Practical guide

Remove access without breaking the client website

Last materially reviewed 2026-09-21

Quick answerTransfer responsibilities and verify continuity before revoking obsolete access.
What to know

Establish continuity before revocation

Begin by confirming who will operate the website after the current person or agency leaves. Provide the ownership map, service inventory and accepted application state. A fictional client should not discover that the departing developer is the only person who can reach DNS or receive billing notices. Resolve those dependencies through supported delegation or transfer before removing access, without sharing secrets in a general handoff document.

What to know

List the actual access paths

Review platform invitations, application administration, file-transfer credentials and relevant external services within the authorized scope. Removing one team member does not necessarily describe every credential involved in the arrangement. Use current provider documentation and known records rather than guessing. Keep the review bounded to the departing role and preserve unrelated users, clients and settings. An offboarding task is not authority to reorganize the entire account.

What to know

Verify the ownership operation before transfer

Cloudways server transfer can involve several applications, while a single client may require only one site to move. Other providers have different site-transfer and billing consequences. Verify the exact target, receiving owner and retained obligations before initiating a change. A successful invitation or transfer acknowledgement is not enough: check that the intended person has usable access and that the public service remains available without relying on the departing operator.

What to know

Close with a recoverable record

After authorized access removal, record what changed and what was verified without exposing credentials. Preserve necessary recovery and audit evidence; do not delete material merely because the engagement ended. Identify any unresolved billing or external-service responsibility plainly. Offboarding succeeds when obsolete access is removed while the client retains a usable, understandable website operation—not when every old account is deleted as quickly as possible.

Continue when useful

Next: A client handoff with evidence, not a pile of passwords

Hand over a usable operating record and verify the client can reach the controls they own.

Open A client handoff with evidence, not a pile of passwords →

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. Cloudways collaboration and separate application credentials — Merchant documentation · support.cloudways.com · Merchant-controlled · checked 2026-09-21
  2. Cloudways server transfers: owner and paid-account requirements — Merchant documentation · support.cloudways.com · Merchant-controlled · checked 2026-09-21
  3. WP Engine site-transfer requirements and extension effects — Alternative provider · wpengine.com · Publisher independence not verified · checked 2026-09-21