Agency operations guide
Give a Departing Client an SEO Handover Pack They Can Use
Hand over account ownership, the current SEO configuration, custom decisions, and pending work, keep credentials out of the document, and test that the next operator can run the site.
On this page
A useful SEO handover pack has four parts: a register of accounts and who now owns each one, a record of the current SEO configuration, a log of the custom decisions and pending work behind it, and a short set of checks the next operator runs to prove they can operate the site. Credentials are transferred separately, and your own access is removed at the end.
The test of the pack is simple: the client should be able to hire someone else and have that person working without calling you.
Keep credentials out of the pack
The pack is a document the client will forward, store, and share. Do not put passwords, API keys, license keys, or Application Passwords in it. Transfer ownership instead, so the client holds each account in their own name:
- WordPress. Confirm the client has their own administrator account. Then remove or downgrade your team’s accounts. WordPress Application Passwords can be revoked one at a time from the user’s profile without changing the main password. WordPress’s Application Passwords documentation, checked September 27, 2026. Revoke each one your team or tools created.
- Search Console. Make sure a client-controlled account is a verified owner of the property, with its own verification token, before you leave it. A delegated owner you added is not enough: Google says that if all verified owners are removed, the remaining users and delegated owners lose access after a grace period. Google also says removing a verified owner does not delete their verification tokens, and while those tokens stay in place the removed owner can re-verify. Google’s help on managing owners, users, and permissions, checked September 27, 2026. Delete your tokens after the client’s verified owner is in place.
- Hosting, DNS, domain, analytics. Move each to the client’s account, or confirm they already hold it, and record the date.
- Paid licenses. Record who holds each license and what happens when you stop paying. This needs its own section; see below.
If the client needs a secret from you, send it through a password manager share or have them reset it, and note in the pack that it was handled, not what it was.
List the records that transfer
Most of the SEO state is already in the site. The pack tells the next operator where to find it and which pieces are outside WordPress.
| Record | Where it lives | Handover format |
|---|---|---|
| Posts, pages, terms, custom fields | The WordPress database | A fresh database backup, plus WordPress’s export if the client wants a portable copy |
| SEO plugin settings | The plugin’s options in the database | Screenshots or a written list of templates, defaults, and identity settings |
| Per-post SEO values | Post and term meta, or the plugin’s own tables | Covered by the database backup |
| Redirect rules | The plugin’s table, the host, or the CDN | A spreadsheet of source, target, and status, per layer |
| Verification codes | SEO plugin setting, DNS, or HTML file | The method used for each service |
| Sitemap address | Served by the SEO plugin or WordPress | The URL and where it is submitted |
WordPress’s export file contains posts, pages, custom post types, comments, custom fields, categories, tags, custom taxonomies, and users. WordPress’s Tools Export documentation, checked September 27, 2026. Plugin settings and plugin tables are not in that list, so the export is not a substitute for a database backup.
If the site runs WP Visibility, moving to another SEO plugin lists the settings that do not travel to another plugin (separator, templates, verification codes, social defaults, identity, crawler policy) and shows how to pull the redirect rules through the REST route. Copy that list into the pack rather than paraphrasing it. Note too that a verification code saved in the plugin prints only while the plugin is active; if the next operator changes plugins, they need to re-enter it or verify another way.
Document custom decisions and pending work
Settings show what the site does. They do not show why. The next operator will otherwise undo deliberate choices because they look like errors.
Write a decision log with one row per non-obvious choice:
| Decision | Where it is set | Reason | Date | Who approved |
|---|---|---|---|---|
| “Clearance” category noindexed | Category SEO settings | Thin, changing inventory | ||
| Article canonical points to partner site | Post SEO settings | Syndicated from the partner’s original | ||
| Old /services/lawn-care/ redirects to /services/ | Redirects | Service discontinued |
These rows are illustrative, for a fictional site, garden.example. Replace them with the real ones.
Then list pending work honestly: tasks started and not finished, issues found and not fixed, and anything the client declined. A half-finished redirect map is more dangerous when nobody knows it is half finished.
Document the SEO plugin license and support arrangement
State in the pack who holds each premium plugin license, who pays for it, who receives support, and what the vendor says happens at expiry. Do not write that a license “transfers” unless the vendor has confirmed it for this case.
For WP Visibility, the facts to record are these. One key covers unlimited sites, and the plugin keeps working with every feature when a key stops validating; only updates and support stop, per the license terms. If your agency’s key is on the client’s site, you can remove it with wp visibility license deactivate, which removes the key while the plugin keeps working. If you provisioned the key as the WPVISIBILITY_LICENSE constant in wp-config.php, delete that line too; the command does not touch it. The client can then enter a key from their own account. Neither the pricing page nor the terms describe moving a license from one account to another, so confirm with support before promising the client anything beyond that.
Deciding who owns the plugin license covers setting this up at the start of an engagement, which makes this section of the pack much shorter.
Verify the recipient can operate the site
Do not end the engagement on “sent.” Ask the client or their new operator to run these checks while you are still available, and record the result of each:
- Log in to WordPress with their own administrator account.
- Open Search Console as an owner and find the Performance report.
- Find the SEO plugin’s settings and the redirect rules.
- View the source of three URLs from your baseline and confirm the title, description, canonical, and robots tag match the pack.
- Load the sitemap address and confirm it is the one submitted in Search Console.
- Confirm who will apply plugin updates and whether a license is active for them.
- Restore test: confirm they know where the latest backup is and who can restore it.
When every check passes, remove your remaining access and tell the client, in writing, the date you did it.
Handover checklist
- No secrets in the document.
- Client owns WordPress, Search Console, hosting, DNS, domain, and analytics accounts.
- Your team’s accounts, Application Passwords, and verification tokens are removed.
- Configuration record, redirect spreadsheet, and database backup are delivered.
- Decision log and pending work list are complete.
- License holder, payer, and expiry behavior are written down for each paid plugin.
- The recipient has passed the operating checks.
