A One-Page Technology Ownership Register for a Growing Business

A business can have a capable web designer, hosting provider and IT support team and still be unsure who can approve a change or recover access. A one-page technology ownership register makes those answers visible before an urgent problem forces the question.

This is a working document, not a catalogue of every device. Start with the services whose loss would interrupt enquiries, delivery or payment.

Record decisions as well as suppliers

For each important service, note the business owner who can make decisions, the person or supplier who operates it, and the account or contract under which it runs. Those roles may be different. A designer can maintain a website without owning the domain registration; an IT provider can administer Microsoft 365 without deciding who should see a confidential folder.

The UK National Cyber Security Centre’s basic risk method recommends recording ownership of important assets. A small register can turn that principle into a practical handover tool.

The six fields worth capturing first

  1. Service and purpose: for example, the public website, domain name, email, Microsoft 365 tenant, CRM or booking system. State what business process depends on it.
  2. Business decision owner: name a role that can approve spending, access and change. Avoid relying only on a supplier contact.
  3. Delivery contact: record who handles routine changes and how to reach support. If several suppliers are involved, state where a request starts.
  4. Account and billing owner: identify whose account holds the service, who sees renewal notices and who can change payment details. Keep passwords out of the register.
  5. Recovery route: note who can restore access, where backup or export arrangements are documented, and who authorises a restore.
  6. Review trigger: record the next renewal and review date, plus events such as a staff departure, supplier change or major website launch.

Use roles and secure references rather than copying credentials into a spreadsheet that may circulate widely. The register should tell an authorised person where to find the approved recovery procedure, not become a second password store.

Check the handoffs with a short scenario

Ask: “If a customer says our form stopped sending enquiries, who checks it first?” The website builder may inspect the form, the host may check delivery or server logs, and the email administrator may check the receiving mailbox. Record the first contact and escalation path. Repeat the exercise for an expiring domain, an inaccessible Microsoft 365 administrator account and a failed backup restore.

Where work crosses companies, agree the scope before changes begin. The Kilwhiss services directory explains which specialist handles hosting, web design, managed IT, Microsoft 365 security, automation and other work. A multi-supplier project still needs one named business owner to accept the result.

Keep it current without making it a project

Review the page at each renewal or material change. Ask the named owner to confirm that the supplier, administrator and recovery details still work. If an entry is unknown, label it “to verify” and assign someone to resolve it; a guessed answer is worse than an explicit gap.

If you are planning a move between providers, pair this register with our website migration enquiry checklist. To clarify who should own an overlapping technology request, contact Kilwhiss Group with the business outcome you need.

← Back to Insights