Who should own cloud resources, domains, and third-party service accounts?
Core accounts should be registered to the client's actual operating entity, with at least two internal administrators controlling recovery. Wavesteam collaborates through named, least-privilege identities and never shares a super-administrator password. Any temporary registration or management arrangement needs a written migration date, cost, and exit procedure.
Placing an account under a developer or outsourcing company can reduce verification work during development, but it makes domain renewal, payment settlement, app release, data migration, and supplier replacement depend on that party. Control is not simply who knows the current password. The verified entity, registrant, contracting and invoice entity, recovery email, and phone must remain sustainable within the client organization. A single employee's account is also fragile when that person leaves or loses the number.
When agreeing deliverables, handover, and ownership boundaries, also compare Who owns the data and intellectual property in a custom software project?; the linked guidance adds context that should be considered in the same decision.
Recommended ownership by asset
| Asset | Registration or contracting entity | Daily access | Acceptance evidence |
|---|---|---|---|
| Cloud compute, database, object storage, CDN | Client enterprise account | Wavesteam IAM identity or role | Client controls billing, root identity, backups, logs, and support |
| Domain, DNS, certificate | Client entity with a durable company contact | Delegated DNS or certificate role | Registrant, renewal, transfer lock, recovery, expiry alerts |
| WeChat property and app stores | Client entity that operates the service and holds qualifications | Developer or collaborator role | Verification, administrators, signing credentials, submission and release rights |
| Payment, SMS, maps, notifications | Client entity bearing business and settlement responsibility | Scoped API and operational roles | Contract, balance, quotas, callbacks, rotation and closure |
| Repository, monitoring, ticketing | Client organization workspace | Members grouped by project | Ownership, history, alert recipients, offboarding process |
Domain control is more than login access. ICANN registrant resources explain that registrants manage domains through registrars and carry associated rights and responsibilities. Use accurate, maintainable registration information and a controlled corporate mailbox. Record registrar, expiry, payment method, transfer lock, and authorization-code process, and send renewal alerts to at least two people. Technical teams may change DNS without owning the domain or its recovery route.
Cloud users should not share a root identity. Client administrators protect the highest privilege with MFA, while development, deployment, finance, and audit use separate identities. Wavesteam receives only the roles needed for agreed work; production-data reading, billing, and resource deletion receive separate approval. NIST SP 800-207 supports continual identity verification, limited privileges, and audited actions rather than implicit trust after entering a company account.
Payment, mini-program, and app-store accounts carry qualifications and business responsibility and should not remain under Wavesteam or an individual for convenience. API secrets belong in a client-controlled secret environment and are rotated at handover. Signing certificates, private keys, and recovery codes need encrypted storage and dual-person access, not chat or source files. Offboarding disables identities, revokes tokens, removes sessions, and reviews recent activity.
If the client entity does not yet exist, an isolated test account or short-term Wavesteam management of non-production resources may support a proof of concept. The contract must list temporary resources, fees, target verification date, portability of domains and historical data, and overdue treatment. Do not put production personal information, formal app release, or payment merchants into a temporary identity that cannot migrate. Confirm whether each platform supports entity changes before relying on them.
The account register should include platform, account ID, verified entity, internal owner, second administrator, billing, renewal, recovery, MFA custody, Wavesteam access, data location, rotation date, and exit steps. Acceptance asks a client administrator to sign in, add and revoke a collaborator, inspect billing and logs, restore a backup, and exercise DNS or key rotation—not merely view screenshots.
Wavesteam's position is simple: client-owned assets, role-based access, auditable actions, and a practical exit. The Transparent Delivery Standard provides the related delivery principles.