Australian Website Design Measured figures. Named sources.
Menu Close

Maintenance

Who holds the keys to your website

Who should hold your website login details? Domain, hosting, CMS admin and DNS access are four things, each held by a different party, worth confirming.

A single website genuinely depends on at least four separate accounts, and a business can hold three of them confidently while having no real access to the fourth — which is enough, on its own, to lose meaningful control of the site if a relationship ends badly. Knowing which of the four a business actually controls is a five-minute audit worth doing regardless of how well any current arrangement is going.

The four accounts, stated plainly

The domain registrar account, controlling the domain licence itself — covered fully in who owns your business domain. The hosting account, controlling whether the server keeps running at all — covered in who holds the hosting account. The CMS admin login, controlling the ability to edit content and, at the administrator level, to change or delete the site’s own software — covered in who can edit the site after launch and user roles and permissions. DNS management, controlling where the domain actually points — covered in domain name servers and DNS explained.

Why these four are frequently split across different parties

A web designer commonly sets up hosting during a build, under their own account, for convenience. A separate developer may later be given CMS access without ever touching the domain or hosting accounts at all. The domain may have been registered years earlier by yet another party entirely. None of this is unusual, and none of it is automatically a problem while every relationship involved is functioning well — it becomes a problem only when a business needs to act quickly and discovers it does not actually control the account it needs.

Why this matters more than it appears to, day to day

None of these four accounts needs to be touched often. A domain renews once a year, hosting rarely needs direct attention, DNS is set once and mostly left alone. This is exactly why the gap goes unnoticed for so long — a business can operate for years without ever needing to log into any of these accounts directly, right up until a supplier relationship ends, a renewal is missed, or something needs fixing urgently, at which point discovering a lack of access becomes an emergency rather than a five-minute check.

What a proper login and access audit actually looks like

For each of the four accounts, confirm: who is named on it, who has working login credentials, and whether the business itself, rather than only a supplier, could act on it today if it needed to. Where any answer reveals the business does not genuinely control one of the four, that is worth raising directly with whichever party does — most suppliers cooperate readily once asked plainly, because there is rarely a legitimate reason to withhold a client’s own access indefinitely.

Why this is a maintenance question, not only a one-off setup question

Access arrangements drift over time in exactly the way content and software do — a former staff member’s admin login is never revoked, a supplier relationship ends without a formal handover, a password is changed by one party and not communicated to another. Reviewing this list is not a task finished once at launch; it belongs in the same periodic review covered in the annual review a small business site needs.

A fifth item worth adding to the security audit

Beyond the four core accounts, any third-party service holding meaningful control over the site’s operation — an email marketing platform, an analytics account, a payment gateway dashboard — is worth including in the same audit, since losing access to any of these can be nearly as disruptive as losing one of the core four, even though it sits one step removed from the site itself. A compromised or forgotten login on any of them is also a genuine security exposure in its own right — an old, weak password on a secondary account is a route to a data breach or a malware infection just as readily as one on the CMS login itself.

Why this audit is worth doing even for a very small business

A one-person business with no staff and a single supplier might assume this level of formality is unnecessary, but the risk it guards against — a supplier relationship ending badly, an account being lost track of over years — applies regardless of business size, and the audit itself takes only minutes precisely because there is no large team to coordinate.

Storing the passwords and login details somewhere genuinely accessible

A completed audit stored only on the device of the one person who did it is not meaningfully more resilient than no audit at all — keeping a copy somewhere at least one other trusted person can reach, in an emergency, is what actually makes the exercise worth the time spent on it.

The practical value of doing this before it is urgently needed

Every item on this list is trivial to check calmly, in advance, and can become genuinely difficult to resolve under time pressure — during a dispute, after a compromise, or when a key person is suddenly unavailable. Doing the audit now, while nothing is wrong, is the entire value proposition of this page.

Where to go from here

Doing this properly at the point maintenance moves from one provider to another is covered specifically in handing maintenance to a new supplier. And the wider question of what else can end up controlled by a different party once a build finishes — copyright, source files — is set out on who owns your website.

Evidence for this page

This page exists because the demand below was measured, not assumed. The figures are search-market data about the topic — they are not prices.

Entity this page targets
who should hold your website login details
Measured Google volume
no data
Keyword difficulty
no data
Advertiser cost per click
no data
AI assistant volume
no data
Advertiser competition
no data
Measured on
3 August 2026
Search results inspected for intent
No

Source: research/outer-volume-au.json · DataForSEO Google Ads search_volume and Labs bulk_keyword_difficulty, location_code 2036 (Australia), language en · pulled 3 August 2026.

Provenance

Written by Australian Website Design. Published 2026-08-03, last updated 2026-08-03.

Sources

  • Outer-cluster demand measurement (this site) — research/outer-volume-au.json