Article image
The Clean Offboarding Checklist: How to Hand Over Digital Assets Without Liability
In the agency world, we spend an enormous amount of time, energy, and budget perfecting our onboarding processes. We craft beautiful welcome packets, map out intricate project timelines, and build automated Slack notifications to ensure every new client feels like a VIP.
But what happens at the end of the lifecycle?
Offboarding web design clients is arguably more critical than onboarding them. When a project concludes, a retainer ends, or a client decides to move their business in-house, the transition of digital assets must be handled with surgical precision. A messy offboarding process doesn't just leave a bad taste in the client's mouth; it creates massive financial and legal liabilities for your agency.
Imagine waking up to a $600 annual hosting renewal charge for a client you haven't spoken to in two years. Or worse, imagine a former client suffering a data breach and pointing the finger at your agency because your administrative credentials were never revoked.
This guide walks through how to build a bulletproof client offboarding checklist: how to transfer a website to a client, safely revoke agency access, and use modern operations dashboards to generate a final Asset Handoff Report — including several policy and platform changes that have reshaped how this process works over the past two years.
- The Hidden Risks of a Messy Offboarding Process Before diving into the checklist, it's worth understanding why a standardized offboarding procedure is a non-negotiable part of your agency's business model. When you fail to cleanly separate your agency from a client's digital infrastructure, you expose yourself to three primary risks.
A. The "Zombie" Subscription (Financial Leakage)
Agencies often purchase premium plugins, SaaS tools, or dedicated hosting environments on behalf of clients. If you don't formally transfer billing for these assets during offboarding, you keep bleeding money long after the relationship ends.
This isn't a hypothetical. Zylo's 2025 SaaS Management Index found that the average organization's SaaS spend reached roughly $4,830 per employee in 2025, up nearly 22% year over year — and about 36% of purchased licenses go completely unused. For an agency running dozens of client subscriptions in its own name, unformalized offboarding is one of the cleanest ways that waste accumulates.
B. The Security and Liability Threat (Data Breaches)
In an era of stringent data privacy laws, lingering access is a real liability, not a theoretical one. If you retain administrative access to a former client's WordPress backend, Shopify store, or Google Analytics account, your agency represents a backdoor vulnerability. If the client's site is compromised, or an employee at your agency has their own credentials stolen, your agency could be pulled into the resulting breach investigation. Revoking agency access severs that liability loop.
This has gotten more, not less, important. In California, the CPPA finalized a significant package of CCPA/CPRA regulatory updates that took effect January 1, 2026, adding mandatory risk assessments and expanded enforcement teeth — the agency issued a record $1.35 million fine in September 2025, and California's Attorney General followed with a $2.75 million settlement in February 2026. GDPR obligations in the EU remain similarly strict. None of this changes the fundamentals of good offboarding hygiene, but it does raise the cost of getting it wrong.
C. The Hostage Situation (Reputational Damage)
When a client asks for their assets and the agency scrambles for weeks trying to locate domain credentials, untangle shared hosting environments, and figure out who holds the premium license for their form builder, the client feels trapped. This damages your reputation, kills referrals, and can lead to contentious disputes over asset ownership.
- Phase 1: The Administrative Break (Transferring Billing & Ownership) The first phase revolves around finances and legal ownership. The goal is to ensure your agency's credit card is removed from all infrastructure and the client holds the primary legal rights to their assets.
2.1 Untangling the Hosting Environment
If you're currently hosting the client's website on your agency's reseller account or a dedicated server, you need to physically transfer the website to the client.
If transferring to a new agency/host: Provide the client (or their new technical partner) with a full, unencrypted backup of the website files (e.g., a .zip of the wp-content folder or equivalent) and a .sql export of the database.
If transferring billing on the same platform: Some managed WordPress hosts support a self-service ownership handoff. Flywheel (WP Engine's design-focused hosting line) publishes a documented "Transfer Billing" workflow: you initiate the transfer, the client receives an email, enters their own billing details, and the site moves to their account without going offline. Support for this varies by host and plan tier, so confirm the exact process with your provider — on some hosts it still requires a support ticket rather than a self-service toggle.
2.2 Domain Name Handover
As with hosting, the client should always own their domain outright. If you registered it on their behalf under your agency's registrar account, you need to transfer it — and the mechanics changed in late 2024.
