You’re stuck with an agency that takes weeks to reply, charges you for changes you don’t understand, and somehow holds the keys to a website you paid for. You’re not the first.
Most Australian SMBs we talk to have lived through some version of this. The good news: getting out is mechanical. There’s a sequence. Skip a step and you can lose your search rankings, your orders, or your domain. Follow it and you can switch developers in two weeks with nothing customer-facing affected.
Here’s the safe way.
First — admit what’s actually happening
Before the logistics, name the problem honestly. You’re probably in one of three situations:
- The agency built it, then disappeared. They were great during the build. Now you can’t reach them. Tickets bounce. The site has a small bug for six weeks.
- The agency is still there, but the relationship is broken. They reply, but every change takes too long, costs too much, or breaks something else. You’ve started avoiding asking for things.
- The agency is actively obstructive. They own the domain, the hosting, the DNS, the design files, or the source code. You’ve asked for access and it hasn’t materialised.
The third one is the only one that legally counts as “hostage.” The first two are bad service, not bad faith. The exit plan differs.
If you’re in situation 3 — agency actively refusing to hand over assets you paid for — you have a stronger position than you think. Australian consumer law and the standard “work for hire” assumption mean almost everything they built for you is yours. The agency doesn’t actually have a legal lever on most of those assets. They have a practical lever — your willingness to keep them happy. Once you’ve decided to leave, that lever is gone.
The five things you need to recover
Before you can switch developers, take inventory of what they hold. There are five categories. You probably control some, the agency holds others.
1. Your domain name
Who should own it: you, in an account in your name.
Where it usually lives: a registrar like Crazy Domains, GoDaddy, or VentraIP — sometimes the agency’s account, sometimes yours. Check the WHOIS record on whois.com.au — if the registrant org is the agency’s name, that’s the problem.
Why it matters: if they own the domain, they can technically point it anywhere. They probably won’t — that would be career-ending — but until it’s in your name, they have leverage.
How to fix: request a domain transfer. They have to send you the EPP code. Open an account at a registrar in your name (Crazy Domains is fine), initiate the transfer, paste the code. Process takes 7–14 days. Do this first.
2. Your hosting
Where it usually lives: SiteGround, WP Engine, Kinsta, Cloudways, or the agency’s own server.
Why it matters: if it’s on their server, they can disable it. If it’s on a shared account that hosts other clients of theirs, you can’t safely run analytics, security scans, or anything that touches the server config.
How to fix: you need a hosting account in your name. Two options:
- Stay on the existing host, change ownership: ask the agency to transfer the account or open a new account on the same host and have them migrate the site. Most reputable hosts will help mediate this.
- Move to a new host entirely: if the relationship is broken, just move. A WordPress site can be migrated to a new host in 2–4 hours with a tool like WP Migrate DB Pro or All-in-One WP Migration. Crucially: do this BEFORE you tell the agency you’re leaving. If you have a recent backup of your site, you can move at any time.
3. Your CMS admin access
Where it usually lives: the WordPress / Webflow / Shopify admin panel.
Why it matters: if you don’t have an admin login in your name, you can’t add new users (like the new developer), can’t see what plugins are installed, can’t recover the site if the agency goes dark.
How to fix: check your WP Admin → Users page. If you have a role of “Administrator,” you’re good. If you only see “Editor” or “Author,” request an upgrade. If the agency refuses, you can recover access via the database — any new developer can do this in 10 minutes.
4. Your source code and design files
Where it usually lives: the agency’s Git repository, design files in Figma or Adobe XD, and any custom plugins.
Why it matters: the website running on your server is “compiled output.” The source code (custom theme files, custom plugins, build pipelines) is what a new developer needs to make changes safely. Without it, every change requires reverse-engineering.
How to fix: ask in writing for the Git repository, design files, and any documentation. Be specific: “Please share the Git repository for the custom theme, the Figma file with the master design, and any deployment notes.” If they refuse — you paid for these things and they’re yours under work-for-hire — escalate to a written demand, citing your contract if you have one. If you don’t have a contract, you still have invoices and emails proving you paid for the work; that’s legally enough in Australia.
In practice: many agencies don’t actually have clean source code. They built the site directly on a live server with a page builder like Elementor, and there is no “source” beyond what you see in the WordPress admin. That’s fine — a new developer can work with the live site as the source of truth.
5. Third-party service access
Examples: Google Analytics, Google Search Console, Google Business Profile, Mailchimp, Stripe, Xero integration, CRM webhooks, social media accounts, payment gateways.
Where it usually lives: accounts owned by the agency, often using a generic email like [email protected].
Why it matters: if Google Search Console is in the agency’s account, you can’t see what’s happening with your search performance. If your Stripe webhooks point to the agency’s webhook URL, your payment processing depends on their server being up.
How to fix: for each service, audit who owns it. Add yourself as Admin on Google Search Console (the agency has to invite you). Move ownership of Google Business Profile to your email. Re-point any webhooks at your own server or a third-party tool like Zapier that you control. We help with this kind of integration recovery as part of our integrations and automation work.
