Digital Marketing

Digital Asset Management Plan: How to Own Your Domains, Accounts and Media for a Sustainable Web Strategy

Talha AslanTalha Aslan 17 min read 3 views

What is digital asset management, and why does a small business need a plan for it?

Digital asset management is the practice of recording who owns, who can access and when to renew every digital piece of your business: domains, hosting, ad and analytics accounts, social profiles and the media library. Without a plan, those assets quietly end up in an employee or agency account.

I have worked in digital marketing since 2012. In that time, most of the expensive mistakes I have seen had nothing to do with ad copy or design. Instead, they came from ownership. For example, a company leaves its agency and loses five years of Google Ads history, because someone opened the account with the agency email. This guide shows you how to build a digital asset management plan step by step.

Which assets belong in your digital asset inventory?

First, know what you own. You cannot fix permissions or set up renewals without a list. That is why I fill in this inventory with every new client in our first meeting:

  • Domains: the main domain, typo variants and old campaign domains.
  • Hosting and servers: the hosting panel, DNS provider, SSL certificate and CDN account.
  • Business email: the Google Workspace or Microsoft 365 admin account.
  • Measurement and ads: Google Ads, GA4, Google Tag Manager, Search Console and the Meta business portfolio.
  • Social profiles and the page admin roles linked to them.
  • Media library: logo files, photos, videos and the brand guidelines.
  • Software and licences: theme, plugin, font and stock image licences.

The list looks long. However, each line needs only four facts: the asset name, the owner, the people with access and the expiry date. As a result, you see the whole picture in one table.

Also ask your team while you build the list. Marketing, sales and HR often open accounts you never heard of. For instance, an old event microsite or a forgotten Pinterest profile may still carry your brand name online.

Who should legally own your domain name?

Your domain is the foundation of every other asset. In practice, your website, your email and most verifications depend on it. Still, in many businesses the domain sits inside the registrar account of whoever built the site. In that case, the registrant is often that person too.

In practice, the right setup is simple. Open the registrar account in the company name, with a shared company email address. The registrant field should show your company. If an agency or developer needs access, give them a sub user or temporary rights, not the account itself. In addition, keep the transfer lock on and store the authorisation (EPP) code where only a company director can reach it.

To check your current setup, run a DNS lookup and see which name servers your domain uses. If you spot a provider you do not recognise, that is the first question for your inventory.

What happens when a domain name expires?

An expired domain does not pass to someone else at once. Still, your website and email may stop working. The ICANN Expired Registration Recovery Policy requires registrars of generic domains to send reminders roughly one month and one week before expiry. They must also send one more notice within five days after expiry.

Under the same policy, registries must offer a 30 day redemption period after deletion. Restoring a domain in that window usually costs more than a normal renewal. Worse, if the reminders go to a former employee whose mailbox no longer exists, nobody reads them. Therefore the contact email on your registrar account is the single most critical line in any digital asset management plan.

Country code domains can follow different rules. So check the current terms of your own registry as well.

How should you organise hosting and DNS access?

After domains, hosting causes the most trouble. For example, here is a pattern I see often. The site lives on a reseller account that belongs to the agency. The agency pays the host, and you pay the agency a monthly fee. When the relationship ends, the agency still holds the files and the database.

So have the host invoice your company directly. The agency or developer should log in with their own user as an extra admin. It also helps to separate DNS from hosting. That way, your email records (MX, SPF, DKIM) stay in place when you move servers.

I explain why email and domain belong together in my business email guide. One note here: the DNS panel login belongs in the inventory too.

Do you really own your Google Ads account?

In Google Ads, ownership is also a little indirect. Instead, every user has an access level. According to Google's access levels page, the options are Admin, Standard, Read only, Billing and Email only. Admin users can add and remove other users.

In practice, my rule is this. At least two people from your company hold Admin access with company email addresses. The agency then connects through its own manager (MCC) account. When the contract ends, you simply unlink the manager account. The account, its history and its conversion settings stay with you.

Also check linked accounts such as Merchant Center, YouTube and your Business Profile. If the agency created those links from its side, they may break during a handover. So list each link as a separate row in your inventory.

In my Google Ads management work, I always open the account in the client name. It is the first clause of the contract.

How should you split GA4 and Tag Manager permissions?

GA4 lets you grant roles at account and property level. Google's GA4 roles guide lists Administrator, Editor, Marketer, Analyst and Viewer. Only Administrators can manage users.

