Guides · Security & maintenance

Sharing access with contractors: safer handover patterns

Agencies appreciate clarity too; ambiguity causes slow fixes and duplicated effort.

Patterns that scale down to one-person shops

  • Named cms-websites">CMS users with roles; disable when the contract ends.
  • Project vault for secrets instead of Slack DMs of root passwords.
  • Read-only dashboards for stakeholders who only need analytics.

Handover minimum artefacts

List hosting, registrar, DNS, email provider, repo URL, deployment method, payment plugins, and cron jobs. Include environment variables without committing secrets to git.

Legal and commercial clarity

Who owns code, licences, and third-party API keys after the project? Sort this when everyone is friendly—post-dispute recovery is slow.

Frequently asked questions

They asked for my main Google login—normal?

Prefer granting access to specific properties (Analytics, Search Console) over full account sharing.

Freelancer disappeared with credentials—now what?

Use registrar/host recovery flows, prove domain ownership, rotate everything, and rebuild access from known owners.

Putting this into practice on your NZ website

This guide sits in our Security & maintenance collection. The goal is practical advice you can act on without a computer science degree. Start with one change, measure whether enquiries or usability improve, then tackle the next item. Small businesses across Auckland, Wellington, Hamilton, Christchurch, and regional New Zealand face the same constraints: limited time, real customers, and a website that must earn its keep.

For Sharing access with contractors: safer handover patterns, the highest-leverage move is usually to align your live site with what the guide recommends, then fix anything that blocks Google from crawling pages or stops visitors from contacting you. If your site runs on WordPress, many of these tasks are configuration and content work rather than custom development.

Document your starting point: note current enquiry volume, average page speed from PageSpeed Insights, and any errors showing in Google Search Console. Without a baseline, improvements are guesswork. Revisit the same metrics after 90 days—SEO and UX changes rarely produce overnight miracles, but sustained progress should be visible in leads and user behaviour.

Share this guide with whoever maintains your site—an employee, a contractor, or your hosting support desk—so terminology and priorities align. The FAQ section on our main site answers common project questions if you are weighing a rebuild versus incremental fixes.

When to involve a web partner

Some tasks—migrations, checkout changes, security incidents, or a full redesign—benefit from experienced help. If you are comparing providers, look for clear scoping, realistic timelines, and measurement tied to business outcomes rather than vanity metrics. Our team builds and maintains business websites nationwide; explore relevant services below or request a quote when you are ready.

A good partner will ask about your customers, geography, and capacity to publish content—not only colour preferences. Review our recent website projects for examples of brochure, WordPress, and ecommerce work across New Zealand.

Related NZDH services

More guides in this topic

Browse the full Security & maintenance guide hub or return to the guides home.

Explore on NZDH.co.nz

Authoritative further reading

These independent resources complement this guide. Search engines and customers both reward accurate, helpful information—we link out where official documentation or regulators explain the topic better than a generic blog post could.