A proper handover is more than receiving a ZIP file. The business should have direct administrative control of the accounts and a clear map of the systems the project depends on.
The handover should transfer control, not just files
A website can be copied while the business remains locked out of the domain, hosting, DNS or third-party services. A useful handover gives the business enough access and information to operate the technology without depending on the departing developer.
1. Domain and DNS
Get registrar access, renewal information, nameserver details and DNS administration. Confirm which account owns the domain and where the DNS zone is managed.
2. Hosting and server access
Collect hosting account access, server or control-panel details, PHP/runtime information, databases, scheduled jobs, SSL setup and backup information. Do not assume the website files alone are sufficient.
3. Website and source code
Get CMS administrator access where applicable, source code or repository access, deployment instructions and a current backup. If there are build steps or environment variables, document them securely rather than placing secrets in public files.
4. Business email and third-party services
List email administration, payment services, analytics, forms, CAPTCHA, CDN, maps, marketing tools and integrations. For every dependency, record who owns the account and how it is renewed or billed.
5. Documentation and known problems
A short handover document should explain the architecture, important URLs, current issues, backup process, deployment method and any unfinished work. This can save more time than another hour of coding.
The final test
Before the developer leaves, have the business owner or new technical owner sign in to the critical accounts and verify that the information is usable. A password sent once is not the same thing as a completed handover.