I suggest this split:

  • Two people from your company hold Administrator at account level.
  • The agency holds Editor at property level, without user management.
  • Managers who only read reports hold Viewer or Analyst.

The same logic also applies to Google Tag Manager. The company account owns the container, and the agency joins with publish rights. In addition, record your GA4 data retention setting and any BigQuery link. Teams often forget these during an agency change, and old data then disappears without warning.

Who should verify your Search Console property?

Search Console has three user types: owner, full user and restricted user. Google's permissions documentation describes owners as the users who can add and remove others.

That said, there is a common trap here. When the agency verifies through a DNS record, ownership sits with the agency Google account. You still see the property, but only as a guest user. Instead, verify the domain property with the company Google account through a DNS TXT record. Then add the agency as a full user.

I cover the tool itself in my Search Console guide. This article focuses only on ownership.

How do you keep ownership of social media accounts?

Above all, social media is the messiest asset group. For instance, an Instagram account may depend on an intern phone number. A LinkedIn page may belong to a former sales manager. A YouTube channel may sit on a personal Gmail address.

On Meta, move your accounts into a business portfolio and make two company people its admins. Add the agency as a partner, never as the owner. On LinkedIn, set at least two super admins. For YouTube, connect the channel to a brand account and add more than one owner.

Also turn on two step verification on every platform, and use a company phone line for recovery. A recovery number on a personal phone effectively locks the account once that person leaves.

How do you keep an access inventory?

An access inventory answers one question: who can get into what? Specifically, you do not need special software. A well kept table works fine. What matters is that the table lives in one place and gets updated after every change.

The table below summarises the simple template I use with clients:

AssetOwner accountOther usersRoleExpiry or review
DomainCompany registrar accountDirector, IT leadAccount ownerRenewal date
HostingCompany billed accountDeveloperExtra userContract end
Google AdsCompany emailAgency MCCStandardQuarterly review
GA4Company Google accountAgencyEditorQuarterly review
Search ConsoleOwner: companyAgencyFull userQuarterly review
Meta portfolioCompany adminsAgency partnerAsset accessQuarterly review

However, never write passwords into this table. Passwords belong in a password manager. The table only shows who holds which role.

Where should passwords and two step codes live?

Password security deserves its own article. For digital asset management, though, two rules matter most. First, never send shared passwords by email or chat. Second, never leave two step codes on a single phone.

A business password manager lets you share vaults with the team. When someone leaves, you remove their access in one step. Keep backup codes on paper in a safe, or in a secure digital vault. When you open a new account, a password generator gives you a strong password in seconds.

For admin accounts, also consider a hardware security key. It costs little compared with a hijacked account.

Finally, keep shared logins to a minimum. Wherever a platform allows it, give each person their own user. That way, the logs show who did what. You can also close one person's access without changing a shared password for everyone.

How do you build a renewal calendar?

A renewal calendar turns inventory dates into reminders. I build it in three layers:

  1. Auto renew: on for domains, hosting and SSL, charged to a company card.
  2. Calendar reminders: shared events 60 and 15 days before expiry.
  3. Named owner: one person per line, plus a deputy for holidays.

Auto renew alone is not enough, because cards expire and limits run out. For example, one client lost an SSL certificate while the company card was being replaced. The site showed a "not secure" warning for two days. To count the days left quickly, use the date calculator.

Then review the whole calendar once a year. Dropping unused domains, or turning them into redirects, cuts waste. That said, check whether an old domain still gets links or traffic before you let it go. Otherwise someone else may register it and catch your former visitors.

How do you organise a media library with DAM?

DAM software keeps logos, photos, videos and design files in a tagged, versioned library. For large brands, a dedicated DAM product makes sense. For small and mid sized businesses, a company owned cloud drive with a disciplined folder structure often does the job.

In practice, the real problem is rarely the software. It is where the files sit. For example, the vector logo lives on the designer laptop. Product photos sit in the photographer download link. Ad videos stay on the agency server. When the agency changes, you pay to produce them again.

So write it into every contract: after each delivery, source files (AI, PSD, Figma, raw video) go into the company library. In my brand identity projects, source files are always part of the handover package.

What folder and naming structure works best?

