Every Friday in October, this blog takes one chapter of Strategic Web Management: First Steps for the Accidental Web Manager and argues its central idea, paired with the podcast episode and the worksheet built from it. This week is Chapter 2, the web account inventory, and the idea at its center is the single most common trap I find in inherited web stacks: the difference between who can log in to an account and whose name the account is actually under.

The two feel identical on a normal day. They behave nothing alike on a bad one. I have watched a Fortune 500 client spend several thousand dollars and months of negotiation buying back a domain that an employee registered years earlier under a personal email address, and I have watched a small nonprofit lose a week of email because the web company that "handled all that" held the registration in its own name. The purpose of this post is to make that distinction impossible to forget.

The distinction

Access is who can log in. Ownership is whose name, whose email address, and whose payment card the account is registered under. You can have full administrator access to a domain registered under a departed employee's personal Gmail, and on the day something goes wrong, the recovery email, the verification codes, and the legal standing all belong to a person who no longer works for you.

While weak access is inconvenient, wrong ownership is dangerous. The vendor who holds your domain registration in its own name is a vendor with your lease in its filing cabinet; the relationship is fine until you want to leave. The site built under a founder's personal account is fine until the founders disagree.

The question to ask

The chapter frames it the way a stakeholder would: if the person who registered your domain left tomorrow and stopped answering texts, what would it cost to get it back? Sometimes the answer is a support ticket and a week. Sometimes the answer is a lawyer. The organizations that know their answer in advance are the ones that ran the ten-minute audit; the rest find out at the worst possible time.

How it happens

Nobody in the pattern acts in bad faith. A helpful vendor or volunteer builds the site and registers the domain, the hosting, and the email under accounts they control, because it was faster that way and nobody objected. Years pass, the site works, and the arrangement becomes invisible. Then the vendor retires, the volunteer moves away, or the relationship sours, and the organization discovers it does not own its own name online. The trap is built from good intentions and missing paperwork, which is why it catches careful people.

The audit

For every account in the inventory, record three facts beside the access column: the owner of record, the recovery email and phone number on the account, and the payment method attached. Then flag anything registered to a personal email address, anything owned by a former employee or an outside vendor, and anything whose recovery contact you cannot verify. The workbook has a flag column for exactly this pass.

The standard

The recommendation is the same across every category. Accounts should be owned by the organization, registered to a role-based address the organization controls, such as [email protected], with billing on an organizational card and at least two people sharing access. Role-based addresses pay off twice: they survive every staff change without a single account migration, and they assert organizational ownership in a vendor support conversation in a way no personal Gmail can. Treat that address as infrastructure; never post it publicly.

Moving each account to that standard is slow work, one support ticket at a time, and domain transfers have their own procedure in Chapter 3. Do the easy ones now and calendar the hard ones. Every account you re-anchor is a risk you retire.

Hear it, read it, do it

Episode 3 of The Web Managers Podcast, The Web Account Inventory: Do This First, walks the whole chapter in about twenty minutes and slows down for this exact trap. Chapter 2 gives it the full treatment, including the discovery hunt and the password vault. The worksheet is where the work gets done: the ownership columns are already in it.

Get the worksheet free. The M2.1 Web Account Inventory Workbook, with the ownership audit columns and the risk flag, is free with a registered account in the Web Managers Portal. Get the book: Strategic Web Management: First Steps for the Accidental Web Manager.