Articles · Ownership

2026-10-08 10 min EN / FR

Who really owns your accounts? A 30-minute audit

Most companies cannot answer a simple question: if your web developer, agency or IT contact disappeared tomorrow, could you still run your business?

This audit will not fix anything by itself. It shows you where you are exposed. You need a spreadsheet, about 30 minutes, and access to your own email and billing records.

The rule behind the audit

For every service you use, four things should be true:

  1. The account is in your name (your company, your email address, not a contractor's).
  2. Billing goes to you (your card or your invoice, not reimbursed through someone else).
  3. You hold an admin or owner role, not just a user role.
  4. You control the recovery path: the 2FA device, the recovery email and the phone number are yours.

If any of the four is missing, you have a dependency. It is invisible until the day it becomes urgent.

Step 1: List everything

Make one row per service. Do not trust memory. Check these sources:

  • Your accounting records and card statements for the past 12 months (recurring charges reveal forgotten tools)
  • The inbox of your main address, searching for "invoice", "receipt" and "welcome"
  • Your website's source or settings, to see which third-party services it loads

Typical categories:

  • Domain name and DNS
  • Hosting or cloud (OVH, AWS, a managed host, a VPS)
  • Website, CMS or shop (WordPress, Shopify, PrestaShop, Odoo)
  • Email (Google Workspace, Microsoft 365, a host's mailboxes)
  • Analytics and marketing (Google Analytics, Search Console, Ads, Meta, Mailchimp)
  • Payments (Stripe, PayPal, your bank's provider)
  • Source code (GitHub, GitLab, Bitbucket)
  • App store accounts (Apple Developer, Google Play)
  • Third-party APIs (maps, SMS, email sending, AI)
  • Business tools (CRM, helpdesk, project tracker, accounting)

Step 2: Fill in four columns for each row

Service Account owner (name/email) Who pays Who is admin Who controls recovery
Example: domain

Mark each cell green (you), orange (shared or unclear) or red (someone else, or unknown).

Step 3: Check the high-risk items first

Your domain name. This is the most important asset on the list. Look up the registrant of your domain with a WHOIS lookup (some registrars hide details, in which case log into the registrar). Questions to answer: Who holds the registrar account? Which email receives the renewal reminders? Is auto-renewal on? If the registrar account belongs to your agency, you rent your own name.

Your hosting and cloud accounts. A very common situation: a freelancer created the AWS or hosting account with their own email and added the company card, or worse, their own card, re-invoiced to you. You may be paying, but you cannot log in.

Your source code. Is the repository in an organization you control? If the code lives in a personal account of your developer, you may not have the right to access it, let alone the ability to hand it to someone else.

Your payment provider. The Stripe or PayPal account should be in your company's legal name. Changing it later is possible but painful.

Your Google accounts. Analytics, Search Console and Ads often get set up under an agency's login. When the relationship ends, years of data can go with it.

Step 4: Check the "single person" risks

Even with accounts in your name, one person can be a single point of failure. Look for:

  • Passwords stored in one person's head, notebook or private password manager
  • 2FA codes going to one person's phone
  • A shared mailbox that only one person can read
  • A "master" admin who has left or is about to leave

Step 5: Fix in priority order

  1. Domain first. Move registrant and registrar access to your company.
  2. Anything that makes money (shop, payments, booking).
  3. Anything that holds your data (CRM, accounting, cloud storage).
  4. Everything else.

For each red item, the fix is usually one of three:

  • Transfer ownership (many platforms have an official procedure).
  • Add yourself as owner, then remove or reduce the other person's role.
  • Recreate under your name and migrate, when transfer is not possible. For SaaS exits that go deeper than account ownership, see leaving a SaaS without losing your data.

Do this calmly and in writing. Most providers cooperate if asked politely and early. It is much harder in the middle of a dispute.

Too many red cells?

If the spreadsheet already shows dependencies you cannot unwind alone, we can walk the high-risk rows with you and plan the transfers under accounts you own.

What a healthy setup looks like

  • Accounts created with a company email address (not a personal one), ideally a role address such as it@yourcompany.com that several people can access
  • Service providers invited as limited, revocable users
  • A shared password manager with at least two administrators
  • A short document listing every service, who owns it and where recovery details are stored. Expand that into a full exit plan with your provider.
  • A yearly review of this list (add it to your calendar now)

Quick self-test

Answer yes or no:

  • I can log into my domain registrar account today
  • I can log into my hosting or cloud account today
  • I can access my source code without asking anyone
  • My payment provider account is in my company's name
  • Two people can recover our main accounts
  • If my developer vanished, a new one could start with the access I hold

Every "no" is a conversation to have this month, not after an incident.

Related

From audit to a clean ownership map

If you want a second pair of eyes on the spreadsheet, write us. We answer on substance.