Put simply, a good library lets you find any file in thirty seconds. Here is the simple structure I recommend:

  • 01-Brand: logo, colour codes, fonts and brand guidelines.
  • 02-Photo: subfolders by shoot date.
  • 03-Video: raw and edited versions kept apart.
  • 04-Ads: by platform and campaign name.
  • 05-Licences: font, stock image and music licence documents.

Put the date, topic and version into file names, for instance "2025-03-product-catalogue-v2". Also keep the licence folder up to date. An image without a licence record can lead to a copyright claim later. Before uploading images to your website, the image resizer speeds things up.

Why does business email sit at the centre of everything?

Above all, almost every digital asset hangs on an email address. So password resets, invoices and security alerts all go there. For that reason, I recommend opening accounts with role addresses, not personal ones.

A role address such as "ads@" or "digital@" stays with the company when people change. If you set it up as a group or shared mailbox, several people see each notice. Consequently, a renewal warning never gets lost in one inbox.

The Google Workspace or Microsoft 365 admin account is an asset in its own right. Lose it, and you lose control of all company email. So the admin account also needs two people, strong two step verification and printed backup codes. Moreover, never use the admin account for daily email.

Who should hold the website source code and backups?

However, even if you own the domain and hosting, the source code may live elsewhere. For instance, custom themes, plugins and software projects often sit in the developer repository. If you cannot reach that repository after the contract ends, even small changes become hard.

Therefore keep the repository in a company organisation account and add the developer as a contributor. Also write down your backup policy. Who takes the backup? Where does it go? How many days back can you restore? A backup that lives only on the same server is useless when that server fails.

My practical advice: keep at least one backup with a provider other than your host. Then run a restore test once a year. An untested backup tends to surprise you at the worst moment.

How does digital asset management protect you during an agency switch?

An agency switch is the real test of a digital asset management plan. With a plan, the handover takes a few days. Without one, it can turn into weeks of negotiation. My handover checklist follows this order:

  1. Update the inventory and move any missing ownership to the company while the agency is still working with you.
  2. Ask for source files, reports and an export of the campaign structure.
  3. Add the new agency and let both teams overlap for a few days.
  4. Remove the old agency and close its lines in the access table.
  5. Rotate passwords and API keys.

Above all, the order matters. Remove the old agency right after the handover, not after the relationship turns sour. Otherwise a setting change, even an innocent one, can slip by unnoticed.

Which assets are at risk during a website migration?

Also, an agency change often comes with a website redesign. In that case the risk doubles, because both ownership and SEO value are at stake. The old site backup, the URL list and the redirect map are digital assets too.

Before the move, save a full backup of the old site in the company library. Once the old server shuts down, you may have no way back to that data. Afterwards, test your redirects with a redirect checker.

I collected the technical side in my website migration checklist. The message here is simpler. Know what you own before you move, or you will never know what you lost.

In addition, prepare a launch day owner list. Who changes DNS? Next, who files the change of address in Search Console? Who checks the GA4 tag? That list belongs in the inventory as well.

Which ownership clauses belong in your agency contract?

Contract language also matters as much as technical setup. I do not give legal advice. Still, from my field experience, I always want to see these clauses in an agency or freelancer agreement:

  • Ad, analytics and social accounts open in the client name.
  • The client receives the source files of every delivered design.
  • Domain and hosting register in the client name.
  • Access transfers within a fixed period after the contract ends.
  • The contract states whose name the stock image and font licences use.

Review these clauses with a lawyer before you sign. The goal is to remove doubt early, even in friendly relationships.

It also helps to attach a short annex: a list of every account the project will open, with its owner. When the work ends, that annex becomes the handover checklist. Both sides then tick the same list instead of arguing.

How does digital asset management support a sustainable web strategy?

A sustainable web strategy means your site can keep growing for years. SEO equity, the learning history of your ad account and your analytics data all gain value over time. However, that value is yours only while the assets stay with you.

For example, five years of GA4 and Search Console history show you seasonal trends. If that data disappears in an agency switch, strategy starts from zero. Likewise, the conversion history in Google Ads helps smart bidding learn faster.

Here is an example calculation. An online shop with four campaign seasons a year reuses each season's results in the next plan. If three years of data sit in one account, you quickly see which month works for which product. If the account resets with every new agency, you pay the same testing cost every year.

So digital asset management is not an IT chore. It is the base of your marketing strategy. Keeping your content fresh matters, and so does owning the assets underneath it.

Who inside the company should own the plan?