The 14-day offboarding plan
Here’s the sequence that minimises customer-facing risk.
Week 1: Take inventory, take backups, don’t tell the agency yet
- Day 1: WHOIS lookup on your domain. Note who the registrant is.
- Day 2: Log into your hosting control panel. Note who owns the account. Take a full backup of the site (most hosts have a “Download backup” button).
- Day 3: Log into WordPress admin (or whatever CMS). Check your user role. Note all installed plugins and themes.
- Day 4: Audit your third-party services. Make a list of every account the agency might be on (Analytics, Search Console, GBP, Stripe, Xero, Mailchimp).
- Day 5: Find a new developer. Talk to them about what you have. They’ll tell you what they need, and how long the offboarding will realistically take. (This is where Web Champion fits in — we do this conversation as a 15-minute scoping call, and we’ve migrated dozens of Australian SMBs off agencies before. We can tell you what you’re actually missing in 15 minutes.)
You don’t tell the agency anything in Week 1. The goal of Week 1 is to know what you’re walking into.
Week 2: Transfer assets, then notify
- Day 8 (Monday): Get any missing access. Ask in writing: “Can you please add me as an Administrator on the WordPress site, and add me as an Owner on the Google Search Console property?” Frame it neutrally — “I want to be more involved in the back-end” — not as a goodbye signal. Most agencies grant this without questioning.
- Day 9–10: Once you have admin access, your new developer can do everything else without involving the old agency. They’ll take a fresh backup, set up a staging copy on new hosting in your name, and verify the migration works. This is when our website fix process picks up.
- Day 11: Initiate the domain transfer. The agency will get a notification email — this is the point at which they’ll know you’re leaving. Have your follow-up email ready.
- Day 12: Send the formal offboarding email. Tone matters here: businesslike, no recriminations.
Hi [Name],
Thanks for your work on the site over the years. We’re moving our web development in-house / to a new partner from [date]. I’m working on a clean handover — could you please:
1. Transfer ownership of the domain (transfer initiated [date])
2. Share the source code for the custom theme (Git URL or zip file)
3. Add [new dev email] as an Administrator on the WordPress site
The hosting transfer will complete by [date] and we won’t need ongoing support from your end after that.
Thanks again,
[Your name]
- Day 13–14: Complete the migration to the new hosting account. DNS propagates. Final smoke test from a few devices.
The reason for this sequence: by the time you tell them, you’ve already got the keys. They can’t disrupt anything because the practical levers are gone.
What to do if they refuse
If the agency refuses to hand over the domain, code, or third-party access — and it has happened to about 20% of the offboardings we’ve helped with — here’s the escalation order:
- One written request citing the work-for-hire principle. Most agencies fold here. Phrasing: “Under standard work-for-hire (and our invoiced engagement), the source code and design files are our property. Please share them by [date 7 days out].”
- Independent recovery. A competent new developer can rebuild source code from the live site, recover Google Search Console access via DNS verification, and complete the domain transfer without the agency’s cooperation. About 80% of “we can’t hand it over” situations are actually “we don’t have it, but we can’t admit that” — which means there’s nothing real to hand over and you proceed without it.
- Letter of demand. A small-business solicitor will send one for around $300–500. The threat of legal escalation moves things in 95% of cases.
- VCAT or Fair Work for amounts under $10,000. We’ve never seen an agency offboarding go this far, because the agency knows they’ll lose.
What not to do
- Don’t tell the agency you’re leaving in Week 1. Until you have admin access and a backup, you have less leverage than you think.
- Don’t pay a “release fee” or “data export fee.” These don’t legally exist for assets you’ve already paid for. They’re an intimidation tactic.
- Don’t accept “we can rebuild it for you” as the only path forward. A competent new developer can take any live WordPress site as a starting point — you don’t need the agency’s source code to move forward.
- Don’t announce the move publicly. No LinkedIn post, no Twitter callout. The agency relationship may end on poor terms; the goal is to make it boring and final, not dramatic.
- Don’t forget your email. If your email is on a domain managed by the agency, plan the migration of email DNS records carefully or you’ll lose inbound mail. This is the most common single point of failure during an offboarding.
When to call us
Web Champion is a Melbourne-based technical team that has done this offboarding sequence enough times that it is no longer interesting.
If you’re stuck in any version of “we paid for this site but can’t get our hands on it,” we run a free 15-minute scoping call. The call covers:
- What you currently own vs what the agency owns
- The cleanest sequence of asset recovery
- An honest estimate of the migration cost (most are $1,500–$3,500 — fixed price, in writing)
- What a healthier ongoing arrangement could look like once you’re out
We don’t try to lock you back into a long retainer at the end. Most clients move to our Care Plans from $2,400/mo, which are month-to-month, or just engage us project-by-project. Your relationship with us is meant to look nothing like the one you’re leaving.