What you can see, you can run.
Check Your ASSets — Don't Lose Your System When Your Developer Does
The contract was fine. The developer was nice. Three years of a humming website, most months you didn't even think about it. And then a Saturday morning of a long weekend, the site is down — and the only person who knows how to fix it isn't answering the phone.
This is The Mundane's longest con. It convinces you that because the work is getting done, the keys are in safe hands. It whispers “why would you ever need to log in yourself?” for years — until the day you need to and discover you can't. Then Chaos steps in wearing a translucent contractor's coat, brass keyring of unlabeled keys dangling, and shrugs: “The docs? Oh — they were ‘around here somewhere.’”
A good external developer is a real asset. The keys to your own systems are an even bigger one. You can — and should — have both. This chapter is how.

Hire good people. Trust them. AND keep your own keys. The faithful steward isn't the one who never delegates — it's the one who's ready when delegation ends.
Every credential in your name. Every admin account yours. Every doc on your side of the table. Every plugin mapped. Every login tested — by you — this quarter. Six lines. Stick them on the wall. #AutomateThis!

The Crew's playbook: the Asset Audit
Walk every system your business touches through these seven questions. Any “no” is a key you don't actually hold — and a thing to fix this week, not someday.
- 1
Is every credential in your org's name?
Domain registrar, hosting, CMS admin, database, email DNS, source-code repo, payment processor, analytics. If any of those are in a vendor's personal account, you don't own them — you're renting them. Reset registrations into the org's name today.
- 2
Is every admin account YOUR account?
The owner role should be you, with the developer added as an additional admin. Not their account that you log in to. When they leave the engagement, you remove their access — not the other way around.
- 3
Do you have your own copy of the source code?
The theme, the customizations, the plugin overrides, the env config — in a repo your org owns (your GitHub/GitLab org, not the dev's personal account). 'It's on his computer' is not a copy.
- 4
Is there a one-page runbook?
Plain language: how to deploy, how to roll back, where backups live, what to do when the site is down, who to call. Stored in your drive, not the vendor's. Future-you on a holiday weekend will be grateful.
- 5
Do you have a plugin and integration map?
Every active plugin, what it does, what it touches, when it renews, who needs to be paid. The mystery plugins your developer 'just added once' are exactly the ones that will break years later.
- 6
Have YOU logged in to every system this quarter?
Not the developer — you. Walk through every credential and confirm it works. If you haven't logged in, you don't actually have access; you have a claim of access, which is not the same thing.
- 7
Are 2FA recovery codes stored where YOU can reach them?
Printed, in a folder, in a safe — or in a password manager your org controls. If the only path back into a locked account runs through someone else's phone, you're one lost phone from a crisis.
The Asset Inventory worksheet
The audit becomes real when you write it down. A five-column table on one page, revisited every quarter:
| System | Owner of record | Where credentials live | Where docs live | Last verified by you |
|---|---|---|---|---|
| Domain registrar | Your org | Org password manager | Org drive / runbook | YYYY-MM-DD |
| Hosting | Your org | Org password manager | Org drive / runbook | YYYY-MM-DD |
| CMS admin | You (dev added) | Org password manager | Org drive / runbook | YYYY-MM-DD |
| Source code (repo) | Your org | Org GitHub/GitLab | README in repo | YYYY-MM-DD |
| Payment processor | Your org | Org password manager | Vendor-portal link | YYYY-MM-DD |
Repeat the row for every system: email DNS, analytics, backup service, plugin marketplace accounts, the lot. The version of this table that has every row filled in and a recent date in the last column is the version of this table that protects you.
What undocumented work looks like in the wild
The most common shape: a small WordPress site, built three years ago by a freelance developer, with a dozen plugins layered in over time. Some are paid; their licenses live in the dev's email. Some have custom code on top — changes that aren't in any public repo because the dev edited the theme files directly on the server. The hosting account is in the dev's name. The DNS is at a registrar the dev set up. The “docs” are an outline in a Notion the dev once shared, that you bookmarked and never opened.
The site works beautifully — until it doesn't. The day the dev goes on a long honeymoon, closes the consultancy, or simply stops returning calls, every one of those quiet assumptions becomes a locked door. The Audit doesn't fire the developer. It just makes sure you're standing on rock instead of someone else's sand.
Avoiding the Ghost Vendor handoff
Set the expectations at the start of an engagement, not the end. A good developer will welcome these — they make the relationship cleaner and protect both sides:
- Open every account in your org's name first; add the developer as an admin. Never the other way around.
- Stand up the repo on your org's GitHub/GitLab before the first line of code. The developer pushes there.
- Require a runbook deliverable as part of any non-trivial project. Plain language, one page, in your drive.
- Schedule the quarterly “I log in to everything” ritual. Calendar reminder. Twenty minutes. The cheapest insurance you'll ever buy.
- Document the handoff plan in the contract. Not because you expect trouble — because a relationship that's designed to end cleanly is one that's healthier while it's running.
How Chaos & The Mundane win
- One person — usually the developer — knows every password, and "will document it later."
- The repo lives on the developer's personal GitHub. The org has never seen the code.
- The .env file with API keys is on a freelancer's laptop, and only on a freelancer's laptop.
- Admin accounts use the developer's email, so renewal notices and security alerts go to them, not you.
- "Trust me, the docs are good" — said about docs nobody on your team has read.
Common questions
▸ How do I ask my current developer for all this without seeming like I don't trust them?
Frame it as succession planning, not suspicion — and good developers will be relieved you asked. The line that works: 'If you got hit by a bus tomorrow, or just took a long vacation, I'd be in real trouble. Can we make sure I'm set up to not be?' A vendor who pushes back on that conversation is telling you something important about the relationship.
▸ We already have a developer and never set this up. Where do we start?
Start with the credentials that touch money or identity: domain registrar, hosting, payment processor, primary email. Move ownership of those into your org's name first; everything else follows. Then schedule a 30-minute working session with the developer to walk through the rest of the audit — most of it can be fixed in an afternoon.
▸ The developer says docs exist. Should I believe them?
Until you've held the docs in your own hand and read them yourself, they don't exist for you. Ask for the link today. Open it. If they need more time, that's fine — but the gap between 'I have docs' and 'you have docs' is the entire risk this chapter is about closing.
▸ What if the developer is a one-person shop and just won't have the bandwidth?
Then this matters even more. A one-person vendor is one phone, one hard drive, one health scare from your site being unrecoverable. Pay them for the time it takes to do the audit properly — it's the cheapest insurance you'll ever buy on the relationship.
The next leg of the journey
Prefer a story? See these ideas play out in our comic-book field guide.
Ready to reach your Pitch?
You don't need a full-time CTO to do this right. Island Pitch works as your Fractional CTO — senior technology leadership at a nonprofit's budget, helping you choose well, lock the doors, and sleep at night.
Get the whole field manual
The full Right-Way Tech Guide — all seven chapters, plus the Asset Inventory worksheet — as a printable PDF.
The field manual is yours — grab it now.
Our signup form is being upgraded. In the meantime, here's the full PDF — no form to fill out.
Download the field manual (PDF)Want occasional tech tips by email too? Talk to a Fractional CTO above — we'll get you on the list.
