Who should own the source code, hosting and software accounts?
A business should be able to operate, maintain and move its software without depending on one supplier for access. That starts with clear ownership of code, infrastructure and accounts.
By Syed Aalishan Asghar · 30 September 2026 · 5 min read
Keep business accounts in the business name
Domain registration, hosting, analytics, app stores, payment services and email delivery should normally sit in accounts controlled by the client. A developer can be given the access needed to work without becoming the permanent owner.
This keeps billing visible, makes staff changes manageable and prevents a routine handover from becoming an account recovery exercise.
Source code needs a durable home
The repository should live in an organisation or account the client can access. It should contain the current code, a useful history of changes and instructions for running and deploying the project. Sending a zip file at the end is not the same as maintaining a proper repository.
Access should be deliberate
Not every person needs full administrative access. Give each supplier and team member the minimum role required, use individual logins where possible and remove access when an engagement ends.
- Use a shared password manager for credentials that cannot have separate users
- Turn on multi-factor authentication for critical services
- Record recovery methods and billing contacts
- Review access at launch and at the end of support agreements
Make handover part of delivery
Ownership should be agreed before development starts and verified before final sign-off. A handover checklist should cover code, credentials, documentation, backups, licences and outstanding recurring costs.