Skip to main content
Our 2026 primary beneficiary: The LGBTQ+ Center Long Beach
IslandPitch.in
← Guides
🗝️ Chapter 7 · The Vanishing Keysvs Chaos & The Mundane

What you can see, you can run.

Check Your ASSets — Don't Lose Your System When Your Developer Does

The contract was fine. The developer was nice. Three years of a humming website, most months you didn't even think about it. And then a Saturday morning of a long weekend, the site is down — and the only person who knows how to fix it isn't answering the phone.

This is The Mundane's longest con. It convinces you that because the work is getting done, the keys are in safe hands. It whispers “why would you ever need to log in yourself?” for years — until the day you need to and discover you can't. Then Chaos steps in wearing a translucent contractor's coat, brass keyring of unlabeled keys dangling, and shrugs: “The docs? Oh — they were ‘around here somewhere.’”

A good external developer is a real asset. The keys to your own systems are an even bigger one. You can — and should — have both. This chapter is how.

Masked Crewsader
Masked Crewsader

Hire good people. Trust them. AND keep your own keys. The faithful steward isn't the one who never delegates — it's the one who's ready when delegation ends.

IP Bot

Every credential in your name. Every admin account yours. Every doc on your side of the table. Every plugin mapped. Every login tested — by you — this quarter. Six lines. Stick them on the wall. #AutomateThis!

IP Bot

The Crew's playbook: the Asset Audit

Walk every system your business touches through these seven questions. Any “no” is a key you don't actually hold — and a thing to fix this week, not someday.

  1. 1

    Is every credential in your org's name?

    Domain registrar, hosting, CMS admin, database, email DNS, source-code repo, payment processor, analytics. If any of those are in a vendor's personal account, you don't own them — you're renting them. Reset registrations into the org's name today.

  2. 2

    Is every admin account YOUR account?

    The owner role should be you, with the developer added as an additional admin. Not their account that you log in to. When they leave the engagement, you remove their access — not the other way around.

  3. 3

    Do you have your own copy of the source code?

    The theme, the customizations, the plugin overrides, the env config — in a repo your org owns (your GitHub/GitLab org, not the dev's personal account). 'It's on his computer' is not a copy.

  4. 4

    Is there a one-page runbook?

    Plain language: how to deploy, how to roll back, where backups live, what to do when the site is down, who to call. Stored in your drive, not the vendor's. Future-you on a holiday weekend will be grateful.

  5. 5

    Do you have a plugin and integration map?

    Every active plugin, what it does, what it touches, when it renews, who needs to be paid. The mystery plugins your developer 'just added once' are exactly the ones that will break years later.

  6. 6

    Have YOU logged in to every system this quarter?

    Not the developer — you. Walk through every credential and confirm it works. If you haven't logged in, you don't actually have access; you have a claim of access, which is not the same thing.

  7. 7

    Are 2FA recovery codes stored where YOU can reach them?

    Printed, in a folder, in a safe — or in a password manager your org controls. If the only path back into a locked account runs through someone else's phone, you're one lost phone from a crisis.

The Asset Inventory worksheet

The audit becomes real when you write it down. A five-column table on one page, revisited every quarter:

SystemOwner of recordWhere credentials liveWhere docs liveLast verified by you
Domain registrarYour orgOrg password managerOrg drive / runbookYYYY-MM-DD
HostingYour orgOrg password managerOrg drive / runbookYYYY-MM-DD
CMS adminYou (dev added)Org password managerOrg drive / runbookYYYY-MM-DD
Source code (repo)Your orgOrg GitHub/GitLabREADME in repoYYYY-MM-DD
Payment processorYour orgOrg password managerVendor-portal linkYYYY-MM-DD

Repeat the row for every system: email DNS, analytics, backup service, plugin marketplace accounts, the lot. The version of this table that has every row filled in and a recent date in the last column is the version of this table that protects you.

What undocumented work looks like in the wild

The most common shape: a small WordPress site, built three years ago by a freelance developer, with a dozen plugins layered in over time. Some are paid; their licenses live in the dev's email. Some have custom code on top — changes that aren't in any public repo because the dev edited the theme files directly on the server. The hosting account is in the dev's name. The DNS is at a registrar the dev set up. The “docs” are an outline in a Notion the dev once shared, that you bookmarked and never opened.

The site works beautifully — until it doesn't. The day the dev goes on a long honeymoon, closes the consultancy, or simply stops returning calls, every one of those quiet assumptions becomes a locked door. The Audit doesn't fire the developer. It just makes sure you're standing on rock instead of someone else's sand.

Avoiding the Ghost Vendor handoff

Set the expectations at the start of an engagement, not the end. A good developer will welcome these — they make the relationship cleaner and protect both sides:

How Chaos & The Mundane win

Common questions

How do I ask my current developer for all this without seeming like I don't trust them?

Frame it as succession planning, not suspicion — and good developers will be relieved you asked. The line that works: 'If you got hit by a bus tomorrow, or just took a long vacation, I'd be in real trouble. Can we make sure I'm set up to not be?' A vendor who pushes back on that conversation is telling you something important about the relationship.

We already have a developer and never set this up. Where do we start?

Start with the credentials that touch money or identity: domain registrar, hosting, payment processor, primary email. Move ownership of those into your org's name first; everything else follows. Then schedule a 30-minute working session with the developer to walk through the rest of the audit — most of it can be fixed in an afternoon.

The developer says docs exist. Should I believe them?

Until you've held the docs in your own hand and read them yourself, they don't exist for you. Ask for the link today. Open it. If they need more time, that's fine — but the gap between 'I have docs' and 'you have docs' is the entire risk this chapter is about closing.

What if the developer is a one-person shop and just won't have the bandwidth?

Then this matters even more. A one-person vendor is one phone, one hard drive, one health scare from your site being unrecoverable. Pay them for the time it takes to do the audit properly — it's the cheapest insurance you'll ever buy on the relationship.

Prefer a story? See these ideas play out in our comic-book field guide.

Ready to reach your Pitch?

You don't need a full-time CTO to do this right. Island Pitch works as your Fractional CTO — senior technology leadership at a nonprofit's budget, helping you choose well, lock the doors, and sleep at night.

Get the whole field manual

The full Right-Way Tech Guide — all seven chapters, plus the Asset Inventory worksheet — as a printable PDF.

The field manual is yours — grab it now.

Our signup form is being upgraded. In the meantime, here's the full PDF — no form to fill out.

Download the field manual (PDF)

Want occasional tech tips by email too? Talk to a Fractional CTO above — we'll get you on the list.