Under the ICANN Transfer Policy that took effect November 19, 2024, the old-style static EPP code (also called an auth code or Auth-Info code) is being phased out in favor of a Transfer Authorization Code (TAC). Functionally it does the same job — it proves to the gaining registrar that the transfer is authorized — but the mechanics are different:
A TAC is generated on demand, not stored indefinitely in your registrar dashboard.
It has a capped lifespan, typically up to 14 days, and is stored by the registry only as a one-way hash rather than in plain text.
Don't generate it weeks in advance the way agencies used to with a static EPP code — it will likely expire before the client uses it.
The updated checklist for this step:
Unlock the domain at your registrar.
Disable domain privacy (temporarily) if required by the receiving registrar.
Generate the TAC/EPP code close to the actual transfer date — ICANN policy requires registrars to supply it within 5 calendar days of the holder's request, assuming the account is in good standing.
Send the code to the client so they can initiate the transfer to their own registrar (GoDaddy, Namecheap, Cloudflare, etc.) within its validity window.
Note also that domains generally can't be transferred within 60 days of initial registration or within 60 days of a prior transfer — a timing detail worth checking before you promise a client a same-day handover.
2.3 Software and Premium Plugin Licenses
This is a frequent sticking point: does the client get to keep your agency's developer license for a premium theme or plugin?
Agency licenses: If you use an unlimited agency license, explain to the client that it's tied to your active maintenance plan. Upon offboarding, the plugin will keep functioning, but they'll stop receiving security updates and support through your license. They'll need to purchase their own single-site license.
Individual licenses: If you purchased a license specifically for them using their budget, change the email address and billing details on the software account to the client's information.
One example worth flagging directly: Advanced Custom Fields (ACF), long used as a shorthand for "safe, boring, premium plugin" in checklists like this one, was at the center of a real ownership dispute in 2024–2025. After WP Engine and Automattic (WordPress.org's parent company) became embroiled in a legal fight, Automattic briefly forked the free version of ACF into a plugin called Secure Custom Fields and revoked WP Engine's access to the original plugin's WordPress.org listing. A federal court ordered access and control restored to WP Engine in December 2025. The practical lesson for agencies: don't assume a plugin's ownership, update channel, or licensing terms are permanently stable just because they've been reliable for years — note the current plugin source and license type in your handoff documentation, not just the plugin name.
- Phase 2: Revoking Agency Access (Security & Liability) Once billing and assets are transferred, you need to methodically lock yourself out. This protects the client from unauthorized changes and protects you from liability.
3.1 Content Management System (CMS) Access
Downgrade or delete: Log into the CMS (WordPress, Shopify, Webflow, etc.). If you're completely severing ties, have the client create their own Administrator account if they don't already have one. Once they confirm they can log in, have them delete your agency's Administrator account.
Attribution: Deleting your user account shouldn't delete the content you published. In WordPress, always reassign the deleted user's posts and pages to the new client administrator during the deletion step rather than letting the software default to "no author."
3.2 DNS and CDN Managers
If you managed a client's DNS records via Cloudflare, Route 53, or directly at the registrar:
Export a copy of the DNS zone file (in case something breaks during the transition).
Remove your team's delegated access from their Cloudflare/registrar account.
If the DNS was hosted on your agency's own Cloudflare account, migrate the domain to a Cloudflare account owned by the client.
3.3 The Google Ecosystem & Other Integrations
Agencies often set up Google Analytics (GA4), Google Tag Manager (GTM), and Google Search Console (GSC) for clients.
Ensure the client's primary Google account is set to Administrator (for GA4/GTM) and Owner (for GSC).
Remove your agency's email addresses from the user management lists.
Disconnect any agency-owned Zapier webhooks, CRM API keys, or SMTP relays (like SendGrid or Mailgun) that were routing through your infrastructure.
Same principle applies to social platforms. Meta rebranded Facebook Business Manager as Meta Business Portfolio in 2024 — the functionality is unchanged, but agencies should confirm they're removing partner access at the Business Portfolio / business-settings level, not just unfollowing a Page, since ad accounts, pixels, and catalogs can sit under different permission layers than the Page itself.
- The Ultimate Client Offboarding Checklist A consolidated checklist you can drop directly into your project management software (Asana, ClickUp, Monday.com) for offboarding web design clients.
Financial & Contractual
[ ] Final invoice generated and paid in full.
[ ] Cancel active recurring subscriptions (care plans, retainers) in Stripe/accounting software.
[ ] Send formal contract termination/completion notice.
Asset Transfer & Billing
[ ] Transfer domain registrar ownership (or provide the current TAC/EPP code, generated close to the transfer date).
[ ] Transfer website hosting ownership/billing.
[ ] Hand over individual plugin/software licenses.
[ ] Provide a list of agency-licensed tools that will require the client to purchase their own licenses.
Access Revocation (Locking Yourself Out)
[ ] Remove agency users from WordPress/Shopify/CMS.
[ ] Remove agency delegated access from the domain registrar/DNS provider.
[ ] Remove agency users from Google Analytics, Google Tag Manager, and Google Search Console.
[ ] Remove agency access from the client's Meta Business Portfolio and LinkedIn Page admin list.
[ ] Delete client passwords and sensitive keys from the agency's password manager (e.g., 1Password, LastPass).
Archiving & Deliverables
[ ] Package brand assets (logos, fonts, brand guidelines) into a secure Google Drive/Dropbox folder.
[ ] Package final design files (Figma, Adobe XD).
[ ] Create a final, full-site backup (files + database) and provide it to the client.
[ ] Archive the project internally in your agency's PM tool.
- Standardizing the Process: The Asset Handoff Report Executing the steps above is only half the battle; documenting the handover is where you truly protect your agency. If a client comes back six months later claiming they never received their domain access, you need a paper trail.
This is where a written Asset Handoff Report earns its keep. Instead of relying on scattered emails and spreadsheets to prove what was handed over, some agencies use renewal and asset-tracking dashboards — InstaRenewal is one example — to keep this information current throughout the project rather than reconstructing it at the end. InstaRenewal is built specifically for this: it tracks domains, SSL certificates, hosting, plugin licenses, ownership, payment responsibility, and access status in one workspace, and it can generate client-ready reports summarizing that information. It's worth noting what it doesn't do — by design, InstaRenewal doesn't store passwords, private keys, API secrets, or client credentials, so it's a record of who owns and controls what, not a credential vault.
What a good Asset Handoff Report should include:
Infrastructure map: The current domain registrar, DNS host, and web host.
License ledger: A breakdown of software running on the site, noting which tools were agency-licensed (requiring client action) and which were transferred to the client outright.
Access confirmation: A documented list of platforms where agency access has been formally revoked.
Important dates: Domain and SSL certificate expiration dates, so the client knows when they're responsible for upcoming renewals.
A note on the "legal release" framing: having the client acknowledge receipt of this report in writing (an email confirmation or an e-signature tool of your choosing) is good practice and creates a useful record. Whether it functions as a full legal release of liability depends on your contract terms and applicable law, so it's worth having your actual services agreement — not just the handoff report — reviewed by a lawyer if you want it to carry that weight. This article isn't legal advice.
- Email Scripts: How to Communicate the Offboarding Communication during the offboarding phase should be clear, helpful, and firm about boundaries.
Template 1: The Transition Kickoff (30 Days Out)
Subject: Next Steps: Transitioning Your Website Assets
Hi [Client Name],
We're thrilled with the launch of the new site and have loved working with your team! As our active maintenance agreement/project comes to a close on [Date], we're preparing to transition full ownership of your digital assets over to you.
Over the next two weeks, we'll be transferring the billing for your hosting and premium software directly to your company. You'll receive a few automated emails from platforms like [Hosting Company] asking you to enter your billing details.
Please keep an eye out for these, as establishing your billing ensures your site stays live and fast without interruption. Let us know when you have a moment this week for a brief 15-minute handoff call to review the final checklist.
Best,
[Your Name]
Template 2: The Final Handoff & Goodbye
Subject: Final Deliverables & Asset Handoff Report Enclosed
Hi [Client Name],
Attached to this email is your final Asset Handoff Report. This document contains a map of your digital infrastructure, including where your domain is registered, where your site is hosted, and a list of licenses associated with your website.
As of today, our team has revoked our administrative access to your systems to protect your security and data privacy. We've also deleted your credentials from our internal password managers.
Included in the linked Dropbox folder are your final design files, brand assets, and a complete backup of your website as it stands today.
We wish you the best moving forward. If you ever need to engage us for a future project, please don't hesitate to reach out!
Best,
[Your Name]
- The Post-Offboarding Internal Audit Even after the client has acknowledged the final Asset Handoff Report and the goodbye email has gone out, the agency should run a quick internal audit.
Profit & loss check: Verify that the client's project has been reconciled in your accounting software. Did all out-of-pocket expenses for their software get billed back to them?
Portfolio update: If your contract permits, add screenshots, performance metrics, and a case study of the project to your agency's portfolio while the data is fresh.
Team debrief: Hold a short post-mortem with the developers and designers who worked on the account. What went well? What scope creep occurred? How can the process improve for the next client?
- What's Changed Recently: Policy and Platform Shifts Worth Tracking Offboarding checklists tend to get written once and reused for years, but several of the underlying mechanics have shifted meaningfully in the last two years. Worth keeping on your radar heading through 2026:
Domain transfers now run on TAC, not static EPP codes. As covered above, ICANN's November 2024 Transfer Policy update replaced indefinitely valid auth codes with short-lived Transfer Authorization Codes. If your offboarding SOP still tells staff to "grab the EPP code and store it in the client folder," it needs updating — the code should be generated close to the actual transfer, not stockpiled in advance.
Plugin ownership isn't always as stable as it looks. The WP Engine–Automattic dispute over the ACF plugin — including a period where the plugin was forked without WP Engine's consent before a court ordered it restored — is a reminder to record which entity actually controls a plugin's update channel, not just its name, in your license ledger.
Meta's admin layer has been renamed. Facebook Business Manager is now Meta Business Portfolio. The permission structure didn't change, but agencies writing offboarding SOPs that still reference "Business Manager" by name should note the current terminology so junior staff can actually find the settings.
Privacy regulation enforcement has intensified. New CCPA/CPRA regulations took effect in California on January 1, 2026, adding mandatory risk assessments and heavier enforcement — multiple settlements in the six- and seven-figure range landed in the months before and after that date. This doesn't change the offboarding checklist itself, but it raises the real cost of lingering, unrevoked access to client systems.
SaaS waste remains a measurable, sourced problem, not just a talking point. Industry data (Zylo's SaaS Management Index) puts unused license rates at roughly a third of all purchased seats industry-wide. For agencies fronting client software costs, that's a solid, citable stat for the "zombie subscription" argument rather than an anecdote.
Conclusion: Turning a Goodbye into a Referral Engine
Offboarding web design clients doesn't have to be a tense, chaotic scramble for passwords and credit cards. When you treat the end of a client relationship with the same systematic rigor as the beginning, you protect your agency from real liabilities, stop financial leakage from zombie subscriptions, and leave the client feeling secure.
By following a clear client offboarding checklist, transferring assets using the current mechanics rather than a two-year-old process, and keeping a central record to generate an Asset Handoff Report, you raise your agency's operational maturity. A clean, professional exit is often the very thing that makes a former client confidently refer you to their network.
Sources
Zylo, 2025/2026 SaaS Management Index — SaaS spend and unused-license statistics
ICANN, Transfer Policy (updated Feb 21, 2024; implementation window through Aug 21, 2025) — icann.org
SEO.Domains, The EPP Code (Auth Code) Explained — 2024 Transfer Authorization Code (TAC) shift
DCHost.com, ICANN Domain Policy Changes: What They Mean For Your Domains In 2025
LegalClarity, What Is an EPP Authorization Code and How to Get It
WP Tavern, WP Engine Regains WordPress.org Access and ACF Plugin Control Following Court Ruling (Dec 2024) and related coverage of the WP Engine–Automattic dispute
365i.co.uk, Court Orders Automattic to Restore WP Engine Access in 72 Hours (Dec 2025)
Flywheel/WP Engine support documentation, Transfer billing to my client
ALM Corp / AgencyAccess, coverage of the Meta Business Manager → Meta Business Portfolio rename (2024)
California Privacy Protection Agency (CPPA), announcements and 2026 regulatory package; Koley Jessen, Lessons for Businesses From 2026's First California Privacy Enforcement Actions
InstaRenewal.com, product and feature pages (instarenewal.com)
Top comments (0)