Your Developer Should Never Control Your Website
A few days ago, an auto shop contacted me because they wanted their WordPress website redesigned.
That part isn't unusual. Businesses redesign websites all the time. The interesting part came when I asked them for access.
They didn't have it.
Not the WordPress login. Not the hosting account. Not the domain account.
Nothing.
Their previous developer had been managing everything for them, including the Namecheap hosting and domain, and when the business asked for access, the developer simply refused to hand it over.
So now they had a website they had paid for, a domain they had paid for, hosting they had paid for, and a developer sitting between them and all of it.
They weren't happy.
And honestly, I understand why.
The reason they originally came to me was already frustrating enough. Their website had become unreliable. Sometimes it worked. Sometimes it didn't. They would send messages about problems and wait days for a response. When the developer eventually replied, the reported issue might still be there, or the "fix" would somehow create a different problem.
Then the developer would disappear again.
Eventually, they got tired of the whole arrangement and wanted someone else to take over. They wanted the site redesigned, properly maintained, and some of the features they'd been asking for added.
That should have been a fairly straightforward project.
Instead, before we could even start, we had to deal with the fact that they couldn't access their own website.
And this is something I think more business owners need to understand before they hire anyone to build or manage their website.
Your developer should have access to your website. They should not own the keys to it.
There is an important difference.
If I'm building a WordPress website for a client, I need access to WordPress. I may need access to the hosting account. I may need access to DNS, the domain, email settings, Cloudflare or whatever else the project requires.
But none of that means those accounts need to belong to me.
In fact, I prefer the opposite.
I tell clients to create the hosting account themselves.
If they need a domain, they buy the domain themselves.
If they need hosting, they open the hosting account themselves.
If they need a particular service, they register it in their own name and with their own payment details.
Then they invite me.
That might mean adding me as another user, giving me administrator access to WordPress, or providing the appropriate developer-level access to the hosting platform.
I can get in, do the work, configure everything, fix the problems, build the site and maintain it.
But the client still owns the house.
I'm just the person they've given a key to.
This sounds like a small distinction when you're sitting down to hire a developer and all you want is a website.
It isn't.
Imagine paying a contractor to renovate your physical shop and then discovering that the contractor kept the title to the building, the keys to the front door and the only copy of the alarm code.
You'd probably have a few questions.
Websites are easier to treat this way because they don't feel physical. A domain is just a name on a screen. Hosting is just another monthly bill. WordPress is something you log into through a browser.
But these things are still business assets.
Your domain is an asset.
Your hosting account is an asset.
Your website is an asset.
Your email accounts can be business-critical assets.
And the account that controls them should ultimately remain under your control.
A developer can leave.
A developer can become unresponsive.
A developer can close their business.
You can decide that you don't want to work with them anymore.
You can find another developer.
You can have a disagreement.
None of those things should leave you standing outside your own website waiting for somebody else to let you in.
That is the part I find most concerning about arrangements like this.
The client often doesn't realise there is a problem until they need access.
Everything works fine while the relationship is good.
The developer handles the hosting. They renew the domain. They manage WordPress. They make changes when asked.
The client doesn't think much about it because, well, why would they?
Then something goes wrong.
The developer stops replying.
The website goes down.
The business wants to move to somebody else.
And suddenly the person they need to contact is also the person standing between them and their own accounts.
Now the redesign isn't the first problem anymore.
Getting control back is.
And sometimes that can become a much bigger mess than it ever needed to be.
This is why I think businesses should get into the habit of separating ownership from access.
You own the account.
Your developer gets access to the account.
Those are two completely different things.
If you're hiring someone to build a WordPress website, create the hosting account yourself. Buy the domain yourself. Keep the recovery email under your control. Keep the billing information under your control. Turn on the security measures yourself.
Then give your developer what they actually need to do the job.
When the project ends, you can remove their access.
If you decide to hire someone else, you can invite the new developer.
Nothing has to be transferred from one developer's personal account to another developer's personal account because the business never lost control in the first place.
And there is another advantage to doing it this way: it makes the relationship healthier.
The developer doesn't have to hold your website hostage to prove that you still need them.
You don't have to worry about what happens if they disappear.
They get paid to do the work.
You keep ownership of the thing you're paying them to build.
That's how it should be.
There are plenty of good developers who will have no problem with this. In fact, a professional developer should generally be comfortable working within a client's accounts and being given the access necessary to do the job.
You shouldn't have to surrender ownership simply because someone knows more about WordPress than you do.
You wouldn't give your accountant ownership of your bank account because they know more about accounting.
You wouldn't give your mechanic ownership of your car because they know more about engines.
Your website deserves the same common sense.
So if you're a business owner about to hire a developer, ask one very simple question before anything gets built:
"Who owns the accounts?"
If the answer is you, good.
If the answer is "I'll set everything up for you," ask a second question:
"Can you set it up under my account and then give yourself the access you need?"
That small decision can save you an enormous headache later.
Because the best developer-client relationship isn't one where the developer controls everything.
It's one where the developer knows exactly what they're responsible for, the client knows exactly what they own, and neither person has to depend on the other for access to something that was paid for by the business.
Your developer should have the keys.
They just shouldn't own the building.
Keep reading
What You Actually Need to Learn to Become a Shopify Developer
There is a particular kind of job post that makes Shopify development sound much harder than it is....
Paid AdsGoogle’s Recommended Budget Is Not Your Business Strategy
There is a particular notification in Google Ads that has probably convinced more advertisers to spend money...