For most software projects, check who controls:
⢠The source code repository and its history.
⢠The domain name and DNS settings.
⢠The cloud account, hosting, and production environment.
⢠The database, file storage, and backups.
⢠Third-party services the app relies on, such as email or payments.
⢠The deployment process and the steps for rolling back a release.
The business should own or administer these accounts. Developers can have their own accounts with the access they need. Avoid making a shared personal login the only way to reach production.
Access is only part of it
Ask for short notes on how to run the app, deploy a change, restore data, and find the logs when something fails. Record which services cost money and who receives renewal or outage notices. Store credentials in a company-controlled password manager or secret store, not in the code repository or a handover document.
The notes do not need to explain every line of code. They should help another capable developer understand how source code becomes a running service and where to look when that stops working.
Before a project ends, sign in to the accounts. Check that the business can access the code, domain, hosting, and data. Make sure a recent backup exists and that someone has tested restoring it.
The developer can still manage the technical work. The business should not be locked out of its own software.