Every agency relationship ends eventually — a contract runs its course, a client moves the work in-house, or you part ways for reasons that have nothing to do with the work. What separates agencies clients still recommend years later from ones they warn people about is almost always the handoff: did you make the exit as clean as the onboarding, or did you leave them locked out of their own site?
The single biggest handoff failure is discovering, on the day a client leaves, that nobody documented where half their assets actually live. Maintain a living asset sheet (a simple Notion page or Google Sheet per client) from day one, covering:
| Asset category | Specific items to track |
|---|---|
| Domain & DNS | Registrar (GoDaddy, Namecheap, Cloudflare Registrar), account owner, DNS record export |
| Hosting | Provider (Cloudways, WP Engine, Kinsta), account login, SFTP/SSH credentials |
| CMS & admin | WordPress admin URL, admin username, 2FA reset method |
| Plugin/theme licenses | Elementor Pro, WooCommerce extensions, ACF Pro — license keys and renewal dates |
| CDN/security | Cloudflare account, Sucuri or Wordfence license |
| Email/transactional | SendGrid, Mailgun, or SMTP credentials used for form/order notifications |
| Analytics & search | GA4 property access, Google Search Console verification, Tag Manager container |
| Payments | Stripe/PayPal API keys, webhook endpoints |
| Source & design | GitHub/GitLab repo, Figma files, brand asset folder |
Emailing plaintext passwords is still the most common handoff method, and it’s the worst one — it sits in an inbox indefinitely and can’t be revoked. Compare the realistic options:
| Method | Security | Best for |
|---|---|---|
| Shared vault (1Password, Bitwarden Organizations) | High — audit trail, revocable, no plaintext exposure | Agencies handling more than a handful of client offboardings a year |
| One-time secret link (e.g. onetimesecret.com, PrivateBin) | Medium-high — self-destructs after viewing | Single-item, one-off handoffs |
| Plain email/spreadsheet | Low — permanent, unencrypted record | Not recommended for anything beyond non-sensitive notes |
If you’re not already running a shared password manager across the agency, the switch pays for itself the first time a handoff doesn’t turn into a security incident.
Access without context just relocates the confusion. A short handoff doc (Notion or Google Docs) covering the hosting stack, any custom code quirks, recurring maintenance tasks, and who to call for what (host support, plugin vendor support) turns a pile of logins into something the client’s next developer can actually use.
Send the final invoice before, not after, transferring the last assets — leverage disappears once everything is handed over. If your contract includes an IP-transfer clause, confirm in writing that custom code and design assets are now the client’s property as of the handoff date. This protects both sides if a dispute comes up later.
A handoff process is one of the cheapest reputation investments an agency can make: it costs a checklist and a couple of hours, and it’s the difference between a client who refers you to their next company and one who tells people you left them locked out. Build the asset inventory as you go, not as an exit-day scramble.
How far in advance should domain transfers start?
At least 7-10 days before the planned cutover — auth codes, registrar locks, and confirmation emails all add delay.
What if the client’s staff can’t handle technical handoff at all?
Offer a paid short-term “landing support” package — a defined number of hours over 30 days to answer questions post-handoff, rather than leaving them stranded or staying on informally for free.
Should I keep a backup after handoff?
Keep one final backup for 30-60 days in case something breaks in transfer, then delete it — retaining client data indefinitely without a business reason is a liability, not an asset.
What about licenses that genuinely can’t transfer?
Tell the client explicitly, in writing, before the handoff date, with a rough repurchase cost, so it’s not a surprise when a plugin update prompt appears asking for a new license key.
Keep the actual notification short and itemized rather than a wall of prose — the client should be able to check items off, not parse paragraphs while stressed about a transition:
Sending this as a single, scannable checklist rather than a narrative email is itself part of the professionalism the client remembers — it signals the handoff was planned, not improvised.
Related reading: When to Fire a Client (Politely) · Reseller Hosting Reputation Issues to Avoid · When to Move Beyond White Label