The project's digital assets must be owned by the beneficiary company.

Repositories, servers, and service accounts should be created for the client, with the delivery team receiving only the access it needs.

Omar Alalwi Article

Before a project begins, the client should create its accounts for code repositories, servers, and third-party services, keeping the digital assets under its ownership. The client grants the developer or agency the required permissions instead of sharing the primary account, unless the contract clearly specifies another arrangement.

Clients may not know these details, which is where professional responsibility matters. The delivery team should explain how to create and secure the accounts and help configure access. Paying for the work should not leave the project's essential assets owned by the vendor without an explicit agreement.

The vendor's rights can be protected by dividing work and payments into milestones tied to clear deliverables, with each phase, handover, and support obligation documented. A fair principle is that completed payment corresponds to completed, delivered work, so neither party can hold the project hostage during a dispute.

These are general operating principles; qualified professionals should adapt the contract to the applicable law and project.

Share your perspective

I’d be glad to hear your perspective. Leave a comment on the original article on social media.

Related articles

Application & Infrastructure Security ·

How Cloudflare Uses Lava Lamps in Encryption

Cloudflare uses the movement of lava lamps as an additional entropy source for secure random-number generation in cryptographic systems.

Read article

Application & Infrastructure Security ·

Beware of the disreputable server

Reliable email delivery depends on more than a running server: IP reputation, authentication, and sending policies determine whether messages reach the inbox.

Read article