Keep the business running first
If a developer becomes unavailable, preserve service and evidence before making broad changes. Inventory every company-owned technical asset and confirm authorized administrative access to the domain, DNS, source repository, hosting, databases, backups, CI/CD, monitoring, and critical vendors.
This process applies only to systems and data your organization owns or is authorized to administer. If ownership is disputed, preserve contracts, invoices, and written records and obtain appropriate legal guidance. Do not attempt to bypass an account, device, or service you are not authorized to access.
Record whether the website, application, payments, email, scheduled jobs, and integrations are operating. Capture current account lists, renewal dates, certificate expirations, recent incidents, and the commit deployed to production. Avoid impulsive credential rotation until you know which keys and tokens keep production alive.
Inventory technical ownership
Start with identity: company email administration, password management, single sign-on, multi-factor recovery, documentation, support inboxes, and a list of employees, contractors, service accounts, and outside collaborators.
Then secure the public edge: registrar ownership, domain billing, DNS records, CDN, firewall, certificates, redirects, analytics, tag management, Search Console, and business listings. Preserve every repository, branch, release, issue, deploy key, webhook, installed app, CI workflow, build variable, artifact store, and signing account.
Map the operating system behind the product: cloud accounts, servers, storage, queues, scheduled jobs, production and nonproduction databases, migrations, backups, logs, uptime monitoring, payments, email, CRM, identity, file storage, licenses, and private dependencies. Every critical service needs a named company owner.
Create a handoff another builder can use
Move code into a company-controlled organization through the platform’s supported transfer process. Maintain more than one trusted owner, grant least-privilege access, and review deploy keys and integrations separately from human users. Removing a person does not necessarily remove access held through another key.
Rotate credentials in dependency order: map where each secret is used, create a company-controlled replacement, test it outside production when possible, deploy it, verify the service, then revoke the old credential. Record each change and its rollback path.
A usable handoff includes an architecture map, account inventory, setup instructions, environments, build and test steps, deployment and rollback, database recovery, known defects, open risks, renewal dates, and named business owners. The handoff is complete when another authorized person can operate the system safely.
No single developer should be the only path to a company’s domain, code, data, or production system.
Creative Minds Studios
Start a project