One person should own the plan, but knowledge should never sit with one person only. In small businesses, the founder or managing director usually takes the role. In mid sized firms, the IT or marketing lead can own it.

I recommend the "one owner, one deputy" rule. The owner updates the inventory and the calendar. The deputy can access everything but stays out of daily work. As a result, the process keeps running when the owner is on leave or moves on.

Still, keep the agency out of this role. The agency can add to the inventory and flag gaps. Still, the plan owner should always be someone inside the company. A good agency prefers this anyway, because it makes responsibilities clear.

Once a year, ask the plan owner for a short review. Leadership then sees on one page which assets carry risk, which renewals are close and which accounts still sit outside.

How often should you audit access rights?

In practice, access lists decay on their own. Employees leave, and freelancers join for one task and stay forever. That is why you need a regular audit.

My starting point, based on field experience and not a guarantee: every three months for accounts with admin rights, every six months for the rest. In each audit, ask:

  • Is this person still with the company or the project?
  • Does this role give more power than the job needs?
  • Are the recovery email and phone up to date?

Also add a "digital access" step to your offboarding process. When HR confirms a departure, the plan owner removes access that same day. That closes the gap between audits. It also prevents awkward moments, such as a former employee pausing a campaign or posting by mistake.

Where should you start in the first 30 days?

First, do not try to fix everything at once. Follow this order and you will close the main risks within a month. Feel free to stretch the timeline, but keep the sequence:

  1. Week 1: create the inventory table and list every asset you know.
  2. Second week: confirm who owns the domain and hosting, then update the contact email.
  3. Week 3: sort out Google Ads, GA4, Search Console and Meta permissions.
  4. Final week: set up the media library, the renewal calendar and the audit dates.

Still, some lines will stay incomplete after the first pass. That is normal. What matters is that the inventory starts life as a living document. Updating it whenever someone opens an account or leaves soon becomes a habit.

Does it make sense to get outside help?

Most businesses can build the inventory and fix permissions themselves. You need no special technical skill, only a clear table and a few focused hours. On the other hand, help saves time on technical steps such as an account transfer, ad history stuck in an agency account or a domain transfer.

I usually handle this as the first step of a new SEO consulting or web design project. Since I work without middlemen, accounts open in the client name from day one, and handover problems never start.

Whichever route you choose, the test stays the same. If your agency or developer vanished today, could you reach your site, your ads and your data on your own tomorrow morning? A yes means your plan works. If not, the 30 day order above is a good place to begin.

In short, what does sustainable digital asset management need?

In short, three things: one inventory, clear ownership and a steady calendar. Domain and hosting belong to the company. In ad and analytics accounts, the company holds Admin and the agency holds limited access. Media files live in the company library.

In other words, none of this is complicated. Yet delay makes it expensive. An agency change, a departing employee or a forgotten renewal date can put years of digital value at risk within a week.

If you have questions, write to me through the contact page. We can review your current setup together and set your priorities.

Frequently Asked Questions

Is digital asset management only for large companies?
No, small businesses need it too. In fact, the risk is often higher in small firms, because every account tends to hang on one person or one agency email. A simple inventory table and a two admin permission setup cut most of that risk in a few hours of work.
What can we do if the agency refuses to hand over the Google Ads account?
First, request the handover in writing and point to the ownership clauses in your contract. If the billing sits in your name, you can also contact Google support. If a transfer proves impossible, you may need a new account. That is why opening the account in your own name from the start is the safest route.
How do I find out who owns my domain name?
Check the registrant details in your registrar panel. If you cannot log in, a WHOIS or RDAP lookup may show some details, although privacy services often hide them. In that case, ask whoever built the site for the registrar login and move the account to a company email address.
Do I have to buy DAM software?
No. For libraries of a few hundred files, a company owned cloud drive with a consistent folder structure usually works well. Consider a dedicated DAM tool once your team grows, once you produce content for many channels, or once tracking versions and licences becomes hard to manage by hand.
How often should I audit access rights?
My starting point, based on field experience and not a guarantee, is every three months for admin level accounts and every six months for the rest. On top of that, removing access on the same day an employee or agency leaves makes a bigger difference than any scheduled audit.
#digital asset management#domain ownership#Google Ads#GA4#Search Console#agency handover
Share:
Talha Aslan
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

No middlemen, no layers: you talk directly to the expert doing the work. The first consultation is free, I listen to your goal and come back with a clear roadmap.

WhatsApp Call Now