Build an access register

List every system required for the work, the minimum role, account owner, approver, date granted, expiration, and removal status. Use agency- or client-controlled named accounts rather than sending passwords through email or chat.

  • Start with read-only audit access.
  • Separate analytics, search, CMS, hosting, DNS, and billing roles.
  • Use multifactor authentication and approved credential storage.
  • Review access at project milestones and offboarding.

Assign responsibility for each stage

For every deliverable, identify who provides inputs, performs the work, reviews technical accuracy, approves client communication, deploys changes, and verifies the result. One person should be accountable even when several people contribute.

  • Use a simple RACI or owner matrix.
  • Keep strategic and deployment approval explicit.
  • Define who can contact the client.
  • Name the escalation owner for security and production incidents.

Protect the client relationship

Agree on branding, confidentiality, meeting participation, response expectations, and how disagreements are presented. White-label work should not require the provider to pretend to be an employee or make claims about credentials that are untrue.

  • Use approved email, report, and meeting conventions.
  • Disclose subcontracting where contracts require it.
  • Keep sensitive client information out of reusable examples.
  • Route promises and scope changes through the accountable agency owner.

Close the loop after implementation

Every material change should have a ticket or record showing the request, approver, implementation, timestamp, validation, and rollback status. At offboarding, return source files, remove access, rotate shared secrets, and document open risks.

  • Keep before-and-after evidence.
  • Verify production rather than assuming deployment succeeded.
  • Review logs and monitoring after high-risk changes.
  • Provide a concise transition packet when ownership changes.

Official references

FAQ

Should an SEO auditor receive administrator access?

Usually not at the audit stage. Begin with the minimum read access needed and grant higher privileges only for approved implementation tasks.

Who should own Search Console and analytics accounts?

The client should normally retain durable ownership, with named agency and provider users granted appropriate roles.

What happens to access after a project?

Remove accounts and tokens that are no longer needed, rotate shared credentials, transfer agreed files, and document remaining ownership and risks.

Keep the Next Step Small

Use the related guides to confirm what the page needs. Ask for support only when the change reaches code, templates, or server settings you do not want to guess at.

Contact Your SEO Wizard