Start with a client map
For each client write one row: the domain and its registrar, the DNS provider, the host, the email provider, the site platform and who holds each login. The map answers most questions before a fault happens, and it is the single most useful thing to have when one does. It must contain no passwords: it names the account and the person, and the credentials live in your own password manager.
- Account names and holders, not secrets.
- Renewal dates for the domain, the host and the certificate.
- Which plugins and tools send email as the client's domain.
Authority stays with the client
Domains, hosting and mailboxes belong to your clients, so changes that matter, such as DNS records, host settings and mailbox moves, need the client's approval or yours under a written arrangement. A repair we scope is for one client's incident, with that client's account holder making or approving the live change. We do not take over a client's login, work under a personal account or contact the client without your agreement.
- Who is the buyer: you or the client, written down before scoping.
- Who approves each live change.
- Who holds the final login after the work.
Scope one incident, or one move, at a time
A bounded repair fits a single named fault: a bare-domain address that does not open, mail that does not arrive, a redirect loop or a cache showing old pages on a site behind Cloudflare, a hacked WordPress site that has an older backup. A move or a baseline project fits a client who needs several of these done in the right order. Standing services fit clients who need steady upkeep. Repairs and moves are published test prices, not tested with buyers, paid after the agreed checks pass and the client or you sign off, or on the schedule in a written proposal for the larger projects; standing services are billed monthly under written terms.
Evidence you can pass to the client
Each job ends with its own evidence: before and after records, test tables, headers and a list of what is left open. You can hand these to the client to inspect. They state limits plainly, for example that a restore does not prove a site is free of malware, that no cut-over can promise zero delay for every sender, and that hardening reduces risk and does not remove it. A shared cPanel host can also leave a client exposed to a compromised neighbour, which only the host can address.
Sources and limits
- WordPress: Hardening WordPress Checked 2026-10-11.
- Hardening is described as risk reduction, not risk elimination, and shared hosting can leave a site exposed to a compromised neighbour.
- cPanel: Backup Wizard Checked 2026-10-11.
- A full cPanel backup cannot be automatically restored through cPanel; a host-level tool or the provider is needed.