Confirm Who Controls the Accounts Before Work Starts

A website or marketing job can look ready while the account control is still a pile of guesses. The domain is in one login, the website is in another, a former helper verified the business profile, and nobody is sure which inbox receives a form.

That is not a reason to start changing passwords at random. It is a reason to stop and build a control record.

Marque & Heir recommends one business-owned account ledger before work begins for a local business. The ledger names the surface, the business owner, the approved managers, the recovery route, and the person allowed to approve changes. It is an operating record, not a legal ruling about title or ownership.

Inventory the surfaces before requesting access

List every surface the agreed work may touch. A typical record may include:

  • the domain registration and DNS service;
  • website hosting and the website editor;
  • the Google Business Profile;
  • form, call, booking, and message destinations;
  • analytics and tracking tools;
  • approved social or advertising accounts; and
  • folders holding approved copy, images, and handoff records.

Do not add an account simply because it might be useful later. Tie each line to the approved job or mark it outside the current scope.

For every line, record the public business name, account or property name, current business owner, primary administrator, approved managers, billing owner when applicable, recovery email or process, and last checked date. If any item is unknown, write UNKNOWN. Do not fill the blank with the person who happens to answer first.

Separate business control from a person’s login

The clean starting point is a business-controlled owner role with outside help added only at the level the work requires. Marque & Heir recommends keeping personal sign-in credentials out of general project documents, email threads, and content folders.

Google’s Business eligibility and ownership guidelines say only business owners or authorized representatives may verify and manage a Business Profile. The same guidance tells authorized representatives to work with the owner on verification, keep the owner informed, encourage the owner to own the profile, add outside representatives as managers, and transfer profile ownership to the business owner on request. The page was checked August 25, 2026. Read Google’s ownership guidelines.

That public rule applies to the Google profile. Marque & Heir uses the same practical division as a house recommendation elsewhere: keep durable business control with the business, and give an outside operator the approved access needed for the signed work.

Access does not settle legal ownership by itself. When company authority, contract rights, a disputed account, or a former relationship is unclear, hold the change for the owner and qualified reviewer.

Give the domain its own control line

The domain is easy to overlook because customers see the website, not the account behind the address. The ledger should name the domain, the registrar account under business control, the renewal payer, the recovery route, the person allowed to approve DNS changes, and the date those facts were checked.

Do not copy a password or recovery code into the ledger. Record where approved access is managed and who controls that process.

If the registrant, renewal, recovery, or transfer status is disputed or unknown, do not treat a successful website login as proof that the domain is settled. Website editing access and domain control are different records. The owner should resolve the missing authority before a move, cancellation, or ownership statement is made.

Map the website and hosting roles separately

The website editor, hosting account, domain account, and connected forms may all be separate. List them separately even when one vendor screen appears to manage several parts.

For the website, record who can publish, who can change users, who owns billing, and where a current handoff copy is kept. For hosting, record who can approve a plan change, see renewal notices, and request support. For each contact form, record the live route and approved destination without placing private submissions in the access ledger.

The purpose is not to give everybody full access. It is to make the approved responsibility visible. A writer may need draft access but not billing access. A technical operator may need DNS access for a defined change but no right to alter a public offer. Write those boundaries before the invitation is sent.

Keep the business profile under owner-visible control

Record the profile’s business owner, approved managers, verification state, recovery route, and last checked date. Keep the owner informed about proposed account changes. Public-fact approvals belong in the separate source sheet; this ledger records who may approve and enter a change, not what the public wording should be.

Trace where contacts and records go

For each form inbox, call record, booking calendar, message route, analytics property, or reporting file inside the signed scope, name the business-controlled account and the approved owner and manager roles. Attach the existing contact-path record for routing and test details instead of repeating them here.

Do not place private customer records inside the account ledger. It can name the system and responsible owner without becoming a copy of the data inside it.

Write the offboarding step before it is needed

Every outside access line should have an end condition. State who can remove access, what must be handed back, which records belong in the final package, and how the owner confirms continuing business control.

Do not remove an old user merely because the name looks unfamiliar. First verify authority, make sure the business has a working owner role and recovery path, record the approval, and then make the authorized change. An access cleanup should not lock the owner out.

At handoff, recheck the ledger without publishing or deleting anything unless the signed scope says to do so. Mark each line CONFIRMED, CHANGED, HELD, or OUTSIDE SCOPE with a date and approver.

The ledger can show who was recorded with which role on the checked date. It cannot guarantee security, uninterrupted access, platform approval, inquiries, or revenue. It also does not replace a security review, contract review, or legal ownership decision.

Bring the account list to the free check and use it to find the first control gap before any work starts.

← All posts