulp, or similar tools, you need those configs to rebuild the project later
Why this matters: If you receive only what’s on the live server, you’re missing the design layer. When you need to update the site later — new service page, new team member headshot, new campaign banner — the person doing that work needs source files, not JPEGs exported from the live site.
Agencies that use page builders (Elementor, Divi, WPBakery) often have nothing meaningful to hand over. The “code” is stored in the database as shortcodes or JSON, and it’s locked to the page builder plugin. If you ever want to move away from that builder, you’re rebuilding from scratch. This is one of several reasons we don’t use page builders in our custom WordPress development — you receive actual, readable code that any developer can maintain.
Credentials
A complete credential handoff includes:
- WordPress admin login — your primary site access
- Hosting control panel — cPanel, Plesk, or the equivalent for your hosting provider
- FTP/SFTP or SSH credentials — server-level access for file management
- Database credentials — username, password, database name, and hostname
- Domain registrar login — the account where your domain is registered
- DNS access — where your domain’s DNS records are managed (sometimes separate from the registrar)
- Third-party service credentials — any API keys, plugin licenses, or service accounts set up specifically for your project (payment gateways, email services, form tools, analytics)
- SSL certificate management access — if the certificate is managed through a separate service
The most commonly withheld credential is the domain registrar. Some agencies register client domains under their own registrar account and provide “access” through a sub-account — which they can revoke at any time. Your domain should be registered in an account you own and pay for directly, with the agency listed as an authorized contact at most.
Kevin, a healthcare practice owner, paid a full project fee and received his WordPress credentials on handoff day. Six months later, the agency folded. His domain was registered under the agency’s GoDaddy account and managed through an employee email that no longer existed. It took ICANN dispute proceedings and four weeks to recover the domain. The domain itself was fine — the path to it was completely controlled by a company that no longer existed.
Documentation
This is the handoff piece that separates professional agencies from transactional ones.
What good documentation includes:
- Technical summary — what CMS, theme framework, plugins, and hosting are in use, and why those choices were made
- Plugin inventory — every plugin installed, what it does, whether it has a license key that needs renewal, and what to do if it stops working
- Update procedures — how to safely update WordPress core, themes, and plugins without breaking the site (this is not always straightforward)
- Contact directory — who to call for hosting issues, who manages DNS, which plugins have premium support, and how to reach each
- Content editing guide — specific instructions for the types of edits the client will actually need to make (not a generic WordPress tutorial)
- Backup protocol — how and where the site is backed up, how often, and how to restore from a backup
Most agencies provide a 30-minute screen recording and call it a training. That’s not documentation — it’s a recording that becomes outdated the next time WordPress updates its admin interface.
Written documentation that lives in a shared Google Drive or Notion document, accessible to multiple people on your team, is what protects you when the person who got the training leaves the company.
What a Health Audit Catches That Handoff Documentation Misses
Even when agencies hand over everything listed above, what they hand over may not be in good shape. A clean handoff of a broken site is still a broken site.
Before accepting a handoff — especially on an inherited project from another agency — an independent technical audit is worth the time. Honest will surface site health issues, performance gaps, and structural problems before you sign off on a completed project.
The questions worth asking at handoff:
- What is the current PageSpeed Insights score on mobile? (It should be above 90 on a properly built site.)
- Are there any known security vulnerabilities in the current plugin versions?
- Has the site been tested on current versions of Safari, Chrome, and Firefox on mobile?
- Is there a backup running now, and where does it go?
If the answers are vague, that’s information.
Intellectual Property: What the Contract Should Say
The files are only useful if you legally own them. A surprising number of web contracts — especially template contracts downloaded by small agencies — default to the agency retaining copyright until the final invoice is paid. Some don’t address IP assignment at all, which creates ambiguity that benefits the agency.
Your contract should state explicitly:
- That all work product created for the project is assigned to you upon payment
- That the agency retains no license to use your site, design, or code after project completion
- That any third-party code (open-source libraries, purchased plugins) is documented and their license terms are disclosed
If your contract doesn’t say this clearly, a business attorney can review it before final payment clears. That’s a $150–$300 investment that can protect a $15,000 project.
The Handoff Meeting: What to Cover
Request a formal handoff meeting, not a casual “here are your credentials” email. During that meeting:
- Test every credential in real time. Credentials that work in the meeting don’t get disputed later.
- Confirm every plugin license is transferred to your email or payment method.
- Verify the database backup works — ask the agency to restore from it to a staging environment before the project closes.
- Go through the plugin list and identify which ones require annual renewals.
- Confirm that the agency’s credentials have been removed or downgraded — they should not retain admin access after handoff without your explicit, renewed consent.
Rachel, a B2B software company founder, assumed her previous agency had removed their admin access at project close. Eighteen months later, during a security audit, she found an active admin account belonging to a developer who had left that agency a year earlier. The access hadn’t been revoked. It took a full security review to establish that nothing had been compromised — but the exposure window was real.
After the Handoff: What You Should Do First
Once you have your credentials, take these actions within the first week:
- Change all passwords to ones you control
- Set up your own backup solution if the agency was handling backups under their account
- Confirm your domain registrar email is one you control and check
- Register your site in Google Search Console under your own Google account if not already done
- Run a baseline performance check so you have a reference point
Our fixed-price packages at /start include all of this as part of the standard process. You leave with everything — every credential, every file, every documentation document — because that’s what you paid for.
Frequently Asked Questions
What if my agency says the design files belong to them? Read your contract. If the contract says IP transfers upon final payment and you’ve paid, the files belong to you — request them formally in writing. If the contract is ambiguous, consult a business attorney. Agencies that retain design files as leverage after project completion are in a legally and ethically weak position. Most will comply with a formal written request.
Do I need to receive the database separately from the live site? Yes. The live site is the running application. The database export is your portable copy — it’s what lets you move the site to a new host, restore from a backup, or rebuild after a hack. If you don’t have a database export, you don’t fully own your site.
What happens if I don’t have documentation and the agency closes? You lose access to everything the agency managed. If your domain was under their account, you lose the domain. If they managed your hosting, the site goes dark. If they held your only admin password and didn’t give it to you, you’d need to reset it via server-level database access — assuming you have that. This is exactly the scenario documentation and proper credential handoff prevent.
How long should a web project handoff take? A proper handoff for a standard WordPress site takes 2–4 hours: credential transfer, walkthrough of the documentation, a training session on the admin, and live testing of critical functions. For a complex WooCommerce build, budget a full day. Any agency that wraps handoff in 20 minutes is cutting corners somewhere.
Should the agency keep admin access after handoff? Only if you specifically want ongoing maintenance support, and only with a clearly defined scope. If the agency is not on a maintenance retainer, their admin access should be revoked or downgraded to a non-admin role at handoff. An active admin account for a developer who no longer works on your site is a security risk, not a convenience.