Digital control
Who Owns Your Domain, Website and Business Accounts?
A supplier can manage a platform without owning it. Clear account ownership makes support, security, recovery and supplier change safer.

A company can pay for a website and still not control it.
The domain may be registered in a developer’s personal account. Hosting may use an email address nobody monitors. Analytics may belong to an old agency. A former employee may be the only administrator of the social profile. Recovery codes may sit on a lost phone.
Everything works until the business needs to change something.
Payment is not the same as ownership
An invoice proves a commercial relationship. Technical control still needs to be visible inside each platform.
Ownership is visible in the platform:
- Which legal or account entity is registered?
- Which email receives recovery messages?
- Who can add or remove administrators?
- Who controls billing?
- Can the business export its information?
- Can it continue if the supplier disappears?
These questions should be answered while the relationship is healthy.
Start with the domain
The domain is a critical business asset. It can control the website, email and customer trust.
The business should know:
- the registrar
- the registrant or account owner
- renewal date and payment method
- administrative contacts
- multifactor authentication status
- DNS provider
- authorised administrators
- recovery process
- transfer restrictions
The domain should normally sit in a company-controlled account. A technical supplier can receive delegated access without becoming the only owner.
Losing a domain can disrupt far more than the homepage.
Map the complete digital estate
Ownership review should include:
- domain and DNS
- website hosting and content management
- source code and deployment
- business email
- cloud storage
- analytics and tag management
- advertising
- social profiles
- Google Business Profile
- CRM
- booking, commerce and payment systems
- design files and media libraries
- network and camera administration
- mobile application stores
- automation and AI platforms
For each system, record the owner, administrators, billing contact, recovery method and supplier access.
Keep the list simple and current.
Separate owner, administrator and user
These roles should not be confused.
Owner
Controls the asset, billing relationship or highest-level account.
Administrator
Configures the system and manages other users.
User
Performs ordinary work inside defined permissions.
An agency may need administrator access to operate the website. It does not necessarily need to own the domain. A marketing employee may manage posts without controlling recovery for the entire company account.
Minimum necessary access makes collaboration safer.
Use company-controlled identities
Critical platforms should not depend on personal email accounts where a business identity is available.
Company-controlled identities make it easier to:
- recover access
- enforce multifactor authentication
- remove departing staff
- retain business records
- separate personal and corporate activity
- document responsibility
Avoid one shared administrator identity used by everyone. Individual accounts create clearer accountability and allow access to be revoked without changing the entire organisation’s password.
Supplier access should be revocable
A strong supplier relationship works with controlled, revocable access.
The business should be able to:
- see which supplier users are connected
- understand their permission level
- approve significant access
- remove access at the end of work
- receive documentation
- transfer management
- export supported data
Contracts and technical configuration should support the same model.
Recovery belongs to the business
Account recovery is often ignored until it becomes urgent.
Check:
- recovery email and phone
- backup codes
- trusted devices
- secondary administrators
- emergency access procedure
- current contact information
- location of ownership documentation
Recovery information should be protected and available to an authorised person when the usual administrator cannot act.
Review after every major change
Ownership should be reviewed when:
- an employee or supplier leaves
- the company changes agency
- a website is rebuilt
- a new location opens
- a business is acquired or reorganised
- billing changes
- an administrator loses a device
- a security event occurs
A short quarterly or biannual review can also reveal forgotten access before it becomes a problem.
A simple ownership standard
Your business should survive a supplier change.
Palmward builds around client-controlled accounts, revocable access, administrator clarity, portable information and documented handover.
A responsible technology partner may operate critical systems. The business should still understand what it owns and retain the ability to control its future.
Your business stays yours because ownership is designed, not assumed.
Run this check before commissioning website design in The Gambia and repeat it when an employee or supplier leaves. The digital offboarding checklist covers the access changes that follow.
Contact