Technical version

Account ownership and recovery checklist.

Inventory fields

For domain/registrar, DNS, GitHub, hosting, database/storage, email, analytics, Search Console, Google Ads, Meta, YouTube, scheduling, AMS/CRM, and monitoring, record: business owner, technical admin, billing contact, login email, recovery methods, 2FA status, backup-code custodian, renewal, plan, data held, connected integrations, export path, and emergency support route.

Access rules

  • No shared production administrator account.
  • Invite named users with the smallest useful role.
  • Require two-step verification for privileged users.
  • Review access quarterly and remove departed users promptly.
  • Keep an activity log for access to claimant information and private files.
  • Confirm ownership with evidence; do not rely on an old project note or verbal assertion.

Recovery session

  1. Start with domain, DNS, email, GitHub, hosting, and database.
  2. Recover the client owner before adding agency access.
  3. Update recovery channels and billing after identity is verified.
  4. Save backup codes in the client’s secure password manager.
  5. Test one non-destructive login and recovery path.
  6. Record the result and the